Policy version: 2026-07-13 · EN

Data Protection Impact Assessment (DPIA) — Template

For: TrustOriginality.ai customers (controllers) processing personal data via the platform
Frameworks: GDPR Art. 35 · KVKK · EU AI Act (where personal data in AI systems)
Version: 0.1-skeleton · Date: 2026-06-16
Not legal advice — complete with your DPO / counsel.


1. Project overview

Field Value
Project name [e.g. CMS AI screening / KYC verification]
Controller [Customer legal name]
Processor Soluzyn OÜ (DPA executed)
DPIA owner [Name, role]
Date [YYYY-MM-DD]
Review cycle [Annual / on material change]

2. Description of processing

Item Detail
Purpose [e.g. Detect undisclosed AI-generated media before publication]
Legal basis (GDPR Art. 6) [Legitimate interest / Consent / Contract — specify]
Special categories (Art. 9) [Yes/No — e.g. biometric KYC selfies via /api/kyc]
Data subjects [Employees, customers, students, claimants, etc.]
Personal data categories Content submitted for analysis; account metadata; IP logs; [biometric if KYC]
Minimization measures Text input SHA-256 hashing (optional); PDF retention [30] days; no raw text stored when hash-only mode enabled
Recipients TrustOriginality (processor); sub-processors per DPA Annex B
Transfers [EU / TR / US — specify SCCs if applicable]
Retention Per DPA Annex A and panel retention settings

3. Necessity and proportionality

  • Why is automated detection necessary vs manual review alone?
  • What is the minimum data required (modality, resolution, duration)?
  • Can hash-only or metadata-only modes suffice?

4. Risks to data subjects

Risk Likelihood Severity Mitigation
False positive → wrongful publication block [L/M/H] [L/M/H] Human review threshold; appeal process
False negative → undisclosed AI content [L/M/H] [L/M/H] Multi-modal checks; provenance (C2PA)
Biometric misuse (KYC) [L/M/H] [L/M/H] Explicit consent; GET /api/kyc/privacy-notice; limited retention
Re-identification from logs [L/M/H] [L/M/H] Hashing; access controls; deletion API
Profiling in high-risk context [L/M/H] [L/M/H] Prohibited per AUP for sole automated Annex III decisions

5. Measures to address risks

  • Executed DPA + Annexes A–C
  • Privacy notice updated (AI analysis disclosed)
  • Retention configured in panel (Account → data retention)
  • AUP acknowledged — no Annex III sole automated decisions
  • Staff training on probabilistic outputs
  • Incident response contact: [security@trustoriginality.ai]

6. KVKK-specific (Türkiye)

Item Detail
VERBİS registration [Customer obligation if applicable]
Data controller representative [If required]
Cross-border transfer [KVKK Board approval / undertakings if needed]
Explicit consent [For special categories / biometric]

7. Consultation

  • DPO / privacy counsel sign-off: [Name, date]
  • Supervisory authority consultation required? [Yes/No — Art. 36 high residual risk]

8. Approval

Role Name Signature Date
Controller representative
DPO
  • DPA: legal/DPA-TEMPLATE.md
  • Annex A processing description: legal/annexes/ANNEX-A-DESCRIPTION-OF-PROCESSING.md
  • Technical limitations: legal/ANNEX-IV-TECHNICAL-DOCUMENTATION.md
  • Panel: DELETE /api/account · retention settings · activity log export