Skip to main content
← Governance

Procurement tool

A DPIA starter for BuiltAI workflows

A pre-filled Data Protection Impact Assessment you can complete and export, built on the ICO structure and BuiltAI’s actual controls. Edit every field; your DPO completes and owns the final assessment.

Starting template, not legal advice. You are the data controller; BuiltAI Intelligence Ltd is the processor. Edit every field, then your DPO completes and owns the final assessment. Nothing you type is sent anywhere; it stays in your browser.
Data Protection Impact Assessment · BuiltAI workflows

Step 1Purpose and need for the DPIA

Why this assessment is being carried out.

This DPIA assesses the data-protection impact of using BuiltAI's AI-assisted workflows to produce construction, FM and M&E deliverables (e.g. tenders, RAMS, commercial documents, board reports). [Your organisation] is the data controller; BuiltAI Intelligence Ltd acts as a data processor under a written data-processing agreement. Adapt this template to your specific engagement and packs.

Step 2Describe the processing

Nature, scope, context and purpose of the processing.

Nature: project and operational documents are uploaded and classified Red / Amber / Green at the point of upload. AI assists with drafting; every output is reviewed and issued by your team. Scope: [the data categories you will process, e.g. tender documents, method statements, commercial/CVR data, service-desk tickets]. Personal data is minimised; Red data (personal, security-sensitive, confidential commercial) is hard-blocked from public AI tools. Context: [your sector, project types, who is involved]. Purpose: reduce document-production time while preserving human review and a full audit trail.

Step 3Necessity and proportionality

Lawful basis, data minimisation, retention.

AI assistance is proportionate to the aim of reducing document-production time. Only data you provide is used; no scraping, no enrichment. Data minimisation: classify and exclude personal / sensitive data where it is not required for the deliverable. Lawful basis: [your lawful basis, typically legitimate interests for B2B operational data; complete your own assessment]. Retention: [your retention period and deletion process].

Step 4Identify and assess the risks

Risks to individuals, with likelihood and severity.

Identify the risks and record likelihood and severity for each, for example: • Inadvertent inclusion of personal data in a draft → [likelihood] / [severity] • Exposure of confidential commercial data → [likelihood] / [severity] • Reliance on an AI output that has not been reviewed → [likelihood] / [severity] The Red classification + hard-block reduces the likelihood of personal or sensitive data reaching a public AI tool; the human review gate reduces the risk of an unreviewed output being issued.

Step 5Measures to reduce the risks

BuiltAI's controls plus your own organisational measures.

BuiltAI controls: 1. R/A/G data classification at upload; Red is hard-blocked from public AI tools. 2. Human review and approval gate before any output is issued. 3. Audit log of every AI-assisted step. 4. Owner-confirmed outputs, signed off by your operational owner, not by BuiltAI alone. 5. Written data-processing agreement and a disclosed sub-processor list. Your measures: [access controls, staff training, DPO review cadence, incident process, contractual terms].

Step 6Outcome and sign-off

Residual risk, DPO advice, controller approval, review date.

Residual risk after measures: [low / medium / high]. DPO advice: [record your DPO's advice]. Controller approval: [name, role, date]. Review date: [date]. This template is a starting point only; your DPO completes and owns the final assessment.

Built on the ICO DPIA structure, pre-filled with BuiltAI’s controls (R/A/G classification, review gates, audit log, owner sign-off, DPA). Illustrative starter: confirm every field against your own processing and policy.