Guide · Worldwide
Data Mapping, ROPA, and DPIA Workbook
When a regulator, customer, or acquirer asks how you use personal data, the answer is a record of processing activities and a set of completed impact assessments. This workbook covers the fields required under GDPR Article 30, when a data protection impact assessment is mandatory, and how to assess cross-border transfers after Schrems II.
Record of processing activities: required fields
- Processing activity name, business owner, and the system or vendor that performs it.
- Purpose of processing and the lawful basis relied upon, recorded per purpose.
- Categories of data subjects, such as customers, employees, candidates, or minors.
- Categories of personal data, flagging special category and financial or health data.
- Recipients, including processors, sub-processors, and any onward disclosure.
- Cross-border transfers, destination countries, and the transfer mechanism used.
- Retention period and the deletion or anonymization method actually applied.
- Technical and organizational security measures protecting the data.
- Whether automated decision-making or profiling occurs, and the safeguards applied.
- Source of the data when it was not collected directly from the individual.
When a DPIA is required
- Systematic and extensive automated evaluation of individuals, including profiling and scoring.
- Large-scale processing of special category data or criminal offence data.
- Systematic monitoring of a publicly accessible area, including workplace monitoring.
- Innovative use of technology, which now routinely includes artificial intelligence features.
- Processing that involves children or other vulnerable data subjects.
- Combining or matching datasets collected for different original purposes.
- Any processing your supervisory authority lists as high risk in its national guidance.
DPIA structure
- 01Describe the processing, its scope, context, and the purposes pursued.
- 02Assess necessity and proportionality, including whether a less intrusive option exists.
- 03Consult stakeholders, and where appropriate the data subjects or their representatives.
- 04Identify risks to individuals, covering confidentiality, accuracy, discrimination, and loss of control.
- 05Define mitigations for each risk, with owners and implementation dates.
- 06Record the residual risk, the sign-off authority, and any requirement to consult the regulator.
- 07Schedule a review date and repeat the assessment when the processing changes materially.
Cross-border transfers
- Identify the transfer mechanism: adequacy decision, standard contractual clauses, or binding corporate rules.
- Complete a transfer impact assessment covering destination-country access laws and available redress.
- Apply supplementary measures such as encryption with keys held in the exporting jurisdiction.
- Track sub-processor locations, since most exposure arrives through the supply chain.
- Reassess whenever a vendor changes hosting region or adds a new sub-processor.
Need a defensible data map and DPIA process?
Dephiant builds the record of processing activities, runs impact assessments with your product and legal teams, and prepares the documentation regulators and enterprise customers request.