Standard: Privacy risk assessment and DPIA decision record
Applies to: precise location, systematic monitoring, extensive evidence, matching and sensitive assignments

Decision rule: A feature should not be described as low-risk merely because it is technically simple. Assess the people affected, the scale, the sensitivity, the possibility of harm and the available alternatives.

1. Minimum assessment questions

  • What is the precise purpose and lawful basis?
  • Which people and data categories are affected, and could the data reveal location, health, identity, performance or reputation?
  • Is the processing necessary and proportionate? What less intrusive alternative was considered?
  • Who can access, export, correct or delete the information?
  • How long is each raw and derived data element retained?
  • Could the processing create discrimination, retaliation, safety, employment or reputational harm?
  • Is there meaningful human review, an appeal route and a way to correct inaccurate data?
  • Which suppliers receive the data, where is it processed and what transfer safeguards apply?

2. DPIA decision record

RecordRequired outcome
ScreeningDocument whether a full DPIA is required and why.
Impact analysisDescribe risks to individuals, likelihood, severity and affected groups.
MitigationsSpecify minimisation, access, retention, redaction, human review and appeal controls.
ApprovalName the owner, reviewer, residual risk decision and next review date.

3. Higher-risk examples

Examples include sending precise coordinates to a reverse-geocoding service, using profile attributes to match shoppers to opportunities, collecting evidence about workers or customers, monitoring repeated performance, processing health-related assignments or combining receipts, photographs, timestamps and payment records. The assessment should be completed before routine rollout and revisited after a material change.

Related information: Governance Centre · Privacy Governance · Contact ClueCheck