beatriz-perez-moya-111685-unsplash

Data Protection Impact Assessment Guide

The General Data Protection Regulation (GDPR) has introduced a new obligation, which requires companies and organizations to carry out data protection impact assessments if the personal data that the company processes is likely to result in a high risk to individuals’ interests.

If a high risk to personal data is detected, the company must consult the local data protection authority.

This is necessary since the company is accountable for designing the processing activities in a way that protects the individual’s data from the start.

Many companies are already carrying out Privacy Impact Assessments (PIA) as good practice but these assessments may not cover all of the mandatory conditions deriving from the GDPR.

If there is no DPIA  procedure in place within your company, you need to design the process and embed it into your organization’s policies and procedures.

What is a data protection impact assessment?

The data protection impact assessment is designed to systematically and comprehensively analyze the company’s personal data processing activities and the risks that they carry.

DPIA helps the company to identify and prevent risks related to data protection and privacy. DPIA covers the compliance risks from the company’s perspective but also the broader risks to the rights and freedoms of individuals. Violations of personal data processing can lead to a significant social or economic disadvantage for the individual.

Therefore, the DPIA should consider the level of risk in regards to both the likelihood and the severity of any impact possible on the individuals.

The DPIA does not remove the risk altogether but should be designed to minimize the possible negative impacts of data processing and to assess whether the remaining risks are managed.

DPIA can also assert broader compliance by taking into account financial and reputational benefits by demonstrating accountability for individual clients.

When is DPIA needed?

DPIA is needed when the processing of personal data may result in a high risk to the rights and freedoms of natural personsThis means widespread or serious impacts on the individual or society in general.

Processing activities when DPIA is needed:

  • Systematic and extensive profiling or automated processing with legal effects on the person
  • Processing on a large scale of special categories of data or personal data relating to criminal convictions
  • Systematic monitoring of a publicly accessible area on a large scale

Processing activities when DPIA is needed according to national DPA (more specifically defined in WP248)

  • Use of new technologies
  • Use of profiling on access to services
  • Behavior and location tracking
  • Targeting and profiling of children
  • Data processing that might endanger an individual’s physical health or safety in case of a security breach
  • Combining data sets from various sources
  • Collecting personal data without providing the privacy notice
  • Processing of biometric data;
  • Processing of genetic data
  • Processing of location data

The need for a DPIA needs to be considered carefully and the requirements of member states might vary greatly.

For example, Finland did not include location data in its original processing list until EDPB advised to add it.

Not every member state requires a DPIA in case of new technology used by the company. However, a DPIA should be considered as a general rule in cases where the processing involves profiling or monitoring, the technology decides about the access to services or opportunities or if the processing involves particularly sensitive data or vulnerable individuals.

Even if high risk for the individual is not detected, the DPIA serves as the basic document on data protection for the processing activity being a document which is dynamic and changes in time.

The European Data Protection Board (EDPB) published a guide on which data processing activities would need a data protection impact assessment (DPIA).

There have been differing opinions amongst the member states national Data Protection Authorities on when a DPIA is necessary and to which processing activities the procedure should apply.

The EDPB guide’s purpose is to form a harmonized approach to cross-border personal data processing activities that can have an effect on the natural person’s free movement within the EU.

Currently, the EDPB guidelines of WP248 on data protection impact assessment (DPIA) serve as a basis for the national authorities to set their own requirements for processing activities that requires data protection impact assessments.

However, the national requirements can turn out to be stricter compared to the EDPB standards but since personal data processing often has cross-border elements the standards of EDPB should be followed.

More to read on this topicRecords of processing activities in GDPR Article 30

Are you GDPR compliant? ​

Assess whether you have to comply with the GDPR in the first place and if you do, what is the level of preparedness of the GDPR compliance. Also check out the answers for the frequently asked questions.
Share on facebook
Share on linkedin
Share on twitter
Share on pinterest
Share on email

Get your compliance organized with proper GDPR tools.
Contact us for a demo and get access to 14-day trial.

Save time and be confident

Latest Posts
The EU-U.S. Data Privacy Framework: A Transatlantic honeymoon for data flows, but for how long?

The EU-U.S. Data Privacy Framework: A Transatlantic honeymoon for data flows, but for how long?

The European Commission concluded that the United States ensures adequate protection for personal data transferred from the EU to U.S....
A Comprehensive Guide to Personal Data Mapping

A Comprehensive Guide to Personal Data Mapping

Introduction Data privacy and security are of utmost concern in the digital era of today, especially when it comes to...
Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

What is a Data Processing Agreement (DPA)? A Data Processing Agreement (DPA) is a legally binding document to be entered...
Direct marketing rules and exceptions under the GDPR

Direct marketing rules and exceptions under the GDPR

Direct marketing includes text messages (SMS) and emails that a customer receives from a product or service provider. But activities...
Transmitting personal data to third countries

Transmitting personal data to third countries

The GDPR has put strict rules in place, when it comes to data transfer to third countries or international organizations. Which...
Records of processing activities in GDPR Article 30

Records of processing activities in GDPR Article 30

What are the records of processing activities (ROPA)? Article 30 of the EU General Data Protection Regulation (GDPR) requires organisations...
10 Great GDPR Software Tools for Compliance in 2023 (Review + Pricing)

10 Great GDPR Software Tools for Compliance in 2023 (Review + Pricing)

In this article, we will introduce you to some useful GDPR software tools which may help you reach GDPR compliance...
Personal Data Breach Reporting Requirements Under the GDPR

Personal Data Breach Reporting Requirements Under the GDPR

What is Data Breach? According to General Data Protection Regulation (GDPR), a personal data breach is a security incident that...
Data Protection Authorities (DPA)

Data Protection Authorities (DPA)

Data Protection Authorities (DPA) Data Protection Authorities (DPA) are independent public authorities that supervise, through investigative and corrective powers, the...
GDPR compliance checklist for controllers

GDPR compliance checklist for controllers

This is a simple GDPR compliance checklist for data controllers that you can use to ensure you have considered most important...