Data Protection Impact Assessment (DPIA) under the JPDP Guideline
On 30 April 2026 the Personal Data Protection Department released its Data Protection Impact Assessment Guideline, alongside guidelines on data protection by design and on automated decision-making and profiling. The DPIA guideline sets quantitative thresholds, processing the personal data of more than 20,000 individuals or the sensitive personal data of more than 10,000, and qualitative triggers such as automated decision-making, children's data, systematic monitoring and decisions that affect a person's legal or financial position. It sets out a five-step method: describe the processing, evaluate its necessity and proportionality, identify the risks, consider the safeguards, and assess the residual risk that senior management must then accept or reduce. For banks, insurers, hospitals, telcos, e-commerce platforms and any organisation with a sizeable customer base, the question is no longer whether to do DPIAs but whether the ones you do would stand up.
This two-day course is built for the people who will run and sign off those assessments: DPOs, privacy and compliance teams, product owners and IT and data architects. Day one covers screening and the method step by step. Day two is practical, taking a live scenario from screening to a signed-off assessment and then wiring the DPIA into change management and vendor onboarding so it happens without being chased. It pairs with Data Protection by Design and Automated Decision-Making and Profiling, and the background is set out in our article on the three 2026 guidelines.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
Where the DPIA Sits in the Amended PDPA
The 2024 amendments, the seven PDPA principles, and how the three April 2026 guidelines fit together. What the DPIA guideline expects of the data controller and its DPO, and why a DPIA is the record that shows accountability after something goes wrong.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:30 AM
Screening: Does This Processing Need a DPIA?
The quantitative thresholds of 20,000 data subjects and 10,000 for sensitive personal data, and the qualitative triggers that apply regardless of volume, including automated decision-making and profiling, children's data, systematic monitoring and biometric processing. Building a screening questionnaire that product and project teams can complete themselves, and recording a decision not to proceed to a full DPIA.
Day 1, 11:30 AM - 12:30 PM
Step One: Describe the Processing
Data inventory, flows, systems, recipients, processors, retention and cross-border transfers for the activity being assessed. How much detail is enough, and the common failure of describing the system rather than the processing.
Day 1, 12:30 PM - 1:30 PM
Lunch
Day 1, 1:30 PM - 3:15 PM
Step Two: Evaluate Necessity and Proportionality
Testing purpose, data minimisation, retention, notice and choice, and data subject rights against the processing as designed. When consultation with data subjects or their representatives adds value, and how to record it.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
Step Three: Identify the Risks
Risks to individuals rather than to the organisation: loss, misuse, discrimination, financial harm, loss of control and chilling effects. Likelihood and severity scales that different assessors apply consistently, and worked examples from banking, healthcare, HR and retail.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Recap and what to review before day two.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Recap of day one and the questions it left open.
Day 2, 9:15 AM - 10:15 AM
Step Four: Consider the Safeguards
Technical, organisational and contractual measures, and how to show each one actually reduces a named risk. Security controls, pseudonymisation, access restriction, retention automation, human review, processor terms and transfer mechanisms.
Day 2, 10:15 AM - 10:30 AM
Break
Day 2, 10:30 AM - 12:30 PM
Step Five: Residual Risk, Sign-Off and Records
Assessing what is left, who in senior management accepts it, and what happens when the residual risk is too high to accept. The DPO's advice and how disagreements are recorded. DPIA records, retention and the review triggers that should reopen an assessment.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 3:15 PM
Making DPIA Routine
Embedding screening in project intake, change advisory boards, procurement and vendor onboarding. A DPIA register, metrics for the board, and how DPIA links to breach response and data protection by design.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:45 PM
Workshop: A Full DPIA on a Live Scenario
Teams take a realistic proposal, such as a customer loyalty app with location tracking or an AI-assisted hiring shortlist, from screening through all five steps to a sign-off recommendation, then present and defend it.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Screen proposed processing against the JPDP quantitative thresholds and qualitative triggers
- Run a DPIA through the five steps: describe, evaluate, identify, consider and assess
- Rate risks to individuals consistently and link each safeguard to the risk it reduces
- Present residual risk to senior management for an informed accept or reduce decision
- Keep DPIA records and know which changes should reopen an assessment
- Embed DPIA screening into project, change and vendor processes
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. For DPOs, privacy and compliance officers, product owners, IT and data architects, and risk managers. Basic PDPA knowledge assumed; attend DPO Basic first if new to the Act.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A completed DPIA on a supplied scenario, presented and defended in the workshop, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance