Data Protection Impact Assessments
A Data Protection Impact Assessment (DPIA) is a mandatory process used to identify and minimize the data protection risks of a project. It must be conducted before processing begins whenever that processing is likely to result in a high risk to the rights and freedoms of individuals.
What it means
The intent of Art. 35 is to enforce "privacy by design." Rather than reacting to data breaches or complaints, organizations are required to proactively analyze how data flows and where vulnerabilities exist before a system is deployed or a process is changed.
In practice, the scope applies to "high-risk" processing. While the GDPR does not provide an exhaustive list of every high-risk scenario, it typically includes the use of new technologies, large-scale profiling, systematic monitoring of public areas (such as CCTV), or the large-scale processing of special categories of data (e.g., health or genetic data).
A DPIA is a risk management exercise. The goal is to determine if risks can be mitigated to an acceptable level through technical or organizational controls. If high risks remain that cannot be sufficiently mitigated, the organization must consult the relevant supervisory authority before proceeding.
How to meet it
- Establish a threshold assessment (screening) process to determine whether a full DPIA is required for every new project or significant change to existing processing.
- Document the data flow in detail, including what data is collected, where it is stored, who has access, and how long it is retained.
- Evaluate the necessity and proportionality of the processing to ensure the objective cannot be achieved by a less intrusive method.
- Identify potential risks to individuals—such as identity theft, discrimination, or loss of confidentiality—and assess their likelihood and severity.
- Define specific mitigation measures (e.g., encryption, pseudonymization, or access controls) to reduce identified risks to an acceptable level.
- Consult with your Data Protection Officer (DPO) for advice on the assessment and its outcomes.
Evidence an auditor asks for
- Completed DPIA reports containing a description of processing, risk assessments, and planned mitigations.
- A DPIA Register or Log showing which projects were screened and the justification for why some did not require a full assessment.
- Documented evidence of DPO involvement, such as sign-offs or emails providing advice on the assessment.
- Proof that the mitigation measures identified in the DPIA were actually implemented in the production environment.
Common pitfalls
- Performing the DPIA after the project has already been designed or deployed, treating it as a retrospective formality rather than a planning tool.
- Failing to review and update existing DPIAs when the nature of the processing changes