New DPIA Module: Integrated Impact Assessments in ProvePrivacy

ProvePrivacy has launched a new DPIA module. Built into the platform alongside the RoPA, information asset register and risk register, it turns the Data Protection Impact Assessment into a governed, auditable record. Teams can run an assessment for a project or a RoPA activity. They can finish it in the platform or with a certified document, and track every stage against a deadline.

Existing DPIAs have already been migrated into the module. Teams can carry on from the stage they had reached.

ProvePrivacy DPIA module at a glance

Feature Detail
Product ProvePrivacy DPIA module
Record types Project DPIAs and RoPA activity DPIAs
Completion modes In the platform, or your own certified document
Workflow Six-stage tracker with green, amber and red urgency
Screening Twelve ICO-style triggers with early exit
Review cycle 12-month default review date
AI support Dedicated AI tab with hard-stop checks
Availability Live now for ProvePrivacy customers

What Is DPIA Software and Why Do Organisations Need It?

DPIA software is a platform that helps organisations carry out, record and review Data Protection Impact Assessments. It replaces scattered documents and spreadsheets with one auditable record of risks, decisions, evidence and sign-off. Privacy teams can then show regulators exactly how they assessed high-risk processing.

A Data Protection Impact Assessment (DPIA) is a structured process for identifying and minimising the data protection risks of a project. Older guidance calls it a privacy impact assessment (PIA).

Article 35 of the UK GDPR requires a controller to complete a DPIA before processing that is likely to result in a high risk to individuals. The ICO also expects assessors to weigh both the likelihood and the severity of harm.

Article 35 names three cases where a DPIA is always required:

  • Systematic and extensive profiling, or automated decisions that significantly affect people.
  • Large-scale processing of special category data or criminal offence data.
  • Large-scale systematic monitoring of a publicly accessible area.

Every DPIA must contain at least four elements:

  • A systematic description of the processing and its purposes.
  • An assessment of necessity and proportionality.
  • An assessment of the risks to individuals.
  • The measures planned to address those risks.

Controllers must also seek the advice of their data protection officer (DPO), where one is designated. They must review the assessment when the risk changes. If a high risk cannot be reduced, the ICO says the controller must consult the regulator before processing begins.

Evidencing all of that is difficult when assessments live in email threads and personal drives. DPIA software gives data protection and information governance teams a single place to prove the work was done.

What Is the ProvePrivacy DPIA Module?

The ProvePrivacy DPIA module is an integrated module for creating, managing and evidencing Data Protection Impact Assessments. It works alongside the RoPA, information asset register, data sharing records and risk register. It treats each DPIA as an organisational record. One record can cover a project, a single RoPA activity or several related activities. It finishes inside the platform or through a certified document.

Previously, a DPIA in ProvePrivacy was a form attached to one activity in the Record of Processing Activities (RoPA). That suited simple cases. Real assessments are rarely that tidy. They cover projects with no RoPA entry yet, involve vendors, and often end with a document the client already wrote.

Can One DPIA Cover Several Processing Activities?

Yes. A ProvePrivacy DPIA links one primary activity and any number of covered activities. A single decision document can therefore cover related processing, such as several trials or a service and its data subjects. Each record keeps its own reference, owner, department and anticipated conclusion date.

Similar assessments are handled as siblings. A sibling DPIA keeps the cloned answers without sharing the wrong set of activities. Cloning a RoPA activity links to the existing DPIA instead of copying an assessment that would drift out of date.

Where Can You Start a DPIA?

Users can open DPIAs from the side menu, which lists every assessment they are entitled to see. They can also raise or link a DPIA from an activity’s assessment chain, where the DPIA tab sits between Findings and File Center.

Project DPIAs need no separate project register. Teams can therefore begin an assessment before every RoPA activity exists.

How Do You Run a DPIA in ProvePrivacy, Step by Step?

Running a DPIA in ProvePrivacy takes seven steps: create the record, screen, describe the processing, assess necessity and measures, identify risks, consult and conclude, then review. Each step maps to a tab in the module. Teams can see what remains at any point.

Step 1: How Do You Create the DPIA Record?

Open DPIAs from the side menu and choose a project or an activity. Set a name, description, department, owner and anticipated conclusion date. ProvePrivacy assigns a reference such as DPIA-00001.

Step 2: How Do You Screen for the Need for a DPIA?

Work through twelve ICO-style screening triggers and record a rationale for each. If screening shows a DPIA is not required, the module offers an early exit. High Risk screening acts as a prompt, not a gate.

Step 3: How Do You Describe the Processing?

Capture the nature, scope, context, data subjects, personal data categories and data flows. Link information assets, international transfers and security assessments. Roles and data-sharing details read through from the RoPA, so the DPIA never contradicts the register.

Step 4: How Do You Assess Necessity and Choose Security Measures?

Record purpose limitation, data minimisation, storage limitation and overall necessity. Choose security measures from the organisation’s own library. ProvePrivacy copies each selected measure into the DPIA, so later library edits never rewrite a concluded assessment.

Step 5: How Do You Identify and Score Risks?

Raise concerns in context and let contributors propose findings. Promote confirmed risks to the register when ready. Unregistered risks stay visible on the DPIA without cluttering the register.

Step 6: How Do You Consult and Conclude?

Record consultation feedback, then conclude with a decision: Accepted, Do not proceed or Reopened. Sign-off covers the owner, the DPO and any senior approver.

Step 7: How Do You Keep the DPIA Under Review?

Every DPIA carries a review date, 12 months by default. Select Mark as reviewed to roll the date forward. Owners and DPOs receive a notification when a review falls due.

How Does ProvePrivacy DPIA Software Compare With Manual Spreadsheets?

ProvePrivacy DPIA software differs from manual spreadsheets and documents by linking every assessment to the RoPA, tracking stages automatically, and recording who contributed and certified. Spreadsheets store answers. ProvePrivacy stores answers, evidence, decisions, dates and accountability together.

Capability Manual spreadsheets and documents ProvePrivacy DPIA module
Link to RoPA activities Copied by hand, drifts out of date Linked records with primary and covered activities
Progress tracking Ad hoc status columns Six-stage tracker with RAG urgency
Contributor attribution Unclear who answered what Named, recorded and auditable
Risk handling Separate risk log Shared findings and risk register
AI assessment Free-text notes Dedicated AI framework with hard-stop checks
Review reminders Calendar entries Automatic 12-month review notifications
Sign-off evidence Email approvals Dated, role-aware sign-off
Management information Manual reporting Organisation-wide DPIA dashboard for DPOs

How Can You Complete a DPIA in the Platform or With Your Own Document?

ProvePrivacy supports two completion modes: in the platform, or with your own external document. Every DPIA records which route it took, so reporting never treats the paths as equivalent. Each route ends in an accountable, named certification or sign-off.

Completion mode How it works
In the platform Complete the assessment in ProvePrivacy and export a prefilled Word document.
External document Upload your own PDF or Word DPIA and certify it with a recorded declaration.

Exports are prefilled from existing data. Only genuine gaps print as labelled blanks. The document uses the organisation’s own risk-matrix terminology, such as its axis names and grades.

When certifying, ProvePrivacy records who certified, when, which file and the declaration wording. The DPIA owner, the DPO or a RoPA Manager can certify. Organisations that prefer their own template therefore keep full accountability.

How Does the DPIA Module Track Progress and Reviews?

The DPIA module tracks progress with a six-stage DPIA workflow tracker measured against the anticipated conclusion date. Each stage shows green, amber or red urgency. Status and stage dates stay in sync, so owners and DPOs see which assessments are drifting without opening each record.

Users click a stage to record completion or set a target date. The status pill on the DPIA list carries the same colour. If no anticipated date is set, the module raises no false overdue warning.

ProvePrivacy statuses follow the language privacy teams use:

  • Draft, Drafted and Consulted for early progress.
  • Assessed and Regulator Consultation for later stages.
  • Concluded and Signed Off for finished assessments.
  • Abandoned, Reopened and Archived for other outcomes.

Review dates work separately from workflow urgency. Concluded decisions therefore do not go stale as processing changes.

How Does the DPIA Module Assess AI and Automated Decision-Making?

The ProvePrivacy DPIA module assesses artificial intelligence through a dedicated AI tab. It applies a shared AI framework, runs hard-stop checks and lists the linked AI systems. The tab appears when AI is involved, so assessors answer AI questions only when they matter.

Incomplete AI system profiles can block a conclusion. Only a DPO can override an AI hard stop. Management information shows AI involvement, AI types and hard-stop counts across the DPIA portfolio.

Necessity and proportionality cells also cover AI proportionality and Article 22 automated decision-making where it applies. Organisations can therefore treat AI as a first-class DPIA concern, not a free-text afterthought.

How Do Risks, Consultation and Sign-Off Work?

Risks, consultation and sign-off in the ProvePrivacy DPIA module run through one shared findings model. Owners raise concerns, contributors propose findings and owners accept or dismiss them. Confirmed risks can be promoted to the risk register, and every step is recorded.

An Accepted outcome requires a credible plan. Every registered risk needs a Target grade and at least one mitigating action. If the inherent grade is High or Extreme, the Target must be below High. Approval therefore means a plan exists, not just a click on Accept.

The module also records the supervisory authority route. Referral dates, expected response dates and the authority’s decision sit in dedicated fields. They never overload the annual review date.

How Can Vendors and Colleagues Contribute to a DPIA?

Vendors, joint controllers, auditors and colleagues contribute through personal, record-scoped links. No shared logins are needed. Each contributor sees only the tabs they need and is told that their name will be recorded for audit. Answers are attributed by name.

Contributor classes include DPO, internal reviewer, vendor or processor, data controller, joint controller, commercial customer, senior approver and auditor. Owners can invite, waive or revoke contributors at any time.

Assignees on a single risk or action receive a reduced view. They see the record facts and their own item. They cannot see files or other people’s answers.

What Happens to Existing DPIAs?

Existing ProvePrivacy DPIAs have been migrated into the new module. Each migrated record keeps its status, evidence locations, key dates and File Center documents. Open assessments resume at the stage they had reached. They do not reset to Draft.

Concluded outcomes carry across, including authority referrals. Where two legacy DPIAs sat on one activity, the module creates two records. Legacy files stay in place and appear in the migrated DPIA’s File Center without duplication.

How Does ProvePrivacy Help Solve DPIA Problems?

ProvePrivacy solves the common DPIA problems of scattered evidence, duplicate typing and unclear accountability. The platform connects each assessment to the RoPA, the information asset register, data sharing records and the risk register. Teams answer each question once and evidence it in one place.

  • Scattered documents: one File Center holds evidence and certified documents.
  • Duplicate answers: roles, retention, lawfulness and AI details read through from the RoPA.
  • Unclear ownership: every DPIA has an owner, department, reference and recorded sign-off.
  • Slow progress: workflow urgency and review reminders show what needs attention.
  • Limited visibility: a DPO dashboard reports status, completion mode, review status and AI involvement.

Who Is the DPIA Module For?

The ProvePrivacy DPIA module is built for DPOs, privacy teams and information governance professionals. It also serves RoPA Managers, department managers, data champions and project owners who run high-risk processing. Vendors and colleagues can contribute without needing a full account.

Role-based visibility keeps each audience in scope. DPOs and RoPA Managers see the whole organisation. Department managers and data champions see their own department. DPIA owners always see their own records.

DPIA Software FAQs

What is a DPIA?

A Data Protection Impact Assessment (DPIA) is a process that helps organisations identify and minimise the data protection risks of a project. Article 35 of the UK GDPR requires one before processing that is likely to result in a high risk to individuals.

Is a DPIA mandatory under UK GDPR?

A DPIA is mandatory when processing is likely to result in a high risk. Article 35 names three cases: large-scale profiling with significant effects, large-scale special category or criminal offence data, and large-scale public monitoring. Other high-risk processing also needs one.

What is the difference between a DPIA and a RoPA?

A Record of Processing Activities (RoPA) lists what personal data an organisation processes and why. A DPIA assesses the risks of specific high-risk processing. ProvePrivacy links the two, so DPIAs read from the RoPA and activity icons reflect the DPIA decision.

Can I use my own DPIA template in ProvePrivacy?

Yes. ProvePrivacy’s external document mode lets you upload your own PDF or Word DPIA and certify it. The platform records who certified, when and what they declared. The uploaded file becomes the issued DPIA document.

Does ProvePrivacy support DPIAs for AI systems?

Yes. When AI is involved, the DPIA module shows a dedicated AI tab. It applies a shared AI framework and hard-stop checks and lists the linked AI systems. Incomplete AI profiles can block a conclusion unless a DPO overrides.

When do you need to consult the ICO about a DPIA?

You need to consult the ICO when a DPIA identifies a high risk that you cannot reduce. Processing cannot begin until consultation is complete. If you reduce the risk so it is no longer high, consultation is not required.

How Do You Get Started With the ProvePrivacy DPIA Module?

The DPIA module is live now for ProvePrivacy customers. Select DPIAs from the side menu, or open an activity’s DPIA tab, to start or review an assessment. Existing DPIAs are already waiting in the module.

Want a walkthrough? Book a ProvePrivacy demo today and see the DPIA module on your own processing activities.

Related Reading on Data Protection Impact Assessments

Sources

Manage personal data and privacy risks

Scroll to Top

Contact us

If you would like to ask more questions or to arrange training, complete the form below and we will respond shortly.

Prefer to schedule a 15 minute call? Schedule call today >>

See our Privacy Statement for more details.