AdvancedjuridicoFree prompt

Personal Data Protection Impact Report (DPIA)

Drafts a Data Protection Impact Report as required by LGPD for high-risk data processing activities.

Produce a DPIA that complies with Article 38 of the LGPD and ANPD guidelines, mapping risks and mitigation measures for sensitive personal data processing.

At a glance

Access

Free prompt

Open to copy without upgrading.

Prompt objective

Produce a DPIA that complies with Article 38 of the LGPD and ANPD guidelines, mapping risks and mitigation measures for sensitive personal data processing.

Real use case

FinCredit, a credit analysis fintech in São Paulo, needs to prepare a DPIA for its new product that uses artificial intelligence for credit scoring based on behavioral social media data, before the ANPD regulates AI in data processing.

Customize these fields first

COMPANY NAMEPROCESSING DESCRIPTIONPURPOSELIST TYPESYES/NO — specify whichNUMBERLEGAL BASISYES/NO — specify parties

Replace the placeholders with your own context before you run the prompt. That usually improves the first output more than adding more instructions later.

Prompt

Draft a Personal Data Protection Impact Report (DPIA) for [COMPANY NAME], concerning personal data processing in the context of [PROCESSING DESCRIPTION].\\\\\\\\n\\\\\\\\n**Processing Information:**\\\\\\\\n- Purpose: [PURPOSE]\\\\\\\\n- Personal data collected: [LIST TYPES]\\\\\\\\n- Sensitive data (Art. 5, II): [YES/NO — specify which]\\\\\\\\n- Estimated number of data subjects: [NUMBER]\\\\\\\\n- Legal basis used (Art. 7 or 11): [LEGAL BASIS]\\\\\\\\n- Third-party sharing: [YES/NO — specify parties]\\\\\\\\n- International transfer: [YES/NO — destination countries]\\\\\\\\n- Automated decision-making: [YES/NO]\\\\\\\\n\\\\\\\\n**DPIA Structure (per Art. 38, LGPD and ANPD guidelines):**\\\\\\\\n\\\\\\\\n1) **Controller and DPO Identification**:\\\\\\\\n   - Full contact details for both\\\\\\\\n   - Person responsible for preparing the DPIA\\\\\\\\n\\\\\\\\n2) **Description of Processing**:\\\\\\\\n   - Nature: what is done with the data\\\\\\\\n   - Scope: data categories, volume, frequency\\\\\\\\n   - Context: why the processing is necessary\\\\\\\\n   - Purpose: specific and legitimate objective\\\\\\\\n   - Data flow: diagram from collection to disposal\\\\\\\\n\\\\\\\\n3) **Necessity and Proportionality**:\\\\\\\\n   - Applicable legal basis and justification\\\\\\\\n   - Data minimization principle: collecting only what is necessary?\\\\\\\\n   - Is there a less invasive alternative?\\\\\\\\n   - Relationship between purpose and data collected\\\\\\\\n\\\\\\\\n4) **Stakeholders and Consultations**:\\\\\\\\n   - Data subjects: consulted? How?\\\\\\\\n   - DPO: technical opinion\\\\\\\\n   - Legal: regulatory compliance\\\\\\\\n   - IT: technical feasibility of security measures\\\\\\\\n\\\\\\\\n5) **Risk Assessment** (matrix format):\\\\\\\\n   - Unauthorized access risk\\\\\\\\n   - Data breach/security incident risk\\\\\\\\n   - Misuse by third parties risk\\\\\\\\n   - Algorithmic discrimination risk (if automated decisions involved)\\\\\\\\n   - Harm to data subjects (material and moral)\\\\\\\\n   - For each risk: likelihood × impact × classification\\\\\\\\n\\\\\\\\n6) **Mitigation Measures**:\\\\\\\\n   - Technical: encryption, pseudonymization, access controls\\\\\\\\n   - Organizational: training, policies, periodic review\\\\\\\\n   - Legal: data processor contracts, confidentiality clauses\\\\\\\\n   - For each risk: mitigating measure + residual risk\\\\\\\\n\\\\\\\\n7) **Conclusion and Recommendations**:\\\\\\\\n   - Opinion on processing feasibility\\\\\\\\n   - Conditions and restrictions\\\\\\\\n   - Action plan with timeline\\\\\\\\n\\\\\\\\n8) **Signatures and Approval**\\\\\\\\n\\\\\\\\nBase this document on Law 13.709/2018 (LGPD), Arts. 5, 7, 11, 38 and 55-J, and ANPD guidance on DPIAs.

Open directly in an AI — the text is pre-filled:

How to use this prompt

  1. 1Replace the key placeholders first: COMPANY NAME, PROCESSING DESCRIPTION, PURPOSE, LIST TYPES.
  2. 2Replace any bracketed placeholders like [this] with your own context.
  3. 3Add extra background information when you want more tailored results.
  4. 4Combine multiple prompts in one conversation when you need a richer output.
  5. 5Save your best-performing prompts so they are easy to reuse later.

Next best step

Open the guide first, then branch only if you still need more.

A guide for choosing prompts, tools, courses, and workflows without creating expensive tool sprawl.

If this prompt is close but not quite right, generate variants next. If the job is recurring, move into the course library after the guide.

Related prompts

View all

SaaS Licensing Agreement with SLA and Data Protection Clauses

Generates a complete SaaS licensing agreement template adapted to Brazilian law, including SLA terms, data processing, and intellectual property provisions.

AdvancedFree prompt

Best for

Draft a SaaS service agreement that protects both provider and client, compliant with the Brazilian Civil Code, Internet Framework Law, and LGPD (Brazil's data protection law).

Copy-ready promptOpen prompt

Mutual NDA for Business Negotiations

Creates a robust mutual non-disclosure agreement to protect sensitive information during negotiations between businesses.

IntermediateFree prompt

Best for

Draft an NDA that protects both parties in commercial negotiations, M&A deals, or strategic partnerships, compliant with Brazilian Civil Code and Industrial Property Law.

Copy-ready promptOpen prompt

Professional Services Agreement with Defined Scope and Scope Creep Protection

Generates a professional services contract with clear scope delimitation, change request mechanisms, and formal acceptance procedures.

IntermediateFree prompt

Best for

Protect service providers from informal scope expansion (scope creep) by establishing formal change procedures.

Copy-ready promptOpen prompt

Commercial Partnership Agreement (Joint Venture) Between Companies

Draft a commercial partnership or joint venture agreement with clear governance rules, profit-sharing, and exit mechanisms.

AdvancedFree prompt

Best for

Structure a commercial partnership or joint venture legally, defining responsibilities, investments, governance, and dissolution mechanisms.

Copy-ready promptOpen prompt

Explore other prompt categories

Move sideways into adjacent libraries when the current category is not the full answer.

Free browsing stays open. Premium prompts unlock the reusable workflow layer.

Use the guides and role paths to validate the job first. Upgrade when you want the full prompt text, editable premium prompts, and the surrounding course paths in one place.

Free access

  • Browse guides, role paths, and category pages.
  • Preview prompts before you decide to upgrade.
  • Find the right starting point without friction.

Membership access

  • Unlock premium prompts and the full copy text.
  • See more workflow paths and course connections.
  • Keep the reusable templates in one place.
Chat on WhatsApp