DPIA Software

DPIA Software

How evidence-grounded drafting, human sign-off and linked risk records make Article 35 assessments defensible under the EU and UK GDPR.

See the DPIA module

The governed workflow

From threshold screen to signed assessment

A DPIA becomes defensible when the legal substance, risk judgement and DPO advice are recorded before processing proceeds.

01Screen
02Describe
03Assess
04Mitigate
05Approve
06Reuse

Screen for high risk

Record why a project does or does not need a full Article 35 assessment.

  • Article 35(3) triggers
  • DPC and ICO lists
  • EDPB criteria

Work the substance

Capture the Article 35(7) description, necessity analysis, risks and measures as structured decisions.

  • Processing description
  • Necessity and proportionality
  • Risk-to-individuals analysis

Record human judgement

Keep the residual-risk call, DPO advice and prior-consultation decision attributable.

  • Named sign-off
  • DPO advice
  • Article 36 trigger

Feed downstream records

Use approved DPIA answers to update RoPA fields, risk treatment and transfer follow-up.

  • RoPA updates
  • Risk register entries
  • Vendor and transfer review

DPIA software is the tool a privacy team uses to run the Article 35 Data Protection Impact Assessment required by the EU and UK GDPR. Useful DPIA software does more than fill in a template — it works the substance of the necessity-and-proportionality assessment, records where each answer came from, and keeps a named human accountable for the sign-off. That distinction — a tickbox form versus a defensible decision record — matters when someone asks why processing went ahead and what evidence supported the decision. This guide covers what DPIA software is, why it is a legal requirement, how it works, and what to check before choosing a tool.

Key takeaways

  • A DPIA is a legal obligation under Article 35 of the EU and UK GDPR wherever processing is likely to be high-risk; skipping a required one is independently sanctionable under Article 83(4)(a).
  • The real work is the Article 35(7) substance — a systematic description, a necessity-and-proportionality assessment, the risks to individuals, and the mitigations — not template tickboxes.
  • The test of DPIA software is provenance, not paperwork: can it show where each answer came from, who approved it, and what the residual-risk decision was — the questions a DPC or ICO inquiry asks.
  • The strongest tools connect the assessment: an approved DPIA feeds the Article 30 RoPA and risk register, complements an EU AI Act FRIA under Article 27, and is reusable across LIAs and TIAs — with a human deciding each outcome.

DPIA software turns Article 35 work into defensible decisions

DPIA software runs the Data Protection Impact Assessment — the structured evaluation the GDPR requires before processing that is likely to result in a high risk to individuals. A blank Word template can capture answers, but it stores only what someone last typed. DPIA software treats each assessment as a governed decision record: it carries the systematic description of the processing, the necessity-and-proportionality reasoning, the risks to individuals and their likelihood and severity, the mitigating measures, the recorded DPO advice and a named approver — and it knows where each of those answers came from.

That provenance is the point. When the Data Protection Commission (DPC) in Ireland or the Information Commissioner's Office (ICO) in the UK looks at a project file, the question is not “do you have a DPIA document” but “can you show the assessment was defensible, dated before the processing, and acted on.” Acompli treats the completed DPIA as source evidence rather than a one-off form: the approved assessment becomes a record that can be reused when the activity changes, a regulator asks, or a similar project starts later.

When is a DPIA required?

A DPIA is required before any processing “likely to result in a high risk to the rights and freedoms of natural persons” — Article 35(1) of the EU and UK GDPR. Article 35(3) then names three cases where one is required in particular; the list is illustrative, not exhaustive, so the practical first question a tool should answer is whether a project crosses the high-risk threshold at all.

The three Article 35(3) cases:

  1. Systematic and extensive evaluation or profiling by automated processing that produces legal or similarly significant effects for individuals.
  2. Large-scale processing of special-category data (Article 9) or of personal data relating to criminal convictions and offences (Article 10).
  3. Systematic monitoring of a publicly accessible area on a large scale.

Beyond those cases, the Article 29 Working Party's nine criteria (WP248 rev.01, endorsed by the EDPB) are the working test for “likely high risk”: in most cases a combination of two of the nine indicates a DPIA is needed, and in some cases one is enough. The nine are evaluation or scoring; automated decision-making with legal or similar effect; systematic monitoring; sensitive or highly personal data; large-scale processing; matching or combining datasets; data concerning vulnerable individuals; innovative use of new technology; and processing that prevents individuals exercising a right or using a service.

Each regulator also publishes its own list. Under Article 35(4) the Data Protection Commission (DPC) has adopted a list of ten types of processing operation that require a DPIA in Ireland where a screening assessment indicates likely high risk; the Information Commissioner's Office (ICO) publishes its own screening criteria for the UK. The defensible pattern is the same in both jurisdictions: a recorded threshold screen first— a short check against these triggers — and a full Article 35(7) assessment only where the screen indicates high risk. Acompli runs that screen as the first step, so a borderline project gets a documented decision on whether a DPIA is required rather than a guess, and the triggers are logged for audit-readiness. See the DPIA requirements guide for Ireland and the UK for the underlying detail.

DPIA software compared to a Word template and a generic GRC form

Most teams run a DPIA in one of three ways. The important difference is whether the assessment can show where each answer came from and who approved it when a supervisory authority opens the project file.

CapabilityWord / templateGeneric GRC form builderEvidence-grounded DPIA software (Acompli)
Article 35(7) fields as distinct, structured entriesFree textPartialYes
Article 35(4) screening against the DPC / ICO high-risk listNoSometimesYes
Per-field evidence traceability back to sourceNoNoYes
Recorded DPO advice (Article 35(2)) and named approverManualPartialYes, attributed
Article 36 prior-consultation trigger on high residual riskNoNoYes
Approved findings feed the Article 30 RoPA & risk registerNoRarelyYes
Self-contained export a DPC / ICO inquiry can readThe file itselfGenericYes, with the decision trail

Acompli is the right-hand column: the DPIA drafts with per-field citations and a named human approves the outcome, so the assessment is a defensible decision record rather than a document that records only what someone last typed.

The DPIA workflow in practice

The strongest DPIA software runs the assessment as a controlled workflow, so the substance is worked rather than improvised in a blank document. In Acompli the pipeline runs in four governed stages:

  • Screen: a structured template asks the Article 35(3)/(4) trigger questions first, so borderline projects get a documented decision on whether a DPIA is required rather than a guess.
  • Draft: the assessment starts from an Article 35(7) template and draws context from the organisational knowledge base; evidence-grounded AI drafting maps responses to each field with a per-field citation back to the source it came from.
  • Review: drafted answers enter a review queue where a named person can trace every field to its evidence, weigh the necessity-and-proportionality reasoning, and approve, edit or reject it before sign-off.
  • Carry through: approved findings flow downstream — into the Article 30 RoPA, the risk register and vendor reviews — and the assessment surfaces for re-review when an upstream fact changes.

This is the honest meaning of “DPIA automation”: automation reduces the typing, the chasing and the re-keying, not the accountability. Acompli's AI drafts, classifies and surfaces; a person approves the outcome, the residual-risk and DPO-advice decisions are recorded rather than assumed, and nothing publishes itself. (See the Acompli DPIA module for how the workflow runs in the platform.)

What to look for in a DPIA platform

Whatever the vendor, assess whether the tool can preserve the reasoning, evidence and approvals behind the assessment. The criteria that matter:

  • Full Article 35(7) coverage — the systematic description of processing, the necessity-and-proportionality assessment, the risks to individuals, and the measures that address them, as distinct fields rather than one free-text box.
  • Screening against the regulator's high-risk list — the Article 35(4) operations the DPC publishes for Ireland and the ICO's screening checklist for the UK, with the EDPB nine-criteria test applied.
  • Evidence traceability — every answer links back to the source response, system or contract that produced it, so a claim can be substantiated, not just asserted.
  • Recorded DPO advice — the Article 35(2) consultation captured as a dated decision, not an afterthought.
  • Reviewer-attributed version history — what changed, who changed it, who approved it, and when.
  • An Article 36 prior-consultation trigger — where a high residual risk remains after mitigation, the tool should flag the prior-consultation workflow rather than let the project proceed silently.
  • Downstream connections — approved outputs carried through to the Article 30 RoPA and the risk register, with a Schrems II transfer flag routing affected processing to a Transfer Impact Assessment.
  • A self-contained export — a record the DPC or ICO can read without a login to your platform.

For a structured side-by-side of DPIA tools against these criteria, see DPIA tools compared for Irish organisations. Acompli is built to each of these criteria: structured Article 35(7) fields, screening against the DPC and ICO lists, per-field evidence citations, recorded DPO advice, an Article 36 trigger on high residual risk, and approved findings that flow to the Article 30 RoPA and risk register.

Which type of DPIA software fits you?

Teams choosing a DPIA tool meet four broad types. The right one turns less on feature count than on whether the finished assessment is a defensible Article 35 decision record a regulator can follow.

Type of toolBest forStrengthsWatch-out
All-in-one privacy suiteLarge enterprises running DPIAs across many frameworksBroad module coverage in one platformThe DPIA is often a generic form, not structured to the Article 35(7) fields, and sits apart from the RoPA
Generic GRC / form builderTeams that want DPIAs inside a wider compliance toolConfigurable workflow and approvalsNot Article 35-specific, and rarely traces each answer back to the evidence behind it
Word template or questionnaireOccasional, low-volume DPIAs, or a first oneFree and familiarA static document — it cannot show where each answer came from or who approved it
Assessment-fed, provenance-led DPIA software (where Acompli sits)Privacy and DPO teams needing a defensible Article 35 decision recordArticle 35(7) fields, per-field evidence citations, human sign-off, and approved findings that flow to the Article 30 RoPABuilt for the governed-record use case, not a quick throwaway form

Who needs DPIA software?

Any organisation that runs processing likely to result in a high risk to individuals needs a DPIA. Privacy and DPO functions use DPIA software to make that assessment guided and repeatable; larger groups need entity-scoped assessments so each subsidiary can show its own supervisory authority a defensible record. The same evidence model also supports related LIAs, TIAs and EU AI Act work. In Acompli those assessments share one workflow and knowledge base, so a DPIA, LIA or TIA reuses the same approved evidence and approval trail rather than starting from a blank form.

Common questions about DPIA software

What is DPIA software?

DPIA software is the tool a privacy team uses to run the Data Protection Impact Assessment required by Article 35 of the EU and UK GDPR. Rather than work the assessment in a Word file, it treats each DPIA as a governed decision record — the systematic description of the processing, the necessity-and-proportionality assessment, the risk-to-individuals analysis, the mitigations and the DPO advice — with a named approver accountable for the outcome. In Acompli, the approved assessment becomes reusable evidence that can feed the Article 30 RoPA and the risk register instead of being re-typed.

Why do businesses need DPIA software?

Where processing is likely to result in a high risk to individuals, a DPIA is a legal obligation under Article 35 of the EU and UK GDPR — and failing to run one where it was required is independently sanctionable under Article 83(4)(a), separate from any later breach. DPIA software keeps that assessment defensible: it captures the Article 35(7) elements as dated decisions before processing begins, preserves the reasoning behind each answer, and produces the record a DPC or ICO inquiry can follow, rather than a free-text note that cannot show why processing went ahead.

How does DPIA software work?

Good DPIA software runs the assessment as a controlled workflow rather than a blank document. In Acompli a DPIA starts from a structured Article 35(7) template, draws context from the organisational knowledge base, and routes responses through evidence-grounded AI drafting where each drafted answer carries a link back to the source it came from; a named reviewer then traces, edits, approves or rejects every field before sign-off. The AI drafts, classifies and surfaces; a person approves the outcome — nothing publishes itself, and the residual-risk decision and DPO advice are recorded, not assumed.

What should DPIA software include?

A defensible DPIA workflow should cover the Article 35(7) fields (description, necessity and proportionality, risks to individuals, and mitigations), screen against the regulator's Article 35(4) high-risk list, trace each answer back to source evidence, record DPO advice under Article 35(2), preserve reviewer-attributed version history, trigger Article 36 prior consultation where unresolved high residual risk remains, and export a complete record the regulator can read. Approved outputs should also carry through to the Article 30 RoPA and risk register, so the assessment is connected to the wider compliance record rather than left as a standalone document.

How does an approved DPIA feed the Article 30 RoPA?

A completed DPIA already contains most of what an Article 30 RoPA entry needs: the purposes of processing, the categories of data and data subjects, recipients and third-country transfers, retention periods and the technical and organisational security measures. In Acompli, approved DPIA answers map directly into the matching Article 30 fields, so the RoPA reflects the assessed reality of the processing rather than a separately-maintained spreadsheet — and if the DPIA changes (a new supplier, a new transfer, a new lawful basis), the linked Article 30 record and the risk register move with it. The AI proposes the mapping; a person approves it.

Does DPIA software help with the EU AI Act FRIA?

It can, because the two assessments overlap. A high-risk AI system under Annex III of the EU AI Act is, in nearly every realistic case, also high-risk processing under GDPR Article 35 — systematic monitoring, automated decisions with significant effects, profiling or special-category data. The Fundamental Rights Impact Assessment that Article 27 of the AI Act requires of certain deployers does not replace the DPIA where personal data is processed; a well-built DPIA already covers much of the ground a FRIA reuses. Acompli's AI System Register is an opt-in early-access capability designed to surface Annex III flags into the DPIA workflow rather than run as a parallel form, so the classification connects back to the same processing activity — and a human, not the tool, decides the outcome.

Can a DPIA be reused across similar processing activities?

Yes, with care. Article 35(1) of the GDPR explicitly allows a single DPIA to address a set of similar processing operations that present similar high risks, and the DPC and ICO both recognise programme-level assessments. The reuse only holds where the risks, controls, lawful basis and affected individuals stay materially the same — a new transfer destination or change in data categories needs a fresh assessment or a documented delta. Because the underlying necessity-and-proportionality logic is the same as a Legitimate Interests Assessment or a Transfer Impact Assessment, good DPIA software lets an approved assessment be cloned and edited for a related LIA or TIA, with a clear audit trail of what changed rather than a one-off file.

Is DPIA software suitable for organisations of all sizes?

Yes. Any organisation that runs processing likely to result in a high risk to individuals needs a DPIA, and smaller organisations are not meaningfully exempt — the Article 35 obligation is keyed to risk, not headcount. Smaller teams benefit most from screening templates and evidence-grounded drafting that turn a daunting assessment into a guided workflow; larger groups need entity-scoped assessments and a defensible decision record each subsidiary can show its own supervisory authority. Acompli scales the same governed DPIA workflow from a single entity to a multi-entity group, with human sign-off the constant at every size.

What are the DPIA requirements in Ireland and the UK?

In both Ireland and the UK the DPIA obligation sits in Article 35 of the GDPR — in Ireland the EU GDPR applied through the Data Protection Act 2018, in the UK the UK GDPR applied through the Data Protection Act 2018. A DPIA is mandatory before any processing likely to result in a high risk to individuals, and each regulator publishes its own trigger list: the Data Protection Commission (DPC) maintains the Article 35(4) list of high-risk operations for Ireland, while the Information Commissioner's Office (ICO) publishes its own screening criteria for the UK, both read against the EDPB's nine-criteria test. The substance is the same in either jurisdiction — the Article 35(7) systematic description, necessity-and-proportionality assessment, risk analysis and mitigations, with DPO advice recorded under Article 35(2) and Article 36 prior consultation where high residual risk remains. Good DPIA software runs one assessment that satisfies both regulators and lets a multi-entity group show each supervisory authority its own defensible record. For the underlying legal detail, see the DPIA requirements guide for Ireland and the UK.

How should you choose DPIA software?

Choose DPIA software for the quality of the decision record it produces, not for the form design. A missing or inadequate DPIA is independently sanctionable under Article 83(4)(a) of the GDPR, which carries an administrative-fine ceiling of up to €10 million or 2% of total worldwide annual turnover, whichever is higher (the UK GDPR mirror is up to £8.7 million or 2%). A defensible tool should cover the Article 35(7) fields, screen against the regulator's high-risk list, trace each answer back to source evidence, record DPO advice under Article 35(2), preserve reviewer-attributed version history, trigger Article 36 prior consultation where unresolved high residual risk remains, and carry approved findings through to the Article 30 RoPA and risk register. Acompli is built around that standard: evidence-grounded AI drafts each field with a citation back to source and a named human approves the outcome.

How does DPIA software assess and score the risk?

A DPIA's core is an assessment of the risk to people's rights and a necessity-and-proportionality judgement — under Article 35(7) that is a reasoned decision, not a number a tool can produce on its own. Many tools present an automated risk score; the difficulty is defending an opaque figure to the DPC or ICO. Acompli structures the assessment instead: it captures the likelihood and severity of each risk, the necessity and proportionality of the processing and the mitigations, with evidence-grounded AI drafting and surfacing the inputs while a named reviewer decides the residual-risk rating and whether Article 36 prior consultation is triggered. The rating is the reviewer's reasoned call, recorded with the evidence behind it, so it holds up under scrutiny rather than reading as an algorithm's guess.

How does DPIA software handle the UK GDPR and the ICO?

Under UK GDPR Article 35, a DPIA is required before processing that is likely to result in a high risk to the rights and freedoms of individuals — the same obligation as the EU GDPR, but enforced by the Information Commissioner's Office (ICO) rather than the DPC. Three types of processing always require one under Article 35(3) — systematic and extensive automated profiling with significant effects, large-scale processing of special-category or criminal-offence data, and large-scale systematic monitoring of a public area — and the ICO has published its own Article 35(4) list of ten further high-risk types, including innovative technology such as AI, large-scale profiling, biometric and genetic data, data matching, invisible processing and tracking. The Data (Use and Access) Act 2025 left the Article 35 DPIA duty unchanged. Acompli runs the UK Article 35(7) assessment on the same governed workflow as the Irish one, screens against the ICO list, and produces a record the ICO can read — so a UK or cross-border group can show each regulator its own defensible DPIA.

What is the best DPIA software?

The best DPIA software is decided by how well it screens Article 35 triggers early, structures the four Article 35(7) contents with version control, records DPO advice and reviewer approvals, and preserves a defensible decision record a regulator can follow. Acompli's angle is to govern these as connected, human-approved records tied to the wider GDPR and EU AI Act programme - each assessment linked to its RoPA activity, risk register and supplier records, and each answer traceable to approved evidence. We would rather point you to a fair comparison than a claim: the DPIA software comparison guide and our full comparison library gather public-source evidence into capability matrices and vendor-by-vendor breakdowns, including the areas where rivals are stronger than Acompli.

Compliance software

Related compliance software guides

Pricing scales with your compliance estate — data controllers, legal entities, jurisdictions and integrations — never a per-seat price. See Acompli pricing.