GDPR decision gateway

LegalAIPay GDPR Kit

Start with the same question a DPO would ask: are we screening a new processing activity, building a full DPIA record, or managing existing GDPR evidence?

This kit creates a structured working record for privacy teams and counsel. It is not a substitute for legal advice on high-risk or regulator-facing matters.

Before you start a DPIA

Gather the minimum evidence first, otherwise the form feels abstract and the output will not be decision-ready.

Start screening
Processing facts
  • Business purpose and owner
  • Systems and vendors
  • Categories of personal data
Legal and privacy inputs
  • Art. 6 lawful basis
  • Art. 9 basis, if sensitive data exists
  • Privacy notice and rights process
Risk evidence
  • Data flow or architecture sketch
  • Security controls and access rules
  • Known harms and mitigation owners

How the DPIA flow maps to the EDPB structure

The tool uses business language, but the checkpoints follow the EDPB logic: description, legal analysis, necessity, risk, consultation, and final decision.

1. Context and scope

Controller, DPO, processing owner, systems, project stage, and why the assessment is being done.

2. Systematic description

Purpose, data categories, data subjects, recipients, transfers, lifecycle, and linked agreements.

3. Compliance analysis

Lawful basis, special category basis, retention, transparency, rights, and data protection by design.

4. Necessity and proportionality

Whether the same objective can be reached with less data, less tracking, or less intrusive means.

5. Risk and safeguards

Possible harms to people, likelihood, severity, mitigation plan, residual risk, and action owners.

6. DPO advice and decision

DPO opinion, views of data subjects where appropriate, sign-off, conditions, or regulator consultation.

Other GDPR workstreams

Use these when the facts show a vendor, transfer, breach, contract, or NDA issue. They should feed evidence back into the DPIA record.

DPA

Controller-processor agreement for vendor processing.

Open DPA tool

Transfer

Chapter V assessment for international data transfers.

Open transfer tool

Breach

Incident record and GDPR Art. 33/34 notification analysis.

Open breach tool

Contracts

Review privacy, confidentiality, and vendor clauses before signing.

Open contract tool

Expected outputs

A good DPIA kit should produce a record you can review, challenge, approve, and update when the processing changes.

DPIA record

Facts, legal basis, data flow, necessity, safeguards, and risks.

DPO summary

Advice, unresolved concerns, and whether consultation is needed.

Action plan

Mitigations, owners, deadlines, and residual-risk conditions.

Decision log

Proceed, proceed with conditions, redesign, consult, or stop.