Svenska Dokumentmallar
DPIA / Data Protection Impact Assessment GDPR Template Package 2026 – Word/PDF/Excel
DPIA / Data Protection Impact Assessment GDPR Template Package 2026 – Word/PDF/Excel
Downloading the template is available immediately after purchase. Our document templates are always delivered in customizable formats.
If you are unsure which template is appropriate or how you should complete it, please see the relevant information under the 'Legal Information' tab in our main menu.
Our templates are designed in accordance with current legislation and practice in each area to ensure that the documents you create are legally correct.
Couldn't load pickup availability
DPIA / Data Protection Impact Assessment GDPR Template Package 2026 – Word, PDF & Excel
Complete template package for Data Protection Impact Assessment (DPIA) according to Article 35 of the GDPR. The package is designed for Swedish companies, organizations, authorities, project managers, data protection officers, information security functions, and lawyers who need to document high-risk processing of personal data in a structured, auditable, and practical manner.
The package combines four professional document templates in Word/PDF with a comprehensive Excel tool for screening, risk assessment, risk-mitigating measures, consultation, Article 36 assessment, and ongoing review. A total of 9 files are included.
What is included – 9 files
- DPIA / Data Protection Impact Assessment GDPR 2026 – Word (DOCX)
- DPIA / Data Protection Impact Assessment GDPR 2026 – PDF
- DPIA Screening / Need Assessment – Word
- DPIA Screening / Need Assessment – PDF
- Consultation, DPO Opinion & Prior Consultation – Word
- Consultation, DPO Opinion & Prior Consultation – PDF
- DPIA Review, Decision & Change Log – Word
- DPIA Review, Decision & Change Log – PDF
- DPIA Risk & Screening Work Tool – Excel (XLSX)
When is a DPIA required?
According to Article 35 of the GDPR, the controller must carry out a data protection impact assessment before starting a type of processing if the processing is likely to result in a high risk to the rights and freedoms of natural persons. This applies particularly to, for example, extensive profiling or automated decision-making with significant effects, large-scale processing of sensitive personal data or data relating to criminal convictions, and large-scale systematic monitoring.
Furthermore, the Swedish Authority for Privacy Protection (IMY) has a specific list according to Article 35.4 and uses the nine high-risk criteria developed in European data protection guidelines. As a general rule, at least two fulfilled criteria indicate that a DPIA should be carried out, but a single criterion may suffice in an individual case. The screening template and the Excel tool are built to document exactly this assessment.
Screening / need assessment
The screening template helps you document, before project start, why a DPIA is required – or why it is not considered mandatory. It includes checks of:
- Article 35.3 of the GDPR
- IMY's Article 35.4 list
- evaluation and scoring
- automated decision-making with significant effects
- systematic monitoring
- sensitive or highly personal data
- large-scale processing
- merging of datasets
- vulnerable data subjects
- innovative use or new technology, including AI
- processing that prevents a person from exercising a right or gaining access to a service or contract
Complete DPIA according to Article 35
The main template is designed to document the elements required by the GDPR and highlighted by IMY in its guidance. It includes, among other things:
- systematic description of the processing and its purposes
- data subjects and personal data categories
- sensitive personal data and Article 10 data
- systems, technology, AI, profiling, and automated decision-making
- data processors and recipients
- third-country transfers
- storage and erasure
- data flow and lifecycle
- legal basis
- assessment of necessity and proportionality
- privacy by design and privacy by default
- risks to the rights and freedoms of individuals
- risk-mitigating technical, organizational, and legal measures
- residual risk
- decision on whether the processing can begin
- need for prior consultation with IMY
- plan for ongoing review
The risks concern people – not the company's business risk
A common weakness in DPIA work is that the risk analysis drifts into business risk. The template therefore explicitly distinguishes between these areas. The DPIA risk must concern how the processing could affect the rights and freedoms of natural persons, for example through discrimination, identity theft, financial loss, reputation damage, loss of confidentiality, improper surveillance, incorrect profiling, limited self-determination, or other physical, material, or non-material damage.
Excel tool with automatic risk classification
The Excel file contains separate worksheets for:
- dashboard with key performance indicators
- DPIA screening
- processing description
- necessity and proportionality
- risk register
- risk measures
- consultation and DPO advice
- review and change log
- Article 36 – documentation for prior consultation
- legal sources and guidance
The risk register automatically calculates a risk value based on probability and impact and shows both inherent risk and residual risk after planned measures. This makes it easier to track how protective measures actually change the risk landscape.
The role of the Data Protection Officer
If the organization has a data protection officer (DPO), the DPO must be consulted during the implementation of the DPIA. The DPO can, among other things, provide advice on the need for a DPIA, methodology, risks, protective measures, and whether the assessment has been carried out correctly. However, it remains the controller's responsibility to ensure that the DPIA is carried out and for the decisions made.
The package therefore contains a separate template for DPO opinion and consultation where advice, deviations, and follow-up can be documented clearly.
Views of data subjects
The GDPR also implies that the views of data subjects or their representatives should be sought when appropriate. The consultation template therefore contains specific fields for methodology, participants, views, how the views have been considered, and – if consultation is not carried out – why it was not appropriate or possible.
Article 36 – prior consultation with IMY
If the DPIA shows that the processing would still entail a high risk despite planned risk-mitigating measures, the controller must request prior consultation with IMY before starting the processing. The package includes both document fields and a specific Excel sheet to verify that the documentation is complete before such an assessment or request is made.
DPIA is an ongoing process
The impact assessment should not be archived and forgotten after the project start. IMY describes the DPIA as an ongoing process. A new or updated assessment may be needed if, for example, purposes, data categories, number of data subjects, systems, AI functionality, suppliers, recipients, third-country transfers, or security risks change.
The separate template for review, decision, and change log makes it possible to document these changes and verify that the actual processing still matches the decided DPIA.
Particularly suitable for
- new IT systems and SaaS services
- AI and automated analysis
- profiling and scoring
- HR and personnel systems
- camera and sensor solutions
- health and other sensitive personal data
- large-scale customer and user databases
- merging of various data sources
- new cloud providers or third-country transfers
- processing of data of children or other vulnerable groups
Legal basis
The package is legally reviewed as of October 3, 2026, and is based, among other things, on:
- the General Data Protection Regulation (EU) 2016/679, particularly Articles 5, 6, 9, 10, 25, 32, 35, 36, and 39
- IMY's guidance on impact assessment and practical guide
- IMY's list according to Article 35.4
- EDPB/WP29 Guidelines on Data Protection Impact Assessment, WP248 rev.01
In 2026, the EDPB presented a new proposal for a common European DPIA template for public consultation. However, this product is not dependent on a draft consultation not yet finalized, but is based primarily on the current GDPR and IMY's current Swedish guidance.
Please note
The templates are general compliance documentation. They do not replace an actual analysis of the planned processing or individual legal advice. A correct DPIA must be based on actual systems, data flows, purposes, suppliers, data subjects, risks, and protective measures. Special sector rules may also need to be considered.
Format: Word (DOCX) + PDF + Excel (XLSX)
Language: Swedish
Jurisdiction: Sweden / EU
Number of files: 9
Version: 1.0 – 2026-10-03
Share



