← Governance framework
Data & Privacy

Data Protection Impact Assessment (DPIA) Methodology

When and how ImpactMiles conducts DPIAs, including the templated risk register and Board approval gate.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Data Protection Officer
Approver
Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
5fdb37eae0ee675e0987e7cf30d1e28c0d4c49847c6d5215ce8453d35261c4cd
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:5fdb37eae0ee675e

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • Any new or materially changed processing activity

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Change management gate: no launch without DPO sign-off for triggering changes

1. Triggers

  • Processing of special-category or biometric data.
  • Large-scale profiling or automated decision-making.
  • New cross-border transfer route.
  • New sub-processor with access to personal data.
  • Any AI feature that ingests personal data.

2. Method

Describe the processing, assess necessity and proportionality, identify risks to individuals, define mitigations, record residual risk. High residual risk requires Board approval and, where required, regulator consultation.

Questions or concerns about this policy? Contact the DPO.

Related policies