FillTrust

How to answer

Have you completed a Data Protection Impact Assessment (DPIA)?

Usually the controller's obligation, not yours. Saying so, and then supplying what theirs needs, is a better answer than either yes or no.

A model answerNot in your documents

As a processor we do not carry out DPIAs for our customers' processing. We provide the information controllers need to complete theirs: the categories of personal data we process, our subprocessors and their locations, our retention periods and our security measures. We have completed an internal assessment covering our own processing.

FillTrust grades an answer like this not in your documents when your documents support it.

Answered from
The assessment itself, if one exists. As a processor you have usually contributed to somebody else's rather than owned one.
Evidence to attach
The DPIA, or the section of it describing your processing. Often shared in summary rather than in full.
Where it is asked
CAIQ v4.0 · DSP-09SIG Lite

A DPIA is required when processing is likely to result in a high risk to people's rights and freedoms. The obligation sits with the controller. If your customer is the controller and you are the processor, they carry out the assessment and you are required to help them do it.

So answer the question they are actually asking. They are not usually checking whether you own a document. They are working out whether you can supply what their assessment needs without a three-week email exchange: what categories of personal data you process, for what purpose, who your subprocessors are and where they are, how long you keep it, and what safeguards you apply. A vendor who can hand that over as a single page is a vendor whose DPIA gets finished.

A security risk assessment is not a DPIA. They overlap and they are not the same document. A risk assessment asks what could go wrong for the business. A DPIA asks what could go wrong for the person whose data it is, and requires you to weigh necessity and proportionality against that. Presenting one as the other is a substitution a privacy reviewer notices immediately.

You may still owe one for your own processing. Employee monitoring, large-scale profiling, biometrics, systematic monitoring of a public space: these are your processing, not your customer's, and if you do any of them the obligation is yours. Most B2B SaaS does not, and saying "we have assessed our own processing and none of it meets the threshold" is a complete answer.

Share a summary, not the file. DPIAs frequently name individuals, describe internal disagreements and record decisions that were finely balanced. The part a reviewer needs is the description of the processing and the safeguards. Offer that first and the full document under NDA if they press.

If nobody has ever done one, say so and say what you rely on instead: the DPA, the subprocessor list, the security measures annexe. That is workable. Claiming an assessment that does not exist is not, because this is a document a serious reviewer will eventually ask to see.

How this one goes wrong

Specific to this question, not general advice.

  • Answering yes because you completed a security risk assessment. A DPIA is about risk to the people whose data it is, which is a different question from risk to the business.
  • Owning an obligation that is the controller's. If you process on a customer's behalf, they carry out the DPIA and your job is to give them what they need for it.
  • Sending the whole document. A DPIA often names individuals and describes internal decisions; a summary of the processing and the safeguards is what the reviewer needs.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.