To undertake

What is a DPIA data protection impact assessment? Explanation and use

What is a DPIA (Data Protection Impact Assessment)? Explanation of the role, when you need it, and what to look out for for SMEs.

Published on August 27, 2026 by MKBjuristen.nl
Request a free quote Call 085 25000 44

MKB Juristen drafts custom legal documents

It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.

  • Custom contracts, terms and conditions, and legal documents
  • Budget-friendly and clear about the costs upfront
  • Request a free consultation or a no-obligation quote
Free consultation Request a free quote

What is a DPIA (Data Protection Impact Assessment): it is a mandatory risk assessment in which you identify in advance the privacy risks that data processing poses and how you will mitigate those risks. This obligation is stipulated in Article 35 of the General Data Protection Regulation (GDPR). You are required to conduct a DPIA when processing is likely to pose a high risk to the rights and freedoms of the data subjects. The outcome determines whether you may simply proceed, must take additional measures, or must first consult the Dutch Data Protection Authority.

The short answer

  • What: a structured assessment of privacy risks of a processing operation, carried out in advance.
  • Legal basis: Article 35 GDPR (mandatory in case of high risk).
  • Goal: Identify and manage risks before you start processing.
  • Who: the controller, with the advice of the Data Protection Officer (DPO), if there is one.
  • When mandatory: in case of high risk, large-scale special data, systematic monitoring, or profiling.
  • Next steps: in the event of residual risk that cannot be covered, prior consultation with the Data Protection Authority follows (Article 36 GDPR).

What exactly is a DPIA data protection impact assessment?

What is a DPIA (Data Protection Impact Assessment) explained for an SME entrepreneur

A DPIA is not a form that you fill out afterwards, but an assessment that you carry out before you start processing. You describe the processing, assess the necessity and proportionality, and weigh the risks for the people whose data you process. Based on this, you take measures to reduce those risks. The GDPR calls this a data protection impact assessment. In practice, almost everyone uses the English term data protection impact assessment.

The DPIA is an instrument within the broader principle of accountability. The data controller must not only comply with the GDPR but also be able to demonstrate that they do so. A documented DPIA is one of the most important pieces of evidence for this.

When is a DPIA mandatory?

Article 35(1) of the GDPR mandates a DPIA when processing is likely to result in a high risk. Article 35(3) lists three situations in which this always applies:

  • Systematic and extensive assessment of personal aspects based on automated processing, including profiling, with legal effects or similar effects on the data subject.
  • Large-scale processing of special categories of data (such as health, race, religion) or criminal data.
  • Systematic and large-scale monitoring of publicly accessible spaces, for example with camera surveillance.

In addition, the Dutch Data Protection Authority has published a list of processing activities for which a DPIA is mandatory in any case, such as large-scale processing of location data, processing of data concerning vulnerable persons, or large-scale monitoring of employees. In doubt? Then the criteria checklist of the European privacy supervisory authorities applies: the more criteria that apply, the more likely a DPIA is required.

The role of the Data Protection Officer

Data Protection Officer advises on the DPIA

If your organization has appointed a Data Protection Officer (DPO), Article 35(2) of the GDPR requires you to seek advice from that DPO when conducting the DPIA. The duties of the DPO are set out in Article 39 of the GDPR: monitoring compliance, advising on the DPIA, and acting as a contact point for the Data Protection Authority. The DPO does not conduct the DPIA themselves, but assesses and advises. The ultimate responsibility remains with the controller.

Many SMEs are not required to have a DPO. The obligation applies primarily to large-scale processing of special categories of data or systematic monitoring. Even without a DPO, you can and must conduct a DPIA when Article 35 requires it.

What happens after the DPIA?

Risk assessment and next steps after a DPIA

The outcome of the DPIA determines your next steps. If you can reduce the risks to an acceptable level through reasonable measures, you may start processing. If a high residual risk remains despite your measures, Article 36 of the GDPR requires you to consult the Data Protection Authority in advance. In principle, that supervisory authority will respond within eight weeks (with a possible extension of six weeks) and may advise or intervene.

A DPIA is not a one-off document. If the processing changes materially, for example due to new technology or an expansion of the purposes, you must revise the assessment. Supervisors advise reviewing a DPIA periodically.

A practical example: a healthcare SME wants to deploy an app that processes and analyzes clients' health data. Because this involves the large-scale processing of special categories of data, a DPIA is mandatory. The assessment shows that encryption and strict access rights sufficiently limit the risk, making prior consultation with the supervisory authority unnecessary.

Honest recommendation

Entrepreneur consults with a lawyer regarding the necessity of a DPIA

You do not always need a lawyer. If you only process ordinary customer and employee data for normal business operations, without profiling, special categories of data, or large-scale monitoring, a DPIA is often not mandatory and a good processing register suffices. If you are unsure whether you fall under Article 35, or if it concerns special categories of data, profiling, or camera surveillance, legal review is advisable. An incorrect assessment regarding the DPIA obligation is one of the most common GDPR violations, and fines run into substantial amounts.

If you want to know for sure whether and how you need to conduct a DPIA, read on about the DPIA (data protection impact assessment), drafting a DPIA , and having a DPIA drafted.

Frequently Asked Questions

What is a DPIA?

A DPIA (data protection impact assessment) is a mandatory assessment in which you identify the privacy risks of data processing in advance and determine measures to manage those risks. This obligation is set out in Article 35 of the GDPR.

When am I required to conduct a DPIA?

When processing is likely to pose a high risk. Article 35(3) of the GDPR mentions profiling with legal effects, large-scale processing of special categories of data, and systematic monitoring of public spaces. The Dutch Data Protection Authority also has a list of mandatory cases.

Who carries out the DPIA?

The controller is responsible for the DPIA. If there is a Data Protection Officer, you seek advice from him (Article 35(2) GDPR). The DPO advises and assesses, but does not bear final responsibility.

What is the role of the Data Protection Officer?

The DPO monitors compliance with the GDPR, advises on the DPIA, and serves as the point of contact for the supervisory authority. These tasks are set out in Article 39 of the GDPR. The DPO does not carry out the DPIA themselves.

What happens if a high residual risk remains?

In that case, Article 36 of the GDPR requires you to consult the Data Protection Authority in advance before you start processing. The supervisory authority may advise or intervene and, in principle, responds within eight weeks.

Do I need to revise a DPIA?

Yes. A DPIA is not a one-off document. If the processing changes materially, for example due to new technology or additional purposes, you must revise the assessment. A periodic review is recommended.

Do I always need a lawyer for a DPIA?

Not always. For ordinary customer and employee data without profiling or special categories of data, a DPIA is often not mandatory. However, if it concerns special categories of data, profiling, or large-scale monitoring, a legal review is advisable, as an incorrect assessment can lead to fines.

Please note: an article provides general information, but your legal situation may turn out differently.

A contract, conflict, or legal risk must always be assessed based on the facts, documents, evidentiary position, and interests. Are you in doubt? Have your situation assessed before you act.

Legal question regarding this article?

A blog provides explanation, but your situation often requires a concrete legal choice. MKB Juristen helps entrepreneurs with contracts, terms and conditions, GDPR documents, employment documents, disputes, and customized legal solutions.

Drafting, reviewing, and amending contracts
Legal Assistance Help with conflicts and disputes.
Expertise Specialist legal experts and lawyers.
Fixed rates. Clarity on costs in advance.

Latest articles

August 28, 2026

What is a DBA-proof contract for services? Explanation and use

What is a DBA-proof assignment agreement? Explanation of its function, when you need it, and what to look out for...

August 28, 2026

Sales agreement: common mistakes and pitfalls

The main pitfalls in a purchase agreement: common mistakes and how to avoid them. Practical explanation for SMEs.

August 27, 2026

Filling out the parental leave form: this is what belongs in it

Filling out a parental leave form? Read which sections it should include, common mistakes, and when to hire a lawyer.

August 27, 2026

What is a DPIA data protection impact assessment? Explanation and use

What is a DPIA Data Protection Impact Assessment? Explanation of the role, when you need it, and what to look out for...

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation