Assessing higher-risk processing before routine use
Standard: Privacy risk assessment and DPIA decision record
Applies to: precise location, systematic monitoring, extensive evidence, matching and sensitive assignments
| Record | Required outcome |
|---|---|
| Screening | Document whether a full DPIA is required and why. |
| Impact analysis | Describe risks to individuals, likelihood, severity and affected groups. |
| Mitigations | Specify minimisation, access, retention, redaction, human review and appeal controls. |
| Approval | Name the owner, reviewer, residual risk decision and next review date. |
Examples include sending precise coordinates to a reverse-geocoding service, using profile attributes to match shoppers to opportunities, collecting evidence about workers or customers, monitoring repeated performance, processing health-related assignments or combining receipts, photographs, timestamps and payment records. The assessment should be completed before routine rollout and revisited after a material change.
Related information: Governance Centre · Privacy Governance · Contact ClueCheck