When is a DPIA mandatory?
Art. 35(1) GDPR requires a DPIA when processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons.
Art. 35(3) lists three situations where a DPIA is always required:
- Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similar effects are based
- Large-scale processing of special categories of data (health data, criminal records, biometric data, etc.)
- Systematic large-scale monitoring of publicly accessible areas (CCTV, Wi-Fi tracking, etc.)
Step 1: Describe the processing
Document the following elements:
- Which personal data are processed
- Whose data (categories of data subjects)
- For what purpose
- By whom (controller, processors, sub-processors)
- For how long (retention periods)
- Which technology is used
Step 2: Assess necessity and proportionality
- Is the processing necessary for the purpose? Could it be achieved with less data?
- What is the legal basis?
- Are retention periods proportionate?
- Are data subjects adequately informed?
- Can data subjects exercise their rights?
Step 3: Identify risks
Map risks to data subjects:
- Unauthorised access — what if third parties access the data?
- Data loss — what if data is lost?
- Inaccurate data — what if decisions are based on incorrect information?
- Discrimination — could the processing lead to unequal treatment?
- Loss of autonomy — are data subjects restricted in their choices?
Assess the likelihood and severity of each risk.
Step 4: Determine measures
- Technical measures: encryption, pseudonymisation, access controls, logging
- Organisational measures: policies, training, confidentiality agreements
- Legal measures: DPAs, strengthening legal basis
Step 5: Assess residual risk
After implementing measures, assess whether the residual risk is acceptable. If the risk remains high despite measures, you must consult the supervisory authority (Art. 36 GDPR: prior consultation).
Step 6: Document and monitor
Record the DPIA in a document covering all assessments, risks, measures and residual risk. Review periodically, especially when the processing changes significantly.
Role of the DPO
If your organisation has a DPO, their advice must be sought when conducting a DPIA (Art. 35(2) GDPR).
Practical tips
- Conduct the DPIA before starting the processing, not afterwards
- Involve relevant departments (IT, legal, the department carrying out the processing)
- Use a structured template to ensure nothing is overlooked
- Link your DPIA to your processing register for a complete overview
- Use DPAkit to conduct DPIAs in a structured way and link them to your vendors and processing activities