REVIEW-READY DRAFT — GBOS-specific and factual, but NOT final and NOT legal advice. Must be confirmed by a qualified solicitor before GBOS relies on it (see the [SOLICITOR TO CONFIRM] items).

Data Protection Impact Assessment (DPIA) — Template

Version 2026-08-r1 · Effective 2026-08-02

A template to assess and mitigate privacy risk for high-risk processing.

1. Describe the processing

Nature, scope, context and purposes of the processing. Data categories, data subjects, volumes, retention, recipients (including sub-processors) and any international transfers. For GBOS this typically covers multi-tenant hosting of finance, contacts and document records.

2. Necessity and proportionality

Lawful basis; how the processing achieves the purpose; data minimisation; accuracy; storage limitation; and how data-subject rights (access, export, deletion) are supported — GBOS provides governed export and governed deletion tooling.

3. Identify and assess risks

For each risk to individuals: likelihood and severity (low/med/high). Consider unauthorised access, cross-tenant leakage, excessive retention, profiling, and re-identification. Note GBOS’s independent database-layer tenant isolation as a key mitigating control against cross-tenant leakage.

4. Mitigations

Controls to reduce each risk: database-enforced tenant isolation (RLS, fail-closed), least-privilege access, HMAC-keyed append-only audit trail, MFA + server-verified step-up, encryption in transit, retention limits, versioned consent capture, and export/deletion tooling. Record residual risk after mitigations.

5. Sign-off

Reviewer, DPO advice (if appointed), decision to proceed, and review date. [SOLICITOR TO CONFIRM] whether prior consultation with the ICO is required where high residual risk remains, and complete this template per high-risk processing activity.

Clauses a solicitor must confirm

The following points in this document require qualified legal sign-off before GBOS relies on it.

  • Whether a DPIA is mandatory for the platform’s processing and which activities trigger it.
  • Sign-off authority and whether prior ICO consultation is needed for any residual high risk.

This document is a GBOS-specific, review-ready draft. It is not final and does not constitute legal advice; it must be confirmed by a qualified solicitor (see the clauses flagged above) before GBOS relies on it.