LegalAIPay GDPR KitLegalAIPay GDPR 工具包
Start with the same question a DPO would ask: are we screening a new processing activity, building a full DPIA record, or managing existing GDPR evidence?从 DPO 会先问的问题开始:我们是在筛查新的处理活动、建立完整 DPIA 记录,还是管理现有 GDPR 合规证据?
I need to know whether a DPIA is required我需要判断是否必须做 DPIA
Use a short GDPR Art. 35 trigger screen before filling the full assessment.在填写完整评估前,先用简短的 GDPR 第35条触发条件筛查。
Run DPIA screening运行 DPIA 筛查Full record完整记录I already know this processing needs a DPIA我已经知道该处理活动需要 DPIA
Build the assessment record, risk register, DPO opinion, and decision log.生成评估记录、风险登记册、DPO 意见和决策日志。
Start full DPIA开始完整 DPIARecords记录I need to manage GDPR documents我需要管理 GDPR 文件
Open the dashboard for DPIAs, DPAs, transfers, incidents, contracts, and exports.打开仪表盘管理 DPIA、DPA、跨境传输、事件、合同和导出文件。
Open dashboard打开仪表盘This kit creates a structured working record for privacy teams and counsel. It is not a substitute for legal advice on high-risk or regulator-facing matters.本工具包为隐私团队和法律顾问生成结构化工作记录。对于高风险或面向监管机构的事项,不能替代法律意见。
Before you start a DPIA开始 DPIA 前
Gather the minimum evidence first, otherwise the form feels abstract and the output will not be decision-ready.
- Business purpose and owner
- Systems and vendors
- Categories of personal data
- Art. 6 lawful basis
- Art. 9 basis, if sensitive data exists
- Privacy notice and rights process
- Data flow or architecture sketch
- Security controls and access rules
- Known harms and mitigation owners
How the DPIA flow maps to the EDPB structure
The tool uses business language, but the checkpoints follow the EDPB logic: description, legal analysis, necessity, risk, consultation, and final decision.
1. Context and scope
Controller, DPO, processing owner, systems, project stage, and why the assessment is being done.
2. Systematic description
Purpose, data categories, data subjects, recipients, transfers, lifecycle, and linked agreements.
3. Compliance analysis
Lawful basis, special category basis, retention, transparency, rights, and data protection by design.
4. Necessity and proportionality
Whether the same objective can be reached with less data, less tracking, or less intrusive means.
5. Risk and safeguards
Possible harms to people, likelihood, severity, mitigation plan, residual risk, and action owners.
6. DPO advice and decision
DPO opinion, views of data subjects where appropriate, sign-off, conditions, or regulator consultation.
Other GDPR workstreams其他 GDPR 工作流
Use these when the facts show a vendor, transfer, breach, contract, or NDA issue. They should feed evidence back into the DPIA record.
Expected outputs预期输出
A good DPIA kit should produce a record you can review, challenge, approve, and update when the processing changes.
DPIA record
Facts, legal basis, data flow, necessity, safeguards, and risks.
DPO summary
Advice, unresolved concerns, and whether consultation is needed.
Action plan
Mitigations, owners, deadlines, and residual-risk conditions.
Decision log
Proceed, proceed with conditions, redesign, consult, or stop.