Legal

Data protection impact assessment template

A template for a controller assessing the use of Pritect Sonar, with the product facts filled in and the assessment left to you.

Version
0.1
Drafted
15 Sep 2026
In force from
Not in force
Draft for review

This is a draft for review and it is a template, not advice. The product facts in it are accurate to this release. Whether a data protection impact assessment is required, and what it concludes, is yours to decide.

1

How to use this template

Scanning a workforce's files and mail for personal data is systematic processing on a large scale, and in most organisations it will merit an impact assessment whether or not one is strictly required. This template follows Article 35(7): a description of the processing, an assessment of necessity and proportionality, an assessment of the risks to individuals, and the measures that address them.

Sections 2, 5, 6 and 8 are filled in for you and describe the product as it is. Sections 3, 4, 7, 9 and 10 are prompts. Where a prompt is uncomfortable to answer, that is the prompt doing its job.

Anything in square brackets is a placeholder for you to replace.

2

The processing, described

The following is accurate for this release and can be used as written.

QuestionAnswer
What is processedDocuments, spreadsheets, presentations, PDFs, mail and attachments in the Microsoft 365 and Google Workspace tenants the controller connects, within the scope the controller selects.
HowContent is fetched, held in memory, classified by a deterministic pattern layer and, where that layer cannot decide, by a contextual model call, then discarded when the job ends.
What is storedA location, a category, a count of values, a count of distinct values, a confidence and a position reference such as a page, a sheet or a cell. Filenames and paths. Sharing state and sensitivity label. The account that owns a site, a drive or a mailbox.
What is not storedDocument text, message bodies, attachments, matched values and snippets. None is written to the database, the queue, storage, a log line, an error message or a temporary file that outlives the job.
Automated decision makingNone with legal or similarly significant effect on an individual. Classification produces a category and a confidence about a document, and exposure rules produce a finding about a document or a container. No rule produces an outcome about a person.
ProfilingNone. There is no capability to search for or assemble an individual's data. The container owner is recorded as the holder of an account, not as a subject of analysis.
Where it runsEU, Frankfurt. The database, the web application and the scanning worker all run in the workspace's region, and the contextual classification call goes to an EU endpoint.
Sub-processorsFour, all processing in the EU. Content reaches two of them and only in memory. Microsoft and Google are the controller's own processors, not the provider's sub-processors.
What the service does.

3

Necessity and proportionality, which is yours to assess

Purpose
Why are you doing this? State the purpose in terms of your own obligations, for example maintaining a record of processing activities, finding personal data held beyond its retention period, or reducing the exposure of personal data through sharing links.
Lawful basis
What is your lawful basis for processing the personal data that appears in the content being scanned? For most employers this will be legitimate interests or compliance with a legal obligation. Record the basis and, for legitimate interests, the balancing test.
Special category data
Content will contain special category data. What is your Article 9 condition for processing it, and does your own policy document cover it?
Could you achieve the purpose with less
Would a narrower scope reach the same outcome? Consider sites before drives, drives before mailboxes, and whether mailboxes are needed at all. Record why the scope you chose is the smallest that works.
Proportionality of scanning mail
If mailboxes are in scope, record separately why scanning correspondence is proportionate to the purpose, and what you considered instead.
Data minimisation
The service stores findings rather than content. Record the settings you chose that reduce what is kept further: the retention periods, whether the owner view is on, and whether masked snippets are on.

4

Who is affected, and consulting them

Data subjects
Who appears in the content you will scan? Typically your own workforce, your customers, your suppliers and your correspondents. Note any group in a position of dependence or vulnerability.
Workforce information
How and when will you tell your people? A notice you can adapt is published alongside this template. Record the date it was sent and the channel.
Works council or employee representatives
Is there a body that must be informed or consulted, and does your jurisdiction require agreement rather than consultation? An explainer written for such a body is published alongside this template. Record what was shared, when, and the outcome.
Data protection officer
Record your data protection officer's advice and the date it was given.
Processor input
The provider's input to this assessment is the published trust page, limits page, data processing agreement and this template. Record anything further you asked for and received.

5

Data flows and recipients

FlowWhat movesWhereBasis
Tenant to the scanning workerContent, in memory, for the life of a jobThe workspace's regionThe controller's instruction, through permissions its own administrator granted
Worker to the contextual classifierShort passages where the deterministic layer cannot decideEU endpointSub-processor under the data processing agreement
Worker to the databaseFindings and inventory rows. No contentThe workspace's regionSub-processor under the data processing agreement
Workspace to the Pritect platformFindings metadata, plus an asset owner's work email address where there is one. No content and no item namesFrankfurt to Ireland, both in the EUOnly where the controller links the two products, and only on the controller's instruction
Workspace to the controllerExports of the inventory, the findings and the audit recordsWherever the controller downloads themThe controller's own act
Where data goes. Filled in.

6

Retention

The service holds no content, so retention concerns the records about content. Each period below is a workspace setting the controller chooses, and a purge runs against it automatically.

Resolved findings
Default is 365 days. Your setting: [days].
Scan records
Default is 730 days. Your setting: [days].
Audit records
Default is 730 days. Your setting: [days].
Inventory rows
Inventory reflects the current state of the tenant and is kept while the workspace is open. Record how a workspace closure would be triggered in your own retention schedule.
End of service
Deleting the workspace destroys its encryption key, purges its rows and leaves a tombstone and a confirmation reference. Record who is authorised to do that and what evidence you will keep.

7

Risks to individuals, which is yours to assess

The four risk areas below are the ones this product actually raises. They are offered so that the assessment starts in the right place, not so that it can be copied. Score each one in your own terms and add the risks specific to your organisation.

Risk 1: the scan reaches correspondence
Mail content is read where mailboxes are in scope. The permission Microsoft grants an application is tenant-wide and is narrowed by the controller's own application access policy. Assess the likelihood and severity of mail being read beyond the intended scope, and record whether the policy is in place and who verified it.
Risk 2: the inventory becomes a map for the wrong purpose
An inventory of where personal data lives, by container and by owner, is useful to an employer for reasons other than data protection. Assess the risk of function creep and record the access controls and the audit review that address it.
Risk 3: exposure of the inventory itself
A breach of the service would expose locations, categories, counts, filenames, paths, sharing state and container owners. There is no content to expose. Assess what that exposure would mean for your organisation.
Risk 4: acting on an incorrect classification
A classification can be wrong in either direction. An item that could not be read is recorded as not read rather than clean, and an item that could not be classified with confidence is marked for review. Assess the consequence of a false negative for your purpose, and record the human review step before anyone acts on a finding.
Your own risks
Add risks specific to your sector, your jurisdiction and your workforce. [Add rows.]

8

Measures the product already provides

These are implemented and can be recorded as mitigations without further verification. The full list is Annex II of the data processing agreement.

  • Content is never persisted, and the claim is enforced by a test that plants known values and then searches the database, the queue, the realtime payloads and the worker's temporary filesystem for each of them.
  • No personal data reaches a log record. Values pass through an allowlisting serialiser and a test drives sensitive values through every field position.
  • The container owner view is off by default, and while it is off the database returns nothing for those fields rather than the interface hiding them.
  • There is no capability to search for an individual's data. It is not a setting that is switched off; it is not in this release.
  • Scope is the controller's choice, and mailboxes are included only if the controller includes them.
  • The application access policy script for narrowing the mail permission is provided, and the service probes an out-of-scope mailbox to report whether the policy is in place.
  • Every change to a setting governing disclosure or retention is written to an append-only audit log that nobody can edit or delete, including the provider.
  • An item that could not be read is recorded as not read with the reason, and an item that could not be classified with confidence is marked for review rather than clean.

9

The mail scope decision, recorded separately

This is the decision most likely to be revisited, so it is recorded on its own rather than inside section 3.

Are mailboxes in scope
[Yes or no.] If no, the rest of this section does not apply.
Which mailboxes, and why those
[Name the group or the criterion, not the individuals.] Record why a narrower set would not meet the purpose.
Application access policy
Record that the policy restricting the application to the chosen group is in place, who applied it, on what date, and the result of the product's own probe.
Who was told
Record the workforce notice and any consultation specific to mail, separately from the general notice.
Review
Record when the decision to scan mail will be reviewed, and what would cause it to be reversed.

10

Outcome, sign-off and review

Residual risk
After the measures, what risk remains, and is it acceptable? If a high risk remains that you cannot mitigate, you must consult your supervisory authority before starting.
Decision
[Proceed, proceed with conditions, or do not proceed.] Record the conditions.
Approved by
[Role and date.] Record the role rather than a name in a document that will circulate.
Data protection officer's opinion
[Recorded, and whether it was followed.]
Review date
[Date.] Also review whenever the scope changes, a new connector is added, a setting governing disclosure is turned on, or the provider notifies a new sub-processor.