LegalAIPay GDPR Kit
Start with the same question a DPO would ask: are we screening a new processing activity, building a full DPIA record, or managing existing GDPR evidence?
I need to know whether a DPIA is required
Use a short GDPR Art. 35 trigger screen before filling the full assessment.
Run DPIA screening Full recordI already know this processing needs a DPIA
Build the assessment record, risk register, DPO opinion, and decision log.
Start full DPIA RecordsI need to manage GDPR documents
Open the dashboard for DPIAs, DPAs, transfers, incidents, contracts, and exports.
Open dashboardThis kit creates a structured working record for privacy teams and counsel. It is not a substitute for legal advice on high-risk or regulator-facing matters.
Before you start a DPIA
Gather the minimum evidence first, otherwise the form feels abstract and the output will not be decision-ready.
- Business purpose and owner
- Systems and vendors
- Categories of personal data
- Art. 6 lawful basis
- Art. 9 basis, if sensitive data exists
- Privacy notice and rights process
- Data flow or architecture sketch
- Security controls and access rules
- Known harms and mitigation owners
How the DPIA flow maps to the EDPB structure
The tool uses business language, but the checkpoints follow the EDPB logic: description, legal analysis, necessity, risk, consultation, and final decision.
1. Context and scope
Controller, DPO, processing owner, systems, project stage, and why the assessment is being done.
2. Systematic description
Purpose, data categories, data subjects, recipients, transfers, lifecycle, and linked agreements.
3. Compliance analysis
Lawful basis, special category basis, retention, transparency, rights, and data protection by design.
4. Necessity and proportionality
Whether the same objective can be reached with less data, less tracking, or less intrusive means.
5. Risk and safeguards
Possible harms to people, likelihood, severity, mitigation plan, residual risk, and action owners.
6. DPO advice and decision
DPO opinion, views of data subjects where appropriate, sign-off, conditions, or regulator consultation.
Other GDPR workstreams
Use these when the facts show a vendor, transfer, breach, contract, or NDA issue. They should feed evidence back into the DPIA record.
Expected outputs
A good DPIA kit should produce a record you can review, challenge, approve, and update when the processing changes.
DPIA record
Facts, legal basis, data flow, necessity, safeguards, and risks.
DPO summary
Advice, unresolved concerns, and whether consultation is needed.
Action plan
Mitigations, owners, deadlines, and residual-risk conditions.
Decision log
Proceed, proceed with conditions, redesign, consult, or stop.