Data Protection Impact Assessment for WorkTwins
1. Project Description
Describe the WorkTwins deployment:
- individual use;
- company workspace;
- employee matching;
- candidate matching;
- AR/visual context;
- cloud-assisted matching;
- chat/collaboration.
2. Processing Purposes
- WorkFootPrint creation;
- computational affinity;
- matching;
- collaboration;
- security;
- support;
- billing.
3. Data Categories
List data collected locally, excluded locally, sent to cloud, shown to users, shown to companies, and retained.
4. Lawful Basis / Legal Basis
Identify applicable legal basis per region.
5. Necessity and Proportionality
Explain why each data category is necessary.
6. Risks
Evaluate risks:
- workplace monitoring concerns;
- sensitive data capture;
- non-work capture;
- inaccurate match outputs;
- discrimination;
- automated decision use;
- employee power imbalance;
- cloud security;
- inference risks.
7. Mitigations
- local-first processing;
- user review before upload;
- granularity control;
- non-work filtering;
- sensitive-data filtering;
- no raw evidence sharing by default;
- human review;
- user rights;
- security controls;
- company notices;
- DPA and subprocessor controls.
8. Residual Risk
Assess remaining risks after mitigation.
9. Approval
Data protection owner: Legal owner: Security owner: Product owner: Approval date: Review date: