Skip to main content

Movahedi Control Atlas worksheet

Scope the right privacy impact assessment before launch.

Use these prompts to bring product, privacy, security, and business owners into the same conversation before a new processing activity becomes difficult to change.

For general operational guidance only. It is not legal advice or a formal PIA/DPIA.

1 · Trigger and context

Start with the change, not the template

  • What product, service, process, or model is changing?
  • What personal information is collected, generated, inferred, or shared?
  • Whose information is involved, and could the use affect vulnerable people or eligibility?
  • What are the purpose, retention period, access path, and deletion trigger?
  • Which vendors, subprocessors, transfers, models, or systems receive the data?
  • What decision would stop launch, require conditions, or escalate to leadership?

2 · Evidence to assemble

Make the assessment reviewable

  • Evidence: Plain-language processing description and data-flow sketch
  • Evidence: Named product, privacy, security, and business owners
  • Evidence: Purpose, necessity, minimization, retention, and access notes
  • Evidence: Vendor, subprocessor, transfer, and contract review record
  • Evidence: Risk decision, conditions, remediation owner, and target date

3 · Decision and follow-through

Choose a documented path

Stop

The purpose, data boundary, owner, or risk is not clear enough to proceed.

Proceed with conditions

Launch depends on named controls, owners, evidence, and a tracked remediation date.

Proceed

The scope, safeguards, decision authority, and monitoring path are documented.

This worksheet is maintained by Mohammad Movahedi as part of the Movahedi Control Atlas. Confirm current legal requirements and obtain qualified advice for your facts and jurisdiction.