Custom DPIA workflow tool development
Appfront builds workflow tools for organisations that carry out DPIAs (data protection impact assessments). The tool covers a pre-scan that determines whether a DPIA is required, a questionnaire per processing activity, risks and measures with an owner, the advice of the data protection officer, the decision of the controller, and a reassessment whenever the processing changes. It's linked to your record of processing activities, so for every processing activity you can see whether a DPIA exists and what its outcome was.
What is a DPIA workflow tool?
Under the GDPR, an organisation must carry out a data protection impact assessment, or DPIA, when a processing activity is likely to result in a high risk to the individuals whose data is involved. Examples include large-scale processing of health data, camera surveillance or profiling. A DPIA describes the processing, assesses the risks and records the measures. The data protection officer advises. A workflow tool guides the organisation through those steps.
In many organisations, a DPIA is a text document that someone fills in and circulates by email. Whether a DPIA is needed is judged differently for each project. Measures are listed in the document, but nobody follows them up. The DPO's advice sits in an email. And when a processing activity changes, nobody knows the DPIA has to be revisited. When the regulator asks a question, everything has to be searched for.
We build custom development because the workflow has to fit your organisation: which DPIA model you use, for example a government model or your own, who drafts, advises and decides on the DPIA, how your record of processing activities is set up, and how measures are followed up. When a DPIA is mandatory and what it must contain is decided with your data protection officer; the tool ensures the process is followed.
Required or not
A pre-screen for each processing activity against the criteria for a mandatory DPIA, with the outcome and rationale recorded.
Risks with measures
Risks with likelihood and impact, and measures with an owner and deadline that are tracked until implemented.
Advice and decision
The advice of the data protection officer and the decision of the controller on the DPIA, with date and rationale.
How we build your DPIA workflow tool
We start with your DPIAs: how many per year, which model, who is involved, and how measures are currently followed up.
Your DPIA model, roles, record of processing activities, and how measures are followed up.
The pre-screen for each processing activity and the questionnaire based on your model.
Risk analysis, measures with an owner, the DPO's advice and the decision.
Reassessment on change, integration with the record of processing activities, reporting, and ongoing management afterwards.
What a DPIA workflow tool actually does
The components below appear in almost every organisation that carries out DPIAs. Which ones you need depends on the number of processing activities.
Pre-screen
A short questionnaire that determines whether a DPIA is needed, with the rationale.
Questionnaire
Description, purpose, legal basis, data, data subjects and recipients for each processing activity.
Risk analysis
Risks to data subjects with likelihood and impact, and the residual risk after measures.
Measures
Measures with owner, deadline and status, tracked until implemented.
Advice and decision
Advice of the data protection officer and decision of the controller.
Reassessment
A notification when a processing activity changes or a reassessment is needed.
Who we build a DPIA workflow tool for
The tool is intended for organisations with many processing activities and regular DPIAs.
Municipalities
Many processing activities in social services and enforcement. The model and the link to the register are at the heart of it.
Healthcare providers
Health data on a large scale. Risks and measures matter most.
Schools and universities of applied sciences
Digital learning tools and systems holding pupil and student data. The pre-screen is what is needed.
Financial services providers
Profiling and automated decisions. Advice and decision are at the core.
Test your idea first: a working prototype in 1 day
With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.
Explore OneDayBuild →Technology and integrations
This page covers DPIAs. For data processing agreements, see our page on a contract register for data processing agreements; for data cleansing, our page on GDPR software; and for risk and compliance, our page on a GRC platform. You can read about our approach at building software.
Why choose Appfront for your DPIA workflow tool?
A DPIA sitting in a folder protects no one. That is what we build on: a route everyone follows, measures that get carried out, and a reassessment when it is needed.
Everyone follows the same route
Pre-scan, questionnaire, advice and decision work the same way for every DPIA.
Measures carried out
Every measure has an owner and remains visible until it has been implemented.
Ready for a question
For each processing activity you can see whether there is a DPIA, what came out of it and who decided.
Security and privacy in a DPIA workflow tool
The tool holds descriptions of processing activities, risks and security measures, information that should not be public. Access is set by role: the author works on their own DPIA, the DPO advises, and the controller decides.
The tool runs in a European data centre or in your own environment, with encrypted storage, daily backups and two-factor sign-in.
Frequently asked questions about a DPIA workflow tool
Questions that privacy officers and lawyers ask before getting started.
It uses a pre-scan to determine whether a DPIA is required, guides the author through the questionnaire, records risks and measures, collects the advice of the data protection officer and the decision, and flags when a reassessment is needed.
Under the GDPR, when a processing activity is likely to result in a high risk to data subjects. The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) publishes a list of processing activities for which a DPIA is mandatory. Which of your processing activities fall under this is determined together with your data protection officer.
Yes. The questionnaire follows the model you use, for example a model used within government or your own model.
If a high risk remains after measures have been taken, the Autoriteit Persoonsgegevens must be consulted in advance. The tool records whether this is required and what the outcome was.
Every measure is given an owner and a deadline, and remains visible until it has been implemented. The DPO can see progress.
Yes. For each processing activity in the register you can see whether there is a DPIA, and the DPIA refers back to the processing activity.
Check that first. There are privacy management packages with a DPIA module, and these are a good fit if your model matches theirs. Custom development makes sense if you use your own model, if the workflow needs to connect to your own register and systems, or if measures need to flow into your existing follow-up processes.
DPIAs that follow a fixed route, with measures that get carried out?
Tell us how many DPIAs you carry out a year, which model you use and how measures are currently followed up. We will show you what the pre-scan, the risk assessment and the advice look like.