The Problem
Your DPIA documentation is scattered across shared drives, and your breach notification checklist is outdated. When a security incident occurs, your team scrambles to find the right forms for each DPA, reformatting the same information multiple times before the 72-hour deadline.
The EDPB's Helsinki Statement, adopted on 2 July 2025, formalizes standardized templates for DPIAs and breach notifications that all EU supervisory authorities will expect you to use. The DPIA template was adopted on 10 March 2026, and the breach notification template followed on 8 June 2026, currently in consultation until 5 August 2026.
If you're still using outdated processes, your documentation won't align with what DPAs will soon require. This is a migration project you need to start now.
What You Need Before Starting
Your current DPIA artifacts:
- Existing DPIA templates or methodologies
- Completed DPIAs from the past 18 months
- Internal guidance documents or checklists for assessments
Your breach notification workflow:
- Current notification forms for each DPA
- Past breach notifications (redacted if necessary)
- Contact lists and escalation trees for breach response
- Any automation or tools that generate notification content
Access to the new templates:
- The EDPB's standardized DPIA template and explainer document (published April 2026)
- The common breach notification template (currently in consultation)
- Your organization's record of which DPAs you're subject to and their notification systems
Cross-functional stakeholders: You'll need input from your DPO or privacy lead, information security, legal, and whoever manages your GRC tooling if applicable.
Step-by-Step Implementation
Phase 1: Gap Analysis on DPIA Documentation
Map your existing DPIA structure against the EDPB's seven-section template. The EDPB template distinguishes between design-level risks (inherent to processing) and operational security risks (failures, breaches, attacks).
Open your most recent DPIA. Does it address design-level risk? If it jumps straight to "what could go wrong" without considering compatibility with data subjects' rights when everything works as intended, you've found a gap.
Create a mapping document:
- EDPB Section 1 (Processing Description) → Your Section X
- EDPB Section 2 (Necessity and Proportionality) → Your Section Y or [MISSING]
- Continue through all seven sections
For each EDPB section your current template doesn't address, note whether the information exists elsewhere or if it's missing.
Phase 2: Template Migration
Don't retrofit every historical DPIA. Build a new working template that meets both your internal needs and the EDPB structure.
If your current template includes sections not required by the EDPB but useful for internal governance, keep them. The EDPB template is a minimum standard.
Add the EDPB's predefined answer options and conditional logic. Test your draft template on a real processing activity. Choose something mid-complexity. Have the person who would normally conduct the DPIA walk through the new template and note where they get stuck.
Phase 3: Breach Notification Workflow Redesign
The breach notification template is designed for IT tools, not static forms. Your implementation path depends on your current infrastructure.
If you use a GRC platform or incident management system, contact your vendor about their timeline for implementing the EDPB template. If they don't have a roadmap, that's a signal.
If you're using spreadsheets or email templates, build a master notification document that includes:
- All fields from the EDPB template
- Conditional logic rules (e.g., "if breach involves special categories, complete Section 4")
- Pre-populated dropdowns for breach type, affected data categories, and likely consequences
Phase 4: Cross-Border Coordination
If you operate in multiple Member States, the breach notification template reduces duplication. But DPAs won't all implement it simultaneously.
Create a jurisdiction matrix:
- Which DPAs you're subject to
- Whether each has implemented the EDPB template
- What their legacy notification system requires if the template isn't live
Until all your relevant DPAs have migrated, you'll run a hybrid process. Prepare your notification content in the EDPB format first, then reformat for any DPA still using their system.
Validation
Test your new DPIA template by running a parallel assessment: conduct a DPIA using your old methodology and the new EDPB-aligned template simultaneously. Compare the outputs. If the new template surfaces risks your old process missed, that's the point.
For breach notifications, run a tabletop exercise. Simulate an incident, set a timer for 72 hours, and have your team complete the new template. Note where they hesitate or need to hunt for information.
Maintenance
The DPIA template will be your new baseline, but it won't stay static. The EDPB will regularly review its guidance. Set a reminder every six months to check for updates to the template or its explainer.
As DPAs implement the breach notification template, update your jurisdiction matrix. When all your relevant DPAs have migrated, retire your legacy notification documents.
The Helsinki Statement also introduced an inconsistency reporting mechanism (launched 24 June 2026). If you encounter conflicting DPA positions, use that channel. The EDPB will publish positions on priority issues, so your report could contribute to future clarification.
Finally, if your organization is subject to the AI Act, NIS2, or other frameworks, integrate these into your GDPR compliance. The EDPB's commitment to cross-regulatory cooperation means these frameworks will converge. Your DPIA process should capture AI Act risk assessments where relevant.



