Does what you are building need an assessment first?
Article 35 of the GDPR requires a Data Protection Impact Assessment before certain processing begins. Not afterwards. The Irish Data Protection Commission has published a list of exactly which kinds, and 9 of its ten items are questions you can answer about your own business right now.
The list binds where a documented screening or preliminary risk assessment indicates the processing is likely to result in a high risk. This page is that screening. It says which items your answers put you on, and you can print the result as the record that you did it.
Two of them catch ordinary marketing work, which is the reason this page exists. Tracking what individual people do is on the list in its own right. So is joining data from separate systems to build a picture of individual customers, which is what a joined-up reporting setup does, including ours.
The answers stay in this tab and we never see them unless you ask us to email you the result. This is a screening against a published list, which is the first step of a DPIA and the only step that can honestly be automated. It is not the assessment and it is not legal advice.
FourWinds Digital · fourwindsdigital.com
Do you need a DPIA?
GDPR Article 35, and the Data Protection Commission's Article 35(4) list
A scoping result produced from the answers given on the page. It says which conversation you are in. It is not legal advice, and it is current as at the date it was printed.
This is a scoping result worked out from your own answers. It tells you which conversation you are in. It is not legal advice, and it is not a determination that you comply.
Optional, and nothing in the answer depends on it. It goes onto the result if you print it, so the document says who it was run for.
What was answered
0 of 9 answered.
Keep this result
Save it as a PDF or print it. It carries your own answers, the duties that follow from them and the article each one comes from, so it is something you can hand to a board, a client or a procurement team. Printing sends nothing anywhere and we never see it.
If the answer is yes
A DPIA is a document with a shape: what the processing is, why it is necessary and proportionate, what could go wrong for the people in it, and what you have done about that. It sits on top of your record of processing, which is why we write the record first and the assessment from it.
The other free checks: which AI Act duties you owe, whether the Cyber Resilience Act reaches you, and whether the Accessibility Act already applies.