A Data Protection Impact Assessment is a structured process for identifying, evaluating and mitigating the risks that a planned data-processing activity poses to the rights and freedoms of individuals. It documents the nature, scope, context and purposes of processing, assesses necessity and proportionality, and records measures that reduce identified risks. Under the General Data Protection Regulation it is mandatory where processing is likely to result in high risk, such as large-scale profiling or use of sensitive data. It is a core accountability instrument linking privacy-by-design to demonstrable compliance.

Overview

  • A DPIA helps organisations identify and minimise the data-protection risks of a project before personal data is processed. It documents what data is processed, why, how and by whom, then weighs necessity and proportionality against the rights of the people affected.
  • It is both a legal obligation under the General Data Protection Regulation for high-risk processing and a practical tool for embedding privacy considerations early, where they are cheapest and most effective to address.

Key aspects

  • A systematic description of the processing operations and their purposes.
  • An assessment of necessity and proportionality relative to those purposes.
  • An evaluation of the risks to the rights and freedoms of data subjects.
  • The measures envisaged to address those risks, including safeguards and security controls, and consultation with the data protection officer or supervisory authority where required.

Applications

  • Large-scale processing of sensitive or special-category data.
  • Systematic profiling, automated decision-making and behavioural monitoring.
  • Deployment of new surveillance, biometric or tracking technologies.
  • Onboarding of new vendors or systems that handle personal data.

Provenance