Training module

Privacy Risk & Impact Assessment (DPIA)

Assess privacy risks, reason about impacts, and document DPIAs within an ISO/IEC 27701-aligned PIMS

Data ProtectionManagement System Manager
Silhouetted people in a blurred environment, representing privacy risk and impact assessment, DPIA decision-making, and structured privacy risk management within an ISO/IEC 27701-aligned PIMS.

Are your DPIAs systematic and defensible?

Learn how to build a repeatable privacy risk and impact assessment process that makes assumptions transparent and aligns treatment and residual risk decisions.

Overview

What this module is about

ISO/IEC 27701 sets explicit requirements for privacy risk assessment and treatment within a PIMS and is no longer dependent on ISO/IEC 27001 certification. In practice, organisations struggle less with “doing a DPIA” than with making the assessment logic repeatable: consistent triggers, defensible impact reasoning, documented assumptions, and clear decision rights for residual risk.

This module focuses on DPIA logic as a management-system capability in a PIMS: structuring assessments, reasoning about impacts on individuals, linking outcomes to treatment decisions, and keeping assessments current as processing changes. It does not teach privacy fundamentals, scoping/role determination, operational privacy controls, or data subject rights execution; those are addressed in adjacent specialisation modules. It also does not re-teach generic risk methodology (scales, scoring models, risk appetite design), which is owned by Risk Management Foundations.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

need a repeatable DPIA logic rather than ad-hoc assessments.

want clear triggers, roles, and decision ownership for DPIAs.

need defensible impact reasoning for approval and acceptance decisions.

want DPIAs to stay current as processing and systems change.

support audit-ready, consistent DPIA governance in a PIMS.

It may not be the best fit if you…

are looking for privacy fundamentals or legal theory.

want a generic risk methodology or scoring model.

expect detailed guidance on technical privacy controls.

already run stable, well-embedded DPIA processes at scale.

Agenda

What is taught

10 parts
01Where privacy risk assessment sits in a PIMS

How privacy risk assessment provides decision-ready inputs for treatment, control selection, and justification, rather than acting as a parallel compliance exercise

02Assessment boundaries and inputs

How to define clear assessment boundaries based on maintained processing context, roles, and scope artefacts, and avoid generic checklists or opinion-based inputs

03Trigger logic: when a DPIA-style assessment is needed

How to recognise practical change triggers that require deeper assessment and apply proportional triage between lightweight reviews and full DPIA-style assessments with defensible rationale

04Defining the assessment unit

How to structure assessments around concrete processing activities, so responsibility and outcomes remain clear

05Impact reasoning focused on individuals

How to reason about impacts on rights and freedoms using severity, scale, reversibility, and vulnerability, while keeping assumptions explicit and evidence-based

06Likelihood reasoning in privacy terms

How to trace causal chains from processing design choices to exposure and harm pathways, using credible indicators and uncertainty notes instead of false numerical precision

07Treatment logic and residual risk decisions

How to link assessment outcomes to treatment options, document decision rationale, and handle residual risk acceptance through clear decision rights, escalation paths, and consultation triggers

08DPIA documentation pack and traceability

How to maintain a minimal, coherent DPIA record set that supports traceability from assessment through decisions to implementation evidence

09Technology as an enabler

How to use registers, workflows, versioning, and AI-assisted summaries to keep assessments current and connected to change signals while preserving human judgement

10Case-based workshop

Applying the learned concepts, methods, and approaches in a realistic case setting

Outcomes

Learning outcomes

01

Explain how ISO/IEC 27701:2025 expects privacy risk assessment and treatment to function within a PIMS

02

Define DPIA trigger logic and proportionality rules that apply consistently across the organisation

03

Structure DPIA‑style assessments around real processing activities with shared services and suppliers

Apply a disciplined approach to impact reasoning on individuals and document assumptions transparently

Translate assessment outcomes into clear treatment decisions and residual risk acceptance criteria

Produce a maintainable DPIA documentation pack with traceability and review triggers so DPIAs stay current

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of Privacy Risk & Impact Assessment (DPIA) is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-DP-S-02
Discipline
Data Protection
Download fact sheet (PDF, 4.6 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Privacy Risk & Impact Assessment (DPIA) · HAM-DP-S-02

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Privacy Risk & Impact Assessment (DPIA) · HAM-DP-S-02

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.