MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
A DPIA (Data Protection Impact Assessment), also known as GEB, is a mandatory risk assessment that you conduct in advance when data processing is likely to pose a high privacy risk. With a DPIA, you identify the privacy risks and take measures to mitigate them. Only then may you process the data. Below, you can read when a DPIA is mandatory and how to conduct one.
What is a DPIA (GEB)?
A DPIA — short for Data Protection Impact Assessment, in Dutch Gegevensbeschermingseffectbeoordeling (GEB) — is a tool to systematically identify the privacy risks of data processing. Based on this, you take measures to mitigate those risks. The DPIA is one of the obligations that the GDPR (General Data Protection Regulation) can impose to better protect the privacy of data subjects.
When is a DPIA mandatory?
The obligation to conduct a DPIA is stipulated in the GDPR and, for specific domains, in the Police Data Act (Wpg) and the Judicial and Criminal Procedure Data Act (Wjsg). The GDPR provisions are relevant for enterprises.
General rule: a DPIA is mandatory as soon as processing is likely to pose a high privacy risk . The law does not specify exactly when this is the case; as the controller, you must assess this yourself. European privacy supervisory authorities have drawn up a list of nine criteria for this purpose that you can use in this assessment. If you conclude that there is a likely high risk, you must conduct a DPIA first and only process the data afterwards.
Under the GDPR, a DPIA is mandatory in any case if you:
- processes special personal data on a large scale;
- follows people on a large scale and systematically in a publicly accessible area;
- systematically and extensively assesses personal aspects via automated processing (such as profiling) and bases decisions on this with consequences for the data subjects.
In addition, the Dutch Data Protection Authority (AP) has drawn up a list of processing activities for which a DPIA is mandatory, such as large-scale processing of genetic personal data in biodatabases. This list is not exhaustive: the obligation may also apply in other cases. TODO_VERIFY: the AP list and criteria may be updated — check the current version with the Dutch Data Protection Authority.
How do you conduct a DPIA?
There are various methods for conducting a DPIA. In principle, you are free to choose the method, as long as you comply with the basic requirements of the GDPR. A good DPIA offers, in any case:
- sufficient insight into the privacy risks of the processing;
- a description of the measures to mitigate those risks;
- the actual implementation of those measures.
If the DPIA shows that you cannot sufficiently mitigate the risks, you must consult with the Dutch Data Protection Authority before processing. This is called a prior consultation.
Frequently asked questions about the DPIA
What is the difference between a DPIA and a GEB?
There is no substantive difference: DPIA is the English term (data protection impact assessment), GEB the Dutch (gegevensbeschermingseffectbeoordeling). It concerns the same instrument.
Do I always have to conduct a DPIA?
No, only when processing is likely to pose a high privacy risk, or falls under the cases designated by the GDPR or the DPA list. In case of doubt, a pre-DPIA is advisable.
When do I need to consult the Dutch Data Protection Authority?
If the DPIA shows that you cannot sufficiently mitigate the high risks, you must conduct a prior consultation with the DPA before processing.
What happens if I do not conduct a DPIA when I am required to do so?
Wrongfully failing to conduct a mandatory DPIA is a violation of the GDPR and may lead to enforcement by the Dutch Data Protection Authority.
Need help conducting a DPIA?
Conducting a DPIA is complex, but as an entrepreneur, you cannot ignore privacy regulations. We advise you on whether a DPIA is mandatory, on its implementation, and on measures to mitigate risks.
Read more about our expertise regarding the DPIA and privacy and data protection. Also view our GDPR package or schedule a no-obligation consultation.