FNDDPIA Starter

Documents · Data

DPIA Starter

A data protection impact assessment your organization can adopt instead of writing from scratch.

Version
v1.0
In force since
24 July 2026
Last updated
24 July 2026
Contents
5 · 6 min read

In short

Processing children's data at scale usually calls for a DPIA under Art. 35.

This is ours, written from the processor's side, for you to adapt and sign.

Every risk is paired with the design decision that answers it.

  1. 1.Whose assessment this is

    The DPIA obligation under Art. 35 GDPR sits with the controller, which is your organization, not with us. What follows is the material only a processor can supply, laid out so a school or a municipality can adopt it, add its own context and sign it.

  2. 2.Necessity and proportionality

    The processing exists so that participants at one organization can see what is happening now and join it, and so staff can run the day. Each category of data in /ropa is tied to one of those two purposes; nothing is collected because it might be useful later.

    1. 2.1Less intrusive alternatives were considered: a paper schedule cannot be updated during a session, and a group chat has neither verification nor moderation.
    2. 2.2The most intrusive option, live location of participants, was rejected at design time and is not collectable in this system.
  3. 3.Risks and measures

    Risk to the participantMeasureResidual risk
    A stranger contacts a minorNo public sign-up, no discovery, verification in person by staff, no cross-organization visibilityLow: requires staff to verify the wrong person, which is a physical-world failure
    A child's whereabouts leakLive location is not collected; presence exists only as zone check-in events kept 30 daysVery low: the datum does not exist to leak
    Photos of minors spread outside the groupPhotos visible only inside the verified organization, no external links, cascade deletionLow: a participant can still photograph their own screen, which is a human problem
    Bullying inside the groupIn-app reporting to staff who know the people, automatic restriction on repeat reports, 30-day audit trailMedium: mitigated, not solved, by any software; staff involvement is required
    Unauthorised access to the databaseRow-level security per organization, MFA on production, encryption in transit and at restLow
    Data kept longer than neededPublished retention schedule, cascade deletion on revocation, 90-day deletion after a termLow
    Vendor lock-in or supplier failureExport on request, published continuity plan at /continuityMedium: inherent to a small supplier, addressed by the export commitment
  4. 4.Consulting the people affected

    Art. 35(9) asks the controller to seek the views of data subjects where appropriate. In practice that means asking participants and parents at your own organization; the plain-language material at /participants and /children exists so they can form a view without reading a contract.

  5. 5.Outcome

    In our assessment the residual risks are low enough that prior consultation with a supervisory authority under Art. 36 is not required. Your organization reaches its own conclusion, in its own context, and we will answer any question that stands between you and that conclusion within two business days.

Change log

  1. v1.024 July 2026

    • First published version.

Issued by

FND (Find 'n Do)

Belgium

Supervisory authority

Gegevensbeschermingsautoriteit / Autorité de protection des données

www.gegevensbeschermingsautoriteit.be

Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.

Write to us