vaulytica

Data Protection Impact Assessment (GDPR Art. 35) review

GDPR Art. 35 DPIA covering necessity, proportionality, risk assessment, and mitigations.

Review your document — free → See a sample report

What it checks

Systematic description of processing — Art. 35(7)(a)

DPIA must contain a systematic description of the envisaged processing operations and purposes.

Critical · PRV-021

Necessity and proportionality assessment — Art. 35(7)(b)

DPIA must assess the necessity and proportionality of processing in relation to the purposes.

Critical · PRV-022

Risk assessment — likelihood and severity

DPIA must assess the risks to the rights and freedoms of data subjects (likelihood × severity).

Critical · PRV-023

Mitigation measures and safeguards

DPIA must describe the measures envisaged to address the risks (technical, organisational, contractual).

Critical · PRV-024

DPO consultation

DPIA must record the DPO's advice (Art. 35(2)) and the controller's decision (whether followed).

Warning · PRV-025

Prior consultation trigger (Art. 36)

If residual high risk remains, DPIA must record the Art. 36 prior-consultation analysis.

Warning · PRV-026

Every run also applies 104 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.

Often reviewed with

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
  3. Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
Review your document — free →

More privacy & data protection documents

Every document type →