DPIA / Data Protection Impact Assessment under GDPR – when is it required and how is it done?
Share
Short answer: A DPIA must be conducted prior to any personal data processing that is likely to result in a high risk to the rights and freedoms of natural persons. The work must describe the processing, assess necessity and proportionality, analyze the risks, and document measures to mitigate them.
What is a DPIA?
DPIA stands for Data Protection Impact Assessment. It is a structured way to identify and mitigate privacy risks before processing begins or before an existing processing activity changes significantly.
When can a DPIA be required?
High risk can arise when several risk factors are combined, such as extensive processing of sensitive personal data, systematic monitoring, large-scale profiling, new technology, or processing that affects vulnerable individuals. The assessment must be based on the actual processing and its context.
Four core components of the impact assessment
- Describe the processing. Purposes, systems, data sources, categories of data, data subjects, recipients, storage, and transfers.
- Assess necessity and proportionality. Is all data necessary? Is the storage period reasonable? Is there a legal basis and correct information?
- Analyze the risks. Assess both the probability and severity for the data subjects, not just the IT risk for the organization.
- Decide on protective measures. Examples include access control, encryption, logging, data minimization, pseudonymization, process controls, and training.
DPIA and AI
AI systems can involve extensive data processing, profiling, and new types of conclusions about individuals. An AI risk assessment under other regulations does not automatically replace a DPIA. If the personal data processing meets the GDPR's high-risk criteria, the data protection assessment must be carried out as a separate part of the governance.
When is prior consultation relevant?
If a DPIA shows that the processing would lead to a high risk and the organization cannot reduce the risk to an acceptable level through planned measures, prior consultation with the supervisory authority may be necessary before processing begins.
Common shortcomings
- conducting a DPIA after the system has already been put into operation
- only describing cybersecurity risks and not consequences for people
- skipping necessity and proportionality
- assessing risk before protective measures but not the residual risk after measures
- not involving a Data Protection Officer when the organization has one
- never updating the assessment when the processing changes
Documentation that makes a DPIA useful
A good DPIA is not just a legal document but a basis for decision-making. Link risks to concrete measures, responsibilities, deadlines, and decisions. This makes it possible to follow up on risk mitigation and to demonstrate why the processing was deemed acceptable.
See the Mallbutiken DPIA / impact assessment package in Word, PDF, and Excel.
Related documents
DPIA work becomes significantly easier if the organization has an updated record of processing activities (ROPA) and documented legal bases. In the event of incidents, the DPIA should also be used as support for understanding what consequences may arise.
FAQ
Is a DPIA needed for every new IT system?
No. The question is whether the planned personal data processing is likely to involve a high risk. However, a new system can be a signal to perform a structured screening.
Can multiple processing activities be covered by the same DPIA?
In some cases, similar processing activities with comparable risks can be assessed together, but the scope must be clearly defined.
Is a DPIA a one-time document?
No. The assessment should be reviewed when the risk profile, technology, purpose, or other central conditions change.
The article provides general information and does not replace legal advice.