GDPR decision gatewayGDPR 决策入口

LegalAIPay GDPR KitLegalAIPay GDPR 工具包

Start with the same question a DPO would ask: are we screening a new processing activity, building a full DPIA record, or managing existing GDPR evidence?从 DPO 会先问的问题开始:我们是在筛查新的处理活动、建立完整 DPIA 记录,还是管理现有 GDPR 合规证据?

This kit creates a structured working record for privacy teams and counsel. It is not a substitute for legal advice on high-risk or regulator-facing matters.本工具包为隐私团队和法律顾问生成结构化工作记录。对于高风险或面向监管机构的事项,不能替代法律意见。

Before you start a DPIA开始 DPIA 前

Gather the minimum evidence first, otherwise the form feels abstract and the output will not be decision-ready.

Start screening
Processing facts
  • Business purpose and owner
  • Systems and vendors
  • Categories of personal data
Legal and privacy inputs
  • Art. 6 lawful basis
  • Art. 9 basis, if sensitive data exists
  • Privacy notice and rights process
Risk evidence
  • Data flow or architecture sketch
  • Security controls and access rules
  • Known harms and mitigation owners

How the DPIA flow maps to the EDPB structure

The tool uses business language, but the checkpoints follow the EDPB logic: description, legal analysis, necessity, risk, consultation, and final decision.

1. Context and scope

Controller, DPO, processing owner, systems, project stage, and why the assessment is being done.

2. Systematic description

Purpose, data categories, data subjects, recipients, transfers, lifecycle, and linked agreements.

3. Compliance analysis

Lawful basis, special category basis, retention, transparency, rights, and data protection by design.

4. Necessity and proportionality

Whether the same objective can be reached with less data, less tracking, or less intrusive means.

5. Risk and safeguards

Possible harms to people, likelihood, severity, mitigation plan, residual risk, and action owners.

6. DPO advice and decision

DPO opinion, views of data subjects where appropriate, sign-off, conditions, or regulator consultation.

Other GDPR workstreams其他 GDPR 工作流

Use these when the facts show a vendor, transfer, breach, contract, or NDA issue. They should feed evidence back into the DPIA record.

DPA

Controller-processor agreement for vendor processing.

Open DPA tool

Transfer

Chapter V assessment for international data transfers.

Open transfer tool

Breach

Incident record and GDPR Art. 33/34 notification analysis.

Open breach tool

Contracts

Review privacy, confidentiality, and vendor clauses before signing.

Open contract tool

Expected outputs预期输出

A good DPIA kit should produce a record you can review, challenge, approve, and update when the processing changes.

DPIA record

Facts, legal basis, data flow, necessity, safeguards, and risks.

DPO summary

Advice, unresolved concerns, and whether consultation is needed.

Action plan

Mitigations, owners, deadlines, and residual-risk conditions.

Decision log

Proceed, proceed with conditions, redesign, consult, or stop.