beatriz-perez-moya-111685-unsplash

Data Protection Impact Assessment Guide

The General Data Protection Regulation (GDPR) has introduced a new obligation, which requires companies and organizations to carry out data protection impact assessments if the personal data that the company processes is likely to result in a high risk to individuals’ interests.

If a high risk to personal data is detected, the company must consult the local data protection authority.

This is necessary since the company is accountable for designing the processing activities in a way that protects the individual’s data from the start.

Many companies are already carrying out Privacy Impact Assessments (PIA) as good practice but these assessments may not cover all of the mandatory conditions deriving from the GDPR.

If there is no DPIA  procedure in place within your company, you need to design the process and embed it into your organization’s policies and procedures.

What is a data protection impact assessment?

The data protection impact assessment is designed to systematically and comprehensively analyze the company’s personal data processing activities and the risks that they carry.

DPIA helps the company to identify and prevent risks related to data protection and privacy. DPIA covers the compliance risks from the company’s perspective but also the broader risks to the rights and freedoms of individuals. Violations of personal data processing can lead to a significant social or economic disadvantage for the individual.

Therefore, the DPIA should consider the level of risk in regards to both the likelihood and the severity of any impact possible on the individuals.

The DPIA does not remove the risk altogether but should be designed to minimize the possible negative impacts of data processing and to assess whether the remaining risks are managed.

DPIA can also assert broader compliance by taking into account financial and reputational benefits by demonstrating accountability for individual clients.

When is DPIA needed?

DPIA is needed when the processing of personal data may result in a high risk to the rights and freedoms of natural personsThis means widespread or serious impacts on the individual or society in general.

Processing activities when DPIA is needed:

  • Systematic and extensive profiling or automated processing with legal effects on the person
  • Processing on a large scale of special categories of data or personal data relating to criminal convictions
  • Systematic monitoring of a publicly accessible area on a large scale

Processing activities when DPIA is needed according to national DPA (more specifically defined in WP248)

  • Use of new technologies
  • Use of profiling on access to services
  • Behavior and location tracking
  • Targeting and profiling of children
  • Data processing that might endanger an individual’s physical health or safety in case of a security breach
  • Combining data sets from various sources
  • Collecting personal data without providing the privacy notice
  • Processing of biometric data;
  • Processing of genetic data
  • Processing of location data

The need for a DPIA needs to be considered carefully and the requirements of member states might vary greatly.

For example, Finland did not include location data in its original processing list until EDPB advised to add it.

Not every member state requires a DPIA in case of new technology used by the company. However, a DPIA should be considered as a general rule in cases where the processing involves profiling or monitoring, the technology decides about the access to services or opportunities or if the processing involves particularly sensitive data or vulnerable individuals.

Even if high risk for the individual is not detected, the DPIA serves as the basic document on data protection for the processing activity being a document which is dynamic and changes in time.

The European Data Protection Board (EDPB) published a guide on which data processing activities would need a data protection impact assessment (DPIA).

There have been differing opinions amongst the member states national Data Protection Authorities on when a DPIA is necessary and to which processing activities the procedure should apply.

The EDPB guide’s purpose is to form a harmonized approach to cross-border personal data processing activities that can have an effect on the natural person’s free movement within the EU.

Currently, the EDPB guidelines of WP248 on data protection impact assessment (DPIA) serve as a basis for the national authorities to set their own requirements for processing activities that requires data protection impact assessments.

However, the national requirements can turn out to be stricter compared to the EDPB standards but since personal data processing often has cross-border elements the standards of EDPB should be followed.

More to read on this topicRecords of processing activities in GDPR Article 30

Are you GDPR compliant? ​

Assess whether you have to comply with the GDPR in the first place and if you do, what is the level of preparedness of the GDPR compliance. Also check out the answers for the frequently asked questions.

Get your compliance organized with proper GDPR tools.
Contact us for a demo and get access to 14-day trial.

Save time and be confident

Latest Posts
Your Essential Guide to Developing a Data Breach Response Plan

Your Essential Guide to Developing a Data Breach Response Plan

The General Data Protection Regulation (GDPR) places significant emphasis on securing personal data, particularly in Articles 32-34, which outline requirements...
Biometric Data and GDPR: Key Considerations

Biometric Data and GDPR: Key Considerations

Biometric data is classified by the GDPR as a special category of personal data, subject to enhanced protection. This means...
Why ‘I Don’t Allow Meta’ Posts Don’t Work and What to Do

Why ‘I Don’t Allow Meta’ Posts Don’t Work and What to Do

Every so often, viral posts resurface on Facebook and Instagram declaring:"I do not allow Meta to use my data, pictures,...
GDPR Fine of €475 Million for Netflix: Top 5 Lessons for Everyone

GDPR Fine of €475 Million for Netflix: Top 5 Lessons for Everyone

Netflix is at the centre of a data privacy cliffhanger as the Dutch DPA indicates it is likely to be...
How to Avoid ICO Fines: Lessons from Recent GDPR Spam Text Penalties

How to Avoid ICO Fines: Lessons from Recent GDPR Spam Text Penalties

Lessons for Legal Teams: Avoiding Costly Mistakes in Data Privacy ComplianceData privacy is no longer a secondary concern for businesses—it's...
Privacy Rights and it’s Challenges – 6 Years of GDPR

Privacy Rights and it’s Challenges – 6 Years of GDPR

Six years since GDPR came into force, the promise of stronger data protection is being undermined by the rise of...
Staying Ahead of GDPR Compliance: Lessons from LinkedIn’s €310 Million Fine

Staying Ahead of GDPR Compliance: Lessons from LinkedIn’s €310 Million Fine

LinkedIn Ireland was recently fined a record-breaking €310 million by the Irish Data Protection Commission for GDPR violations, underscoring the...
Preparing Your Small Business for GDPR Compliance

Preparing Your Small Business for GDPR Compliance

The General Data Protection Regulation (GDPR) is a European Union law that protects the privacy and personal data of individuals...
The GDPR Data Map – Your Complete Guide

The GDPR Data Map – Your Complete Guide

The General Data Protection Regulation (GDPR) is a European regulation establishing the framework for personal data protection of individuals in...
GDPR in Healthcare: Compliance Guide

GDPR in Healthcare: Compliance Guide

Since General Data Protection Regulation (GDPR) entered into force, the personal data protection has become more challenging to the Healthcare...