{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:02738153a65d168bc7ff1493536796f963b8a9e5ef5983fe302a521f962b0815","slug":"reg-dpia-privacy-impact-assessment","url":"/assets/agent_workflow-reg-dpia-privacy-impact-assessment-e931fa07.a0faa7e3a6afbb51.json"},"kind":"record","record":{"attributes":{"department":"privacy","domain":"reg","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=reg-dpia-privacy-impact-assessment","description":"GDPR Article 35 data protection impact assessment as a decision-aware workflow, run on the existing Process item (process_type=business_process) that represents the processing activity under assessment — the Process item doubles as the AssureSwarm proxy for the activity's records-of-processing (RoPA) entry, and the instance enriches it rather than creating a duplicate. It draws on upstream evidence — the RoPA extract, the data inventory and data-flow map, the Article 28 processor arrangements and transfer impact assessment from vendor due diligence, and the security risk assessment for the hosting systems — and moves the activity from screening, through necessity and proportionality and privacy-risk treatment, to a residual-risk decision with Article 36 prior consultation where needed and DPO sign-off. The named deliverable is the signed, versioned DPIA package (or, on the screened-out path, a defensible screening memo), registered against the Process item with tracked mitigation actions; close-and-archive hands that package off to records-of-processing maintenance. In scope: one processing activity (or a set of similar operations with comparable risks per Article 35(1)) from screening through sign-off; out of scope: the related workflows it draws on or feeds — vendor due diligence for new processors, transfer impact assessment for third-country transfers, security risk assessment for the hosting systems, and the records-of-processing maintenance that absorbs the outcome.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=reg-dpia-privacy-impact-assessment","capabilities":[],"controls":["UC-RISK-16"],"domains":["reg"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:02738153a65d168bc7ff1493536796f963b8a9e5ef5983fe302a521f962b0815","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:reg-dpia-privacy-impact-assessment","standards":["gdpr"],"teams":["privacy"]},"download":{"releaseId":"sha256:02738153a65d168bc7ff1493536796f963b8a9e5ef5983fe302a521f962b0815"},"history":{"digest":"6513159ffb827b5ee83ff4d033b2cc23e3fbffae1d55f46da60942de847344ee","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:R8","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AR8","slug":"reg-dpia-privacy-impact-assessment","sourceIds":["gdpr","nist-800-53"],"sourceUrl":null,"title":"DPIA / Privacy Impact Assessment","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:fda4770d953c7433b9fa2b7a8c84ed8282cfb8848fc14d1dcb93668a0a3f99a5","properties":{},"sourceDetailPath":"/data/v1/records/wf-r8-7a63c8f3.json","sourceId":"wf:R8","targetDetailPath":"/data/v1/records/uc-uc-risk-16-81243062.json","targetId":"uc:UC-RISK-16","type":"operates"}],"schemaVersion":1}
