Documents · Data
DPIA Starter
A data protection impact assessment your organization can adopt instead of writing from scratch.
In short
Processing children's data at scale usually calls for a DPIA under Art. 35.
This is ours, written from the processor's side, for you to adapt and sign.
Every risk is paired with the design decision that answers it.
1.Whose assessment this is
The DPIA obligation under Art. 35 GDPR sits with the controller, which is your organization, not with us. What follows is the material only a processor can supply, laid out so a school or a municipality can adopt it, add its own context and sign it.
2.Necessity and proportionality
The processing exists so that participants at one organization can see what is happening now and join it, and so staff can run the day. Each category of data in /ropa is tied to one of those two purposes; nothing is collected because it might be useful later.
- 2.1Less intrusive alternatives were considered: a paper schedule cannot be updated during a session, and a group chat has neither verification nor moderation.
- 2.2The most intrusive option, live location of participants, was rejected at design time and is not collectable in this system.
3.Risks and measures
Risk to the participant Measure Residual risk A stranger contacts a minor No public sign-up, no discovery, verification in person by staff, no cross-organization visibility Low: requires staff to verify the wrong person, which is a physical-world failure A child's whereabouts leak Live location is not collected; presence exists only as zone check-in events kept 30 days Very low: the datum does not exist to leak Photos of minors spread outside the group Photos visible only inside the verified organization, no external links, cascade deletion Low: a participant can still photograph their own screen, which is a human problem Bullying inside the group In-app reporting to staff who know the people, automatic restriction on repeat reports, 30-day audit trail Medium: mitigated, not solved, by any software; staff involvement is required Unauthorised access to the database Row-level security per organization, MFA on production, encryption in transit and at rest Low Data kept longer than needed Published retention schedule, cascade deletion on revocation, 90-day deletion after a term Low Vendor lock-in or supplier failure Export on request, published continuity plan at /continuity Medium: inherent to a small supplier, addressed by the export commitment 4.Consulting the people affected
Art. 35(9) asks the controller to seek the views of data subjects where appropriate. In practice that means asking participants and parents at your own organization; the plain-language material at /participants and /children exists so they can form a view without reading a contract.
5.Outcome
In our assessment the residual risks are low enough that prior consultation with a supervisory authority under Art. 36 is not required. Your organization reaches its own conclusion, in its own context, and we will answer any question that stands between you and that conclusion within two business days.
Change log
v1.024 July 2026
- First published version.
Issued by
FND (Find 'n Do)
Belgium
Supervisory authority
Gegevensbeschermingsautoriteit / Autorité de protection des données
Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.
Write to us