Risk

What is a data protection impact assessment (DPIA)?

A data protection impact assessment (DPIA) is a documented risk assessment required under GDPR Article 35 when a type of processing is likely to result in a high risk to individuals' rights and freedoms, used to identify and reduce that risk before processing begins.

Definition

A DPIA is a structured assessment, required by GDPR Article 35, that describes a planned processing of personal data, evaluates its necessity and the risks to individuals, and sets out measures to address those risks.

Background

Under the GDPR, when processing is "likely to result in a high risk" to people's rights and freedoms, the controller must carry out a DPIA before starting. Article 35 gives examples such as large-scale systematic monitoring, large-scale processing of special-category (sensitive) data, and systematic evaluation based on automated processing including profiling. The assessment documents the processing, its purpose and necessity, the risks, and the safeguards; if high risk remains after mitigation, the controller must consult its supervisory authority.

Why it matters

A DPIA is both a legal obligation for high-risk processing and a practical tool: doing it early surfaces privacy risks while they are cheap to fix, and it evidences accountability, a core GDPR principle. Skipping a required DPIA is itself a compliance failure.

Step by step

  1. Describe the processing: what data, whose, why, how, and for how long.
  2. Assess whether the processing is necessary and proportionate to its purpose.
  3. Identify and evaluate the risks to the individuals involved.
  4. Define measures to reduce those risks (minimization, encryption, access controls, and similar).
  5. If high risk remains, consult your supervisory authority before proceeding.

Examples

  • A company planning large-scale monitoring of employees runs a DPIA before rolling it out.
  • A product that profiles users with automated decision-making documents a DPIA covering the data, the risks, and the safeguards.

Common mistakes

  • Treating the DPIA as a one-time form instead of revisiting it when the processing changes.
  • Running the DPIA after processing has already started rather than before.
  • Failing to consult the supervisory authority when high residual risk remains.

FAQ

When is a DPIA required?

Under GDPR Article 35, when processing is likely to result in a high risk to individuals, including large-scale systematic monitoring, large-scale processing of special-category data, and systematic automated evaluation such as profiling. Supervisory authorities also publish lists of processing that requires one.

Is a DPIA the same as a risk assessment?

It is a specific, privacy-focused risk assessment mandated by the GDPR. It shares methods with general risk assessment but has a defined legal trigger, required contents, and a consultation step for high residual risk.

Related

What is GDPR? → What is a risk register? → Do I need GDPR if I am a US company? →

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free