Client DPIA template — Natalia Analytics

A pre-filled Data Protection Impact Assessment template you can hand to your DPO. Triggered above ~5000 phone lines (CNIL threshold for systematic monitoring of work).

1. Description of the processing

Nature of processing: collection, storage and analysis of phone call metadata (CDR) generated by the Alcatel OXE / OXO PBX of the organisation.

Scope: [to complete: number of phone lines, geographical perimeter, departments concerned]

Categories of data: external phone numbers (encrypted at rest, displayed in clear only to the Admin role, searchable by cryptographic fingerprint), internal extension numbers, employee names and job titles (extension directory, sourced from the PBX), date and time of calls, durations, direction (in/out), redirections, trunk identifiers.

Categories of data subjects: employees of the Controller, third parties calling or being called.

Retention period: [to complete: typically 12 months for raw CDR. For the part hosted by Natalia in connected mode, published maximum retention periods: audio recordings 12 rolling months, transcripts and analyses 24 months, technical logs 90 days, permanent erasure within 30 days on request; aggregated, anonymized statistics with no retention limit.]

Recipients: HR department (anonymised aggregates), IT operations (raw CDR for troubleshooting), management (KPIs).

Sub-processors: strict disconnected mode: none. Connected mode: Natalia SAS + Gemini (Google Ireland eu-west). Support 72h: ad-hoc Natalia SAS during the intervention only.

2. Necessity & proportionality

Legal basis (art.6): [most common: legitimate interest (art.6-1-f) for IT operations and capacity planning. For HR uses, consult employee representatives and document the proportionality.]

Purposes: [detail each purpose. Avoid aggregating heterogeneous purposes under a single basis.]

Data minimisation: external phone numbers are encrypted at rest in the Software (per-tenant key) and shown in clear only to the Admin role, on an individually audited action; the Viewer role only ever sees a masked number (last 4 digits); search is performed on a non-reversible per-tenant fingerprint, never on the plaintext number. Only the necessary metadata are collected, raw audio is never processed.

Storage limitation: [document the retention period for each category of data and the deletion procedure at the end of the period.]

3. Risks to data subjects

Risk Likelihood Severity Notes
Re-identification of employees through call patterns Medium High External numbers are encrypted at rest and masked for the Viewer role; the Admin role can decrypt a number on an individually audited action (see 'Internal abuse' row below), and CDR remain identifiable through call patterns regardless.
Inappropriate HR monitoring Medium High Aggregated KPIs may be misused to assess individual performance.
Data breach (external attack) Low High On-prem appliance behind customer firewall, reduced attack surface.
Internal abuse (admin) Medium Medium Mitigated by immutable audit log + auditor role separation; each phone-number decryption by an Admin is individually and nominatively logged (dedicated reveal log, distinct from the general audit log).
Sub-processor LLM leak (connected mode) Low High Mitigated by 0-day retention contractual + no training on prompts.

4. Mitigation measures

  • Encryption at rest of external phone numbers (per-tenant key), decryption restricted to the Admin role and individually audited, search performed on a non-reversible per-tenant fingerprint (never on the plaintext number).
  • Role-based access control (4 roles: viewer, admin, auditor, integrator). Auditor role untouchable by admin.
  • Immutable audit log with hash chain (tamper-evident).
  • On-prem appliance, no remote control by Natalia in strict disconnected mode.
  • Documented information of employees (art.13 GDPR) before activation of the processing, consultation of employee representatives where required by law.
  • Strict separation between IT operations purposes and HR analytics purposes (separate roles, separate dashboards, separate retention).
  • Periodic review of the DPIA (recommended every 12 months or after any major scope change).

Validation

DPO : [name, date, signature]

IT security manager: [name, date, signature]

HR director (if applicable): [name, date, signature]

Next review date: [date]