Data Protection Impact Assessment (GDPR Article 35)
The base: GDPR Article 35 for one processing activity, any sector.
One processing activity, screened against Article 35 and carried through to a prior-consultation decision — each risk scored for severity and likelihood before any safeguard is credited.
Ansvar is a gateway for the AI assistant your team already uses — Claude, Microsoft Copilot, any MCP client. Connect it and your agent runs the workflow; the server enforces the stages and fetches every citation.
A DPIA here is a staged interview, not a template you fill in. The run screens first: does Article 35 require an assessment at all, and on what basis. Then it takes the processing description, the DPO's position and your necessity-and-proportionality reasoning, enumerates the risks to data subjects for you to confirm, and scores each one on the CNIL severity and likelihood scale before crediting a single safeguard — and only safeguards you have actually built, since a planned control belongs in the recommendations rather than in the residual score. It closes on transfers, processors and an Article 36 determination: prior consultation, or not, with the reason recorded. The variants change the context the run reasons in — a supervisory authority's practice, or the aviation regime over aerial capture; the assessment itself is the same.
Data Protection Impact Assessment (GDPR Article 35)
The base: GDPR Article 35 for one processing activity, any sector.
Germany (BDSG-aware)
German practice, with competence split between the Land authority under § 40 BDSG and the BfDI.
Sweden (GDPR Art. 35 + IMY supervisory practice)
Swedish practice, reasoned against IMY as supervisory authority.
Drone / UAS Aerial Data Capture (GDPR Art. 35 + Reg (EU) 2019/947)
Aerial capture, where Article 35 meets Regulation (EU) 2019/947.
The supervisory authority a variant reasons against is part of its configuration, and each conclusion cites the provision it rests on. Where an authority publishes a mandatory-processing list we do not serve, the screening records that gap instead of reproducing the list from memory.
whether Article 35 bites, the processing description, the DPO's position, necessity and proportionality
data-subject views recorded, risks enumerated, and the list confirmed by you before anything is scored
one step per risk: the rights affected, CNIL severity and likelihood, then the safeguards that reduce it
transfers, processors, and the Article 36 determination on prior consultation
the assessment and its risk register — structured for your agent, rendered for your auditor
Using Ansvar, run a GDPR Article 35 DPIA for our new HR analytics platform. Screen it first, then take it through to the prior-consultation determination.
Using Ansvar, which DPIA workflow types can I start, and which supervisory authority does each one reason against?
Free gets one workflow run a month and Solo two, spendable on the base DPIA against a processing activity you describe, and a Free or Solo run can also return a render carrying a self-asserted banner. Premium adds the German, Swedish and drone variants on five runs a month. Team and Company run them against records you upload and add unwatermarked HTML, PDF and DOCX exports. Run allowances and what each tier adds live on the pricing page.
Every workflow here is also an expert-run service: we run it against your systems, review the output as practitioners, and hand over the finished deliverable. See the services page for how engagements work, or contact us to scope one.
Related: Free DPIA template · Worked DPIA run · STRIDE threat model · Privacy sector · Drone & UAS sector · Vendor DPA directory · Workflow docs · Have us run it
Connect the AI client you already use and ask your first cited question — Free, Solo, Premium and Team are self-serve.