← Governance framework
Data & Privacy
Data Protection Impact Assessment (DPIA) Methodology
When and how ImpactMiles conducts DPIAs, including the templated risk register and Board approval gate.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Data Protection Officer
- Approver
- Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
5fdb37eae0ee675e0987e7cf30d1e28c0d4c49847c6d5215ce8453d35261c4cdSHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:5fdb37eae0ee675eThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- Any new or materially changed processing activity
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- Change management gate: no launch without DPO sign-off for triggering changes
1. Triggers
- Processing of special-category or biometric data.
- Large-scale profiling or automated decision-making.
- New cross-border transfer route.
- New sub-processor with access to personal data.
- Any AI feature that ingests personal data.
2. Method
Describe the processing, assess necessity and proportionality, identify risks to individuals, define mitigations, record residual risk. High residual risk requires Board approval and, where required, regulator consultation.
Questions or concerns about this policy? Contact the DPO.