Certus
← All services

DPIA Design & Execution

A structured, defensible Data Protection Impact Assessment methodology built into how projects actually get approved.

What it is

A repeatable methodology for identifying when a Data Protection Impact Assessment is required, running it properly, and embedding the decision into your project and change-approval process — not a one-off document written after the fact.

Why it matters

DPIAs done retroactively, after a system is already live, protect no one. Done well, a DPIA is what lets a CISO or DPO say "yes, and here is exactly what we did about the risk" — to a regulator, a board, or a worried customer.

What Certus does
  • Build a DPIA screening trigger into your project intake and procurement process.
  • Facilitate DPIA workshops with the business owner, not just paperwork completed in isolation.
  • Score residual risk and define concrete mitigations, with named owners and deadlines.
  • Establish an escalation path for high-risk processing that needs executive or DPO sign-off.
What you receive
  • A DPIA methodology and template calibrated to your risk appetite
  • A trained panel of facilitators who can run DPIA workshops independently
  • A live DPIA risk register with mitigation tracking
  • An escalation and sign-off framework for high-risk processing
Typical timeline

3–4 weeks to stand up the methodology; individual DPIAs typically run 1–3 weeks depending on complexity.

Who this is for

DPOs, project and product owners, and CISOs who need privacy risk assessed before launch, not discovered after.

How this differs from a generic consultancy

We build the DPIA into how decisions actually get made in your organisation — procurement, project approval, change control — rather than leaving it as a standalone compliance exercise nobody remembers to run.