Screening
A short, documented decision on whether the activity needs a full DPIA, tested against the guideline's thresholds and qualitative triggers. A recorded decision not to proceed is evidence too, and most organisations never keep it.
Every new system, vendor and AI use case is now a question: does this need a DPIA? Since JPDP's DPIA Guideline in April 2026, the answer is often yes, and the assessment has to stand up when someone reads it after something goes wrong. We screen, assess and document, so your projects keep moving and the record holds.
A DPIA delivery service. For each proposed processing activity, we screen it against the JPDP thresholds and triggers, run the full five-step assessment where one is needed, and hand senior management a residual risk decision they can actually make. We can do this for a single project or as a standing arrangement that handles the assessments as they arise.
The DPIA Guideline released by JPDP on 30 April 2026 sets quantitative thresholds, processing the personal data of more than 20,000 individuals or the sensitive personal data of more than 10,000, and qualitative triggers that apply at any volume, including automated decision-making and profiling, children's data, systematic monitoring and decisions affecting a person's legal or financial position. Most organisations have the policy. Far fewer have the time, method or independence to run assessments that would survive scrutiny, and projects stall while the DPIA waits for someone to write it.
Priced per assessment or as a standing arrangement. An organisation-wide PDPA audit is a different product; see Data Protection Solutions.
A short, documented decision on whether the activity needs a full DPIA, tested against the guideline's thresholds and qualitative triggers. A recorded decision not to proceed is evidence too, and most organisations never keep it.
The data, the flows, the systems, the processors, retention and any cross-border transfer, for the activity being assessed rather than the system in general. This is where most DPIAs go wrong.
Testing purpose, minimisation, retention, notice and choice, and data subject rights against the processing as designed, while there is still time to change the design.
Identifying and rating the harm to the people whose data it is, not only the risk to the organisation, on scales that give consistent results from one assessment to the next.
Linking each technical, organisational and contractual safeguard to the risk it reduces, then presenting what remains to senior management for an informed accept or reduce decision.
A register of every screening and assessment, owners, sign-off dates and the triggers that should reopen each one, so assessments stay current when systems and vendors change.
A DPIA that sits in someone's queue delays a launch. A standing arrangement means assessments start when the project does, with an agreed turnaround.
After a complaint or a breach, the DPIA is the first document asked for. One that follows the guideline's method and records real decisions is evidence of accountability. A template with the blanks filled is not.
The people building a system are the worst placed to assess it. An outside assessor asks the uncomfortable questions early, when changing the design is still cheap.
Residual risk is presented in plain terms with options, so the accept or reduce decision the guideline expects is a real decision rather than a signature.
Automated decision-making is a DPIA trigger at any volume. We assess AI and profiling use cases against the ADMP guideline as well, so the two records agree.
Where you want the capability in house, our two-day DPIA course is HRD Corp claimable and uses the same method we apply, so the handover is seamless.
You tell us about the project, system, vendor or use case. We agree who we need to speak to and the turnaround.
A documented decision on whether a full DPIA is needed, and why. If not, the screening record is filed and the project moves on.
Workshops with the business owner, IT and your DPO, working through the five steps: describe, evaluate, identify, consider and assess.
Safeguards linked to risks, with owners and effort, and any design changes that would materially reduce risk.
A residual risk summary for senior management, with the DPO's advice recorded, and the decision filed in the register.
Reopening the assessment when a review trigger fires, such as a new data type, a new vendor or a model change.
A documented decision against the guideline's thresholds and triggers, for every activity screened.
The five-step assessment for the activity, with data flows, risk ratings and the safeguards linked to each risk.
Recommended safeguards with owners, effort and priority, ready to feed into the project plan.
A short paper for senior management setting out what remains and the accept or reduce options.
Every screening and assessment, its owner, sign-off and the triggers that reopen it.
A questionnaire your project teams can complete themselves, so the right activities reach assessment.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
Under the JPDP DPIA Guideline of 30 April 2026, when it involves the personal data of more than 20,000 individuals or the sensitive personal data of more than 10,000, or when a qualitative trigger applies at any volume, such as automated decision-making or profiling, children's data, systematic monitoring or decisions affecting a person's legal or financial position. Screening is how you document the answer either way.
An audit looks at the whole organisation against the Act. A DPIA looks at one processing activity, usually before it launches, and asks whether the risk to individuals is acceptable. You need both, and they are priced and scoped differently.
It depends on the activity. A screening is usually a short exercise. A full assessment of a new customer-facing system or AI use case needs workshops with the business, IT and your DPO, and the elapsed time is driven mostly by how quickly those people are available.
Senior management accepts or reduces the residual risk. Your DPO advises, and where the DPO disagrees, that advice is recorded. We prepare the assessment and the summary; the decision stays with your organisation.
Often yes. Automated decision-making and profiling are DPIA triggers under the guideline regardless of volume, and the separate ADMP guideline adds transparency and consent points. We assess both together so the records agree.
Yes, and many should for routine changes. Our two-day DPIA course is HRD Corp claimable and uses the method we apply, and some clients use us only for the high-risk or contentious assessments.
Tell us what you are launching or changing, what data it uses and when it needs to go live. We will come back with a screening view, the scope of any full assessment and a fixed quotation.