Form
DPIA Template
Status not confirmedView on ODPA's website Source document
Summary
This is a template published by Guernsey's Office of the Data Protection Authority to help organisations record the process and outcome of a Data Protection Impact Assessment (DPIA). It is a practical tool, not a binding rule, intended to be used once screening questions have shown that a DPIA is needed for a project.
- Step one: Identify the need for a DPIA, describe the project's aims and benefits, and answer screening questions about new data collection, disclosure, new technology, high-impact decisions, sensitive data and intrusive contact.
- Step two: Describe the information flows: collection, use and deletion of personal data, and the number of individuals likely affected.
- Step three: Set out consultation requirements: who should be consulted internally and externally and how, linked to the project management process.
- Step four: Identify data protection and related risks by answering questions mapped to the seven data protection principles: lawfulness/fairness/transparency, purpose limitation, minimisation, accuracy, storage limitation, integrity/confidentiality, and accountability.
The template does not itself create new legal duties; it operationalises the existing requirement to conduct a DPIA where processing is likely to result in high risk to individuals, and organisations may adapt it to fit their own project management processes.
Applies to
data controllers, organisations conducting DPIAs
Topics
Version history
2026-07-30