Ensure your DPIA reflects your ROPA automatically
Scope it to the processing activity or system you are assessing, and the ROPA records behind it enter the assessment on their own — nobody rebuilds the data map inside the questionnaire
Entity-tagged questions — questions tagged to an entity in scope appear in the assessment on their own. So for example, a DPIA on a lending journey asks lending-journey questions without anyone needing to assemble them
Avoid unnecessary DPIAs with a preliminary assessment
Preliminary assessment — send a short set of questions about the processing and its impact on data principals before committing anyone to the full DPIA
Recorded yes/no decision with mandatory written justification, stored in Result History — easy to show to auditors
Run the DPIA with the right questions and the right people
Templates and a central question library
Load a pre-built DPIA template, or build your own set once and reuse it on every DPIA you run.
No juggling email threads
Responders attach evidence against the question it answers, and you review it all on the platform.
Per-question responders
Assign specific questions to specific teams or owners, so only the relevant POCs are answering.
Turn every DPIA finding into a scored risk
Risk register updates in real time — when a respondent answers a question in a way that violates your risk rule, it gets flagged instantly. You don't need to wait for the full questionnaire to be filled
Inherent, target and residual scores on every risk, on a 1–10 scale or a 5×5 Impact × Probability matrix with severity bands you configure
Re-run the DPIA when the processing changes, and on cycle
Periodic DPIA review
Run repeat cycles on the same processing activity to fulfil your SDF and internal obligations.
Re-run a DPIA on the same entity
The next cycle runs on the same template and responders, without rebuilding the assessment.
A dated record per cycle
An auditable, timestamped record of the DPIA each round.
Execute the DPA and assess the processor, in one flow
DPA drafting and negotiation — draft the DPA or an amendment from a template, negotiate it with the processor, compare versions to see exactly what changed, and route it through your review workflow
eSign and digital stamping — execute the DPA with Aadhaar eSign or DSC, with stamping handled in the same journey
The assessment runs off the executed contract — once the DPA is signed, the assessment on that processor starts from the same flow, so the contract and the check on whether it is being honoured are not two separate projects
See your own questionnaire running in Consentin
Bring your current assessment questionnaire to a 30-minute walkthrough. We’ll build it in the platform, send it to a test responder, and show you the risks landing in the register.
Frequently asked questions
What is a DPIA under India's DPDP Act?
A Data Protection Impact Assessment is a review you run when you launch or change high-risk processing of personal data. You run one each time a high-risk journey launches or changes, not once a year.
What is the difference between a DPIA and a DPDP gap assessment?
A gap assessment is a one-time review of your current state against the Act, usually at the start of a compliance programme and usually done by a consultant. A DPIA is ongoing and specific to a processing activity. Consentin runs DPIAs and vendor assessments; it does not run your gap assessment.
Who has to run periodic DPIAs?
A Significant Data Fiduciary carries the periodic DPIA duty as a standing obligation. Every other Data Fiduciary runs a DPIA when high-risk processing launches or changes — which, for an organisation shipping new journeys, works out as a recurring obligation too.
Is a DPIA the same as a PIA?
In practice, yes — the two names describe the same exercise, and Indian RFPs use them interchangeably. Consentin's assessment type is named DPIA.
Do we have to start from your DPIA template?
No. Load a pre-built DPIA template, edit one, or build your own set from the central question library and reuse it on every DPIA. Questions tagged to a processing activity or system also load on their own when that entity is in scope.
How does a DPIA connect to our ROPA?
Scope the assessment to a Processing Activity, System, Purpose, Profile or Data Category, and the ROPA records behind that entity enter the assessment's scope automatically, along with any questions tagged to it. The link runs one way — a DPIA does not create ROPA records.
How much of the DPIA is automated?
Creation and risk tracking. Scope and questions populate themselves from your ROPA, and risks are created, scored and banded automatically by rules on the answers. The answers themselves come from people — responders, evidence and your review.
What record does a DPIA leave for an audit or a DPB inspection?
The assessment itself: every question, every response with the evidence attached to it, your review comments, the preliminary decision with its written justification, and every risk with its scores, owner and mitigation proof. Consentin does not currently generate a downloadable DPIA report file — the record lives in the platform.
Can we assess a processor as soon as we sign the DPA?
Yes. The DPA is drafted, negotiated and executed in Leegality with Aadhaar eSign or DSC and digital stamping, and the assessment on that processor runs from the same flow — so the contract and the first check on it are one piece of work.