GDPR › GDPR Documentation & Compliance

Data Protection Impact Assessment

You must conduct a DPIA when the processing of personal data poses a high risk to data subjects. This article outlines these requirements.

DPIA

Table of Contents

    Data Protection Impact Assessment (DPIA) 

    The GDPR  requires you to carry out a data protection impact assessment (DPIA) if the processing of personal data could have significant adverse effects for individuals.

    A DPIA is a detailed risk assessment that must comply with specific requirements outlined in Article 35 GDPR.

    When should you conduct a DPIA?

    You must conduct a DPIA if your data processing is likely to result in a high risk to individuals' rights and freedoms. Such risks include physical or financial harm, or serious impacts on privacy.

    Using new technology (such as iris scanning or artificial intelligence) could require a DPIA. However, simply implementing a new IT system does not automatically mean you're using new technology.

    Three situations where a DPIA is mandatory

    In accordance with Article 35(3) GDPR, you must always conduct a DPIA in these scenarios:

    1. Automated decision-making 

    When a systematic and extensive evaluation of personal details is carried out using technology to automatically process information and make decisions about individuals, a DPIA must always be conducted.

    For example, a football club checks fans for possible security risks before a major match by comparing ticket buyers against publicly available data. This process might lead to someone being denied entry, even if they have already bought a ticket. This potential impact means that a DPIA is required.

    2. Extensive use of sensitive personal data or criminal records

    If you process  large amounts of sensitive personal data or data related to criminal offenses, you must conduct a DPIA.

    In this context, "large amounts" can be assessed by considering the number of people affected, the volume of data, the duration of processing and the geographical scope of the processing.

    For example, a national platform for patient records processes sensitive personal data across a broad geographical area and over an extended period. A DPIA is required due to the scale and sensitivity of the data.

    3. Extensive public area surveillance

    If your organisation carries out large-scale surveillance of public spaces using video cameras, for example, you must conduct a DPIA.

    Surveillance has a significant impact on privacy because people may find it difficult to avoid being monitored or to control how their data is used.

    How to conduct a DPIA

    A DPIA is essentially a risk assessment, but it must meet specific GDPR requirements in terms of how it is conducted. In accordance with Article 35(7) GDPR, a DPIA must include at least the following elements:

    • Clearly outline what data is being processed, how it is being collected, stored, used and shared, and the reasons for processing.

    • Evaluate whether the data processing is essential to achieve its purpose and if there are less intrusive alternatives.

    • Identify potential risks, such as unauthorised access, data breaches or negative impacts on individuals.

    • Describe how you will reduce or manage the risks, which may include implementing technical security measures (encryption, access controls) or organisational measures (policies, staff awareness training).

    Below is a step-by-step approach outlining how to conduct a DPIA in compliance with these requirements.

    Describe your data processing

    When conducting a DPIA, the first step is to clearly describe the processing activity  that the assessment covers. This description should be similar to the information recorded in your records of processing activities:

    1. Clearly describe why the DPIA is necessary, what the processing aims to achieve and which business processes it supports.

    2. Identify the types of data being processed, where it comes from, the purpose of the processing and how long the data is stored.

    3. Determine who the data concerns, including whether it involves vulnerable groups such as children or patients.

    4. Describe the technology used for processing personal data.

    5. Explain how the processing impacts the individuals involved and society as a whole.

    6. Specify if data is shared with third parties  and provide details on how this is managed.

    Evaluate the legality

    Once you have described the processing activity, you must assess the lawfulness of the processing:

    1. Determine the legal basis of the processing.

    2. Assess whether the purpose is clear and reasonable and if the processing is necessary and appropriate.

    3. Explain how data accuracy is ensured and how data is deleted in a timely manner.

    4. Describe the security measures in place and how potential security breaches are managed.

    5. Outline how the rights of data subjects  are handled.

    6. Identify any data processors  involved and whether data is transferred outside the EU.

    Evaluate risk likelihood and severity

    After assessing the lawfulness of the processing, you should evaluate the risk to individuals' rights and freedoms. These risks are determined by assessing possible incidents with negative consequences for data subjects, such as:

    • Identity theft

    • Financial loss

    • Damage to reputation

    • Discrimination

    • Loss of confidential data

    The level of risk is determined by the likelihood of these incidents occurring and the potential negative consequences if an incident were to occur.

    Involvement of your data protection officer

    If your company has appointed a data protection officer, they must always be involved in preparing the DPIA.

    Stakeholder engagement

    When deemed relevant and appropriate, you should also involve the data subjects in the DPIA. This can be done, for example, by consulting interest groups for their assessment of the DPIA’s content.

    Risk reduction

    If the DPIA identifies a high risk, you must also explain how this risk will be mitigated. This could involve strengthening data security, adjusting workflows or restricting access to data. Clearly outline the measures to be implemented, who is responsible for them and the timeline for their completion.

    Involvement of the supervisory authority

    If your DPIA shows that the processing still involves a high risk for data subjects even after implementing organisational and technical measures, you must consult the supervisory authority  before proceeding with the processing.

    When submitting a consultation request to the supervisory authority, you must include the following information:

    • A clear description of the division of responsibilities between the data controller, data processors  and any joint controllers .

    • The purpose of the processing and how it is carried out in practice.

    • The protective measures in place.

    • The contact details of the data protection officer.

    • The DPIA itself.

    Update the DPIA

    The DPIA should be regularly reviewed and updated, especially if there any changes in the processing of personal data that could alter the risk landscape.

    DPIA template

    Conducting a DPIA is a significant responsibility because it impacts an organisation’s operations and planning. If you are tasked with carrying out a DPIA, you can use the template provided by the supervisory authority as a starting point.

    DPIAs and artificial intelligence

    If your DPIA involves the use of artificial intelligence, you should also review the AI Act, which governs how AI can be applied, especially in cases where the technology introduces new and significant risks that require special attention.

    Further reading

    You can find more information about DPIAs in the following sources:

    Frequently Asked Questions About Data Protection Impact Assessments

    What is a Data Protection Impact Assessment (DPIA)?

    A DPIA is a detailed risk assessment required under GDPR Article 35 when data processing is likely to result in high risk to individuals' rights and freedoms. It systematically evaluates the necessity and proportionality of processing, identifies risks, and proposes measures to mitigate them.

    When is a DPIA mandatory under GDPR?

    A DPIA is mandatory in three scenarios: (1) when automated decision-making systematically evaluates personal data and affects individuals, (2) when processing large amounts of sensitive personal data or criminal records, and (3) when conducting large-scale surveillance of public areas. It is also required whenever processing is likely to result in high risk to individuals.

    What must a DPIA contain?

    Under GDPR Article 35(7), a DPIA must include: a clear description of what data is processed and why, an assessment of whether processing is necessary and proportionate, an evaluation of potential risks to individuals such as unauthorised access or data breaches, and a description of measures to reduce or manage those risks.

    Who is responsible for conducting a DPIA?

    The data controller is responsible for conducting the DPIA. If a Data Protection Officer (DPO) has been appointed, their advice must be sought during the process. The data processor may also need to assist by providing relevant information about their processing activities and security measures.

    What happens if I do not conduct a required DPIA?

    Failing to conduct a DPIA when required is a GDPR violation that can result in significant fines. More importantly, it means potential high risks to individuals' data have not been identified or mitigated, increasing the likelihood of data breaches and harm to data subjects.

    Can I use a template for my DPIA?

    Yes, using a template is a practical approach to ensure your DPIA meets all GDPR requirements. Templates help standardise the process across your organisation, ensure consistency, and make it easier to document and review assessments. Your supervisory authority may also provide guidance or template recommendations.

    When should I consult the supervisory authority about my DPIA?

    You must consult your supervisory authority before processing if your DPIA identifies high risks that you cannot sufficiently mitigate. The authority will provide written advice and may use its powers to prohibit or restrict the processing if it would violate GDPR requirements.

    How does new technology trigger a DPIA requirement?

    Using new technology such as iris scanning, artificial intelligence, or advanced profiling systems may trigger a DPIA requirement because these technologies can create novel risks to individuals' rights and freedoms. However, simply implementing a new IT system does not automatically constitute new technology requiring a DPIA.

    How often should a DPIA be reviewed?

    DPIAs should be reviewed regularly and whenever there are significant changes to the processing activity, the technology used, the risk landscape, or the regulatory environment. It is good practice to review DPIAs at least annually or when new risks are identified.

    What is the difference between a DPIA and a regular risk assessment?

    While both assess risks, a DPIA is specifically required by GDPR and must follow particular requirements outlined in Article 35. It focuses on risks to individuals' rights and freedoms from data processing, must include an assessment of necessity and proportionality, and may require consultation with the supervisory authority if high risks cannot be mitigated.

    Processing activities

    .legal compliance platform Simplify your Data Protection Impact Assessments

    Use .legal to conduct and document DPIAs efficiently with built-in templates and risk assessment tools that ensure full GDPR compliance.
    • Built-in DPIA templates
    • Automated risk scoring and tracking
    • Complete documentation for auditors
    • Consultation workflow support
    +400 companies use .legal
    Region Sjælland
    Aarhus Universitet
    aj_vaccines_logo
    Realdania
    Right People
    IO Gates
    PLO
    Finans Danmark
    geia-food
    Vestforbrænding
    Evida
    Klasselotteriet
    NRGI1
    BLUE WATER SHIPPING
    Karnov
    Ingvard Christensen
    VP Securities
    AH Industries
    Lægeforeningen
    InMobile
    AK Nygart
    ARP Hansen
    DEIF
    DMJX
    Axel logo
    qUINT Logo
    KAUFMANN (1)
    SMILfonden-logo
    kurhotel_skodsborg
    nemlig.com
    Molecule Consultancy
    Novicell