Data protection impact assessment

A data protection impact assessment, or DPIA, is the study you carry out before starting processing that is likely to result in a high risk to the rights and freedoms of individuals. You describe the processing, assess its necessity and proportionality, map the risks and record the measures that address them.

Legal basis

Article 35 GDPR contains the obligation and names three cases in which a DPIA is always required: systematic and extensive automated evaluation of personal aspects producing legal effects, large-scale processing of special category or criminal data, and systematic large-scale monitoring of publicly accessible areas. The Dutch Data Protection Authority publishes an additional list of processing operations for which a DPIA is compulsory, from workplace camera surveillance to blacklists and credit scoring. Article 36 requires prior consultation with the regulator if the residual risk remains high despite mitigation. Under Article 35(2) the data protection officer must be asked for advice.

How it works in practice

A workable DPIA is a decision document, not a form. You first describe the data flows concretely enough for an outsider to follow them, including suppliers and retention periods. You then test, purpose by purpose, whether the means are heavier than necessary: could it be done with less data, with pseudonymisation, with a shorter retention period? Only once that question has been answered honestly do security measures come into play. The document is a living one: a material change to the processing calls for an update.

Where it goes wrong

The classic mistake is the retrospective DPIA, written to justify a system that is already running. The outcome is then predictable and the exercise has lost its function. A second is skipping consultation where the residual risk is high; organisations are inclined to rate that risk low to avoid a visit to the regulator. A third is the DPIA completed by the supplier of the system, who has no interest in concluding that a less intrusive option exists.

Related terms

The DPIA links to the data processing agreement, since the processor must supply the information, and to the AI Act, which prescribes a separate fundamental rights assessment for certain systems.

Would you like a DPIA reviewed or guided? Our IT lawyers do this together with your data protection officer.