Scope the right privacy impact assessment before launch.
Use these prompts to bring product, privacy, security, and business owners into the same conversation before a new processing activity becomes difficult to change.
For general operational guidance only. It is not legal advice or a formal PIA/DPIA.
1 · Trigger and context
Start with the change, not the template
□What product, service, process, or model is changing?
□What personal information is collected, generated, inferred, or shared?
□Whose information is involved, and could the use affect vulnerable people or eligibility?
□What are the purpose, retention period, access path, and deletion trigger?
□Which vendors, subprocessors, transfers, models, or systems receive the data?
□What decision would stop launch, require conditions, or escalate to leadership?
2 · Evidence to assemble
Make the assessment reviewable
Evidence: Plain-language processing description and data-flow sketch
Evidence: Named product, privacy, security, and business owners
Evidence: Purpose, necessity, minimization, retention, and access notes
Evidence: Vendor, subprocessor, transfer, and contract review record
Evidence: Risk decision, conditions, remediation owner, and target date
3 · Decision and follow-through
Choose a documented path
Stop
The purpose, data boundary, owner, or risk is not clear enough to proceed.
Proceed with conditions
Launch depends on named controls, owners, evidence, and a tracked remediation date.
Proceed
The scope, safeguards, decision authority, and monitoring path are documented.
This worksheet is maintained by Mohammad Movahedi as part of the Movahedi Control Atlas. Confirm current legal requirements and obtain qualified advice for your facts and jurisdiction.