# Data Privacy Impact Assessment

> From $20K · Compliance & GRC · https://cisomarketplace.services/services/data-privacy-impact-assessment

Systematic evaluation of data handling practices to ensure compliance with privacy regulations and identify potential privacy risks.

## In scope

- Data flow mapping
- Privacy risk assessment
- Consent mechanism review
- Data protection controls evaluation
- Third-party data sharing analysis

## Deliverables

- Privacy impact assessment report
- Risk mitigation recommendations
- Privacy control improvements
- Compliance gap analysis
- Implementation roadmap

## Tiers

### Small Organization DPIA: $20K

DPIA for an organization of up to 100 employees: up to 5 processing activities and up to 5 third-party data recipients. Data flow maps, privacy risk assessment, consent mechanism review, report with mitigations and roadmap.

Limits: employees 100, vendors 5

Includes:
- Data flow mapping for up to 5 processing activities
- Privacy risk assessment with rated risks
- Consent mechanism review
- Third-party sharing analysis for up to 5 recipients
- DPIA report, gap analysis and roadmap

Excludes:
- More than 5 processing activities
- Implementing the recommended controls
- Policy or notice drafting
- Regulator consultation

### Medium Organization DPIA: $35K

DPIA for up to 500 employees: up to 15 processing activities and up to 15 third-party data recipients. Same method as Small with workshops per business unit and a data protection controls evaluation per system.

Limits: employees 500, vendors 15

Includes:
- Data flow mapping for up to 15 processing activities
- Workshops with each business unit in scope
- Data protection controls evaluation per system
- Third-party sharing analysis for up to 15 recipients
- DPIA report, gap analysis and roadmap

Excludes:
- More than 15 processing activities
- Implementing the recommended controls
- Policy or notice drafting

### Large Organization DPIA: $55K

DPIA for up to 2,500 employees: up to 40 processing activities and up to 40 third-party data recipients, including cross-border transfers. Larger estates are scoped separately.

Limits: employees 2500, vendors 40

Includes:
- Data flow mapping for up to 40 processing activities
- Cross-border transfer analysis
- Data protection controls evaluation per system
- Third-party sharing analysis for up to 40 recipients
- Consolidated DPIA report with per-activity annexes
- Roadmap with owners

Excludes:
- Implementing the recommended controls
- Full privacy program build (see Data Privacy Compliance Program)
- Legal opinions

## Terms

Starting price shown is the lowest published tier. A written proposal fixes scope, tier and price before anything is signed. Timeline is set in the SOW.

Scope this engagement: https://cisomarketplace.services/scope?service=data-privacy-impact-assessment
