Data Protection Impact Assessment (DPIA) First Draft
When a business team proposes a new system, vendor or AI deployment that processes personal data and you need a structured first draft and question list before the assessment meeting.
A data protection impact assessment is increasingly the gate a new system has to pass before launch, especially for AI tools, profiling, large-scale monitoring and anything involving sensitive data. The hard part is rarely the template. It is turning a product team's loose description into a precise account of what data moves where, why each piece is needed, and which risks to individuals remain after mitigation.
This prompt separates the project description from the data-flow notes and asks Claude for the core components of an assessment: a processing description, a necessity and proportionality analysis, a risk register with likelihood, severity, mitigation and residual risk, and a residual-risk summary. Every claim about the project is quoted from the intake material. Anything the intake does not answer goes into an owner-sorted question list instead of being assumed.
The draft is only as good as the information the business team provided, and the ratings are preliminary. Counsel decides the lawful basis, whether consultation with a regulator is required and whether the residual risk is acceptable. Verify every legal reference against current law and regulator guidance, and treat the result as a working draft that stakeholders complete together.
The Prompt
I am privacy counsel at [ORGANIZATION] preparing a first-draft data protection impact assessment for the project below. The assessment will be reviewed under [GDPR ARTICLE 35 / UK GDPR / APPLICABLE STATE LAW RISK ASSESSMENT REQUIREMENT / INTERNAL POLICY] and our template is [PASTE TEMPLATE HEADINGS OR "USE A STANDARD STRUCTURE"]. <project_description> [PASTE THE BUSINESS TEAM'S PROJECT DESCRIPTION, PRODUCT SPEC OR INTAKE FORM] </project_description> <data_flows> [PASTE DATA-FLOW NOTES, SYSTEM LIST, VENDORS, RETENTION SETTINGS, AND ANY EXISTING SECURITY REVIEW] </data_flows> Draft the DPIA with these sections: 1. Description of the processing: purposes, data categories (flag any special-category or sensitive data), data subjects, sources, recipients and vendors, systems, retention, and transfers. 2. Necessity and proportionality: lawful basis [TO BE CONFIRMED BY COUNSEL], data minimization, retention, transparency, and how individuals can exercise their rights. 3. Risk register as a table: Risk to individuals | Source in the project description (quote it) | Likelihood (Remote/Possible/Probable) | Severity (Minimal/Significant/Severe) | Existing controls | Proposed mitigation | Residual risk. 4. Residual risk summary and whether any high residual risk may require consultation with a regulator under [APPLICABLE PROVISION]. 5. Open questions: everything the business team must answer before sign-off, grouped by owner (product, engineering, security, vendor management). Base every statement about the project on the pasted text and quote it. Where the description is silent, do not assume; add the point to Open questions. Mark risk ratings as preliminary. This is a draft for counsel and the business team to complete.
Example Output
A sectioned DPIA draft with a processing description, necessity analysis, a quoted risk register with likelihood, severity and mitigation, a residual-risk summary and a question list by owner.
Illustrative example — names, figures, and facts are fictional.
DPIA FIRST DRAFT (PRELIMINARY, FOR COUNSEL REVIEW) Project: "Smart Routing" AI triage for customer support tickets | Owner: Support Operations 1. DESCRIPTION OF PROCESSING Purpose: "automatically categorize and prioritize incoming tickets" (project description, para. 1). Data: names, emails, ticket text; ticket text "may include account or health details customers volunteer" (para. 3). Possible sensitive data: flagged. Vendor: hosted model provider (data-flow notes, item 4). Retention: "logs kept indefinitely for tuning" (item 6). 2. NECESSITY AND PROPORTIONALITY Lawful basis: [TO BE CONFIRMED BY COUNSEL]. Minimization concern: full ticket history is sent when only the latest message appears to be needed for routing. 3. RISK REGISTER Risk | Source | Likelihood | Severity | Existing controls | Mitigation | Residual Sensitive data sent to vendor | para. 3 | Probable | Significant | None stated | Redaction before API call; vendor DPA no-training term | Possible / Significant Indefinite log retention | item 6 | Probable | Significant | None stated | 90-day retention; purge job | Remote / Minimal Misrouting delays urgent requests | para. 2 | Possible | Significant | Human queue review | Escalation keywords bypass model | Remote / Significant 4. RESIDUAL RISK SUMMARY No residual risk rated high if mitigations are adopted. Reassess if redaction is not implemented. 5. OPEN QUESTIONS Product: Is full ticket history needed? Engineering: Where are logs stored, and who can access them? Vendor management: Does the provider's DPA bar training on our data? Security: Has the vendor completed a security review?
Tips
- •Paste the raw intake material rather than summarizing it. Claude's quotes let reviewers see exactly which statement each risk came from.
- •Expect the Open questions list to be long on the first pass. Send it to the business team before you refine the risk ratings.
- •For AI projects, add notes on training data, model outputs and human review to the data-flow section, since those drive several risks.
- •Treat the lawful basis and any regulator-consultation conclusion as counsel's call; the draft leaves them flagged on purpose.
- •Verify any legal references against current law and guidance. The DPIA is a draft for attorney and stakeholder review.
Frequently Asked Questions
Can this replace our DPIA template?
No. Paste your template headings into the prompt and Claude will follow them. The prompt's default structure reflects the components most assessments include, but your organization's template, regulator guidance and internal policy should control the final format and the sign-off process.
How should I use the likelihood and severity ratings?
As a starting point for discussion. Claude rates risk from the text you pasted, which usually omits controls the business team has not mentioned. Review the register with security and product owners, adjust ratings with their input, and record why. The final ratings and the acceptance of residual risk are human decisions.
Does the prompt work for US state risk assessments as well as GDPR?
The structure transfers well, but the required content differs by law. Name the framework in the first line and paste any required headings. Where a specific statutory requirement matters, verify it against the current statute and regulations rather than relying on Claude's summary.
What if the business team's description is thin?
Run the prompt anyway. A thin description produces a long Open questions list, which is useful in itself: send it to the project owner, collect answers, then rerun the prompt with the fuller material. That loop is usually faster than an unstructured kickoff meeting.
Related Prompts
Get New Prompts Like This Every Week
Join the free Claude for Lawyers newsletter — weekly prompts, tutorials, and practice-specific guides.