When is a DPIA required?
A DPIA is required where processing personal data is likely to result in a high risk to the data subjects. You carry out the assessment before the processing begins, not after the fact.
That last point is the misunderstanding we come across most often. A DPIA is not a form you fill in once the project is finished, and that difference decides whether it is worth anything to you.
A company is required to carry out a Data Protection Impact Assessment when it is going to process personal data that is likely to result in a high risk to the data subjects. That can apply when new technologies are used, or where personal data is processed on a large scale. The point of it is to give you a clear view of the negative effects your processing may have on the privacy of the people involved.
When is a DPIA always required?
A DPIA is required where there is:
- large-scale processing of special categories of personal data, for example health data or criminal data;
- systematic and large-scale monitoring of publicly accessible areas;
- systematic and extensive profiling on which decisions are based that have legal consequences for individuals;
- the use of new technologies that are likely to involve a high privacy risk.
On top of that, the Dutch Data Protection Authority maintains a list of processing operations for which a DPIA is required in any event. Think of camera surveillance aimed at tackling fraud, systematic monitoring of employees, and large-scale processing of data about someone’s financial situation. That list is the first thing we reach for.
And if your situation isn’t on it?
Then it becomes a judgement call. The European supervisory authorities have set out nine criteria for this, including evaluation or scoring, automated decision-making, systematic monitoring and processing data relating to vulnerable individuals. If your processing meets two or more of them, a DPIA is in principle called for.
Concluded that you don’t need one? Record how you reached that conclusion. It takes you ten minutes and it forms part of your accountability obligation.
What has to be in it?
A DPIA must contain at least:
- a systematic description of the processing you intend to carry out and the purposes for it;
- an assessment of the necessity and proportionality of the processing of personal data;
- an assessment of the privacy risks to the individuals whose personal data you want to process;
- the measures envisaged to address those risks, together with a description of why the processing complies with the GDPR.
If you have a data protection officer, you ask them for advice. That advice, and what you did with it, should be reflected in the document.
And if the risks remain too high?
If the DPIA shows a high risk remaining that you cannot mitigate, you have to consult the Dutch Data Protection Authority before you start processing. That procedure takes weeks. It is exactly the kind of discovery you don’t want to make in the final week before go-live.
If your processing changes substantially later on, for example because you add an AI component to it, you hold the DPIA up to the light again. On that combination we wrote earlier about the AI Act transparency obligation.
So a DPIA is above all a question of timing. Carried out early, it is a tool that helps you adjust your design. Carried out late, it is a justification after the fact for choices you are no longer going to reverse.
We assess whether a DPIA is required in your case and can carry it out for you. Running into this? Feel free to get in touch or read more about privacy law.