MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
What is a DPIA (Data Protection Impact Assessment): it is a mandatory risk assessment in which you identify in advance the privacy risks that data processing poses and how you will mitigate those risks. This obligation is stipulated in Article 35 of the General Data Protection Regulation (GDPR). You are required to conduct a DPIA when processing is likely to pose a high risk to the rights and freedoms of the data subjects. The outcome determines whether you may simply proceed, must take additional measures, or must first consult the Dutch Data Protection Authority.
The short answer
- What: a structured assessment of privacy risks of a processing operation, carried out in advance.
- Legal basis: Article 35 GDPR (mandatory in case of high risk).
- Goal: Identify and manage risks before you start processing.
- Who: the controller, with the advice of the Data Protection Officer (DPO), if there is one.
- When mandatory: in case of high risk, large-scale special data, systematic monitoring, or profiling.
- Next steps: in the event of residual risk that cannot be covered, prior consultation with the Data Protection Authority follows (Article 36 GDPR).
What exactly is a DPIA data protection impact assessment?
A DPIA is not a form that you fill out afterwards, but an assessment that you carry out before you start processing. You describe the processing, assess the necessity and proportionality, and weigh the risks for the people whose data you process. Based on this, you take measures to reduce those risks. The GDPR calls this a data protection impact assessment. In practice, almost everyone uses the English term data protection impact assessment.
The DPIA is an instrument within the broader principle of accountability. The data controller must not only comply with the GDPR but also be able to demonstrate that they do so. A documented DPIA is one of the most important pieces of evidence for this.
When is a DPIA mandatory?
Article 35(1) of the GDPR mandates a DPIA when processing is likely to result in a high risk. Article 35(3) lists three situations in which this always applies:
- Systematic and extensive assessment of personal aspects based on automated processing, including profiling, with legal effects or similar effects on the data subject.
- Large-scale processing of special categories of data (such as health, race, religion) or criminal data.
- Systematic and large-scale monitoring of publicly accessible spaces, for example with camera surveillance.
In addition, the Dutch Data Protection Authority has published a list of processing activities for which a DPIA is mandatory in any case, such as large-scale processing of location data, processing of data concerning vulnerable persons, or large-scale monitoring of employees. In doubt? Then the criteria checklist of the European privacy supervisory authorities applies: the more criteria that apply, the more likely a DPIA is required.
The role of the Data Protection Officer
If your organization has appointed a Data Protection Officer (DPO), Article 35(2) of the GDPR requires you to seek advice from that DPO when conducting the DPIA. The duties of the DPO are set out in Article 39 of the GDPR: monitoring compliance, advising on the DPIA, and acting as a contact point for the Data Protection Authority. The DPO does not conduct the DPIA themselves, but assesses and advises. The ultimate responsibility remains with the controller.
Many SMEs are not required to have a DPO. The obligation applies primarily to large-scale processing of special categories of data or systematic monitoring. Even without a DPO, you can and must conduct a DPIA when Article 35 requires it.
What happens after the DPIA?
The outcome of the DPIA determines your next steps. If you can reduce the risks to an acceptable level through reasonable measures, you may start processing. If a high residual risk remains despite your measures, Article 36 of the GDPR requires you to consult the Data Protection Authority in advance. In principle, that supervisory authority will respond within eight weeks (with a possible extension of six weeks) and may advise or intervene.
A DPIA is not a one-off document. If the processing changes materially, for example due to new technology or an expansion of the purposes, you must revise the assessment. Supervisors advise reviewing a DPIA periodically.
A practical example: a healthcare SME wants to deploy an app that processes and analyzes clients' health data. Because this involves the large-scale processing of special categories of data, a DPIA is mandatory. The assessment shows that encryption and strict access rights sufficiently limit the risk, making prior consultation with the supervisory authority unnecessary.
Honest recommendation
You do not always need a lawyer. If you only process ordinary customer and employee data for normal business operations, without profiling, special categories of data, or large-scale monitoring, a DPIA is often not mandatory and a good processing register suffices. If you are unsure whether you fall under Article 35, or if it concerns special categories of data, profiling, or camera surveillance, legal review is advisable. An incorrect assessment regarding the DPIA obligation is one of the most common GDPR violations, and fines run into substantial amounts.
If you want to know for sure whether and how you need to conduct a DPIA, read on about the DPIA (data protection impact assessment), drafting a DPIA , and having a DPIA drafted.
Frequently Asked Questions
A DPIA (data protection impact assessment) is a mandatory assessment in which you identify the privacy risks of data processing in advance and determine measures to manage those risks. This obligation is set out in Article 35 of the GDPR.
When processing is likely to pose a high risk. Article 35(3) of the GDPR mentions profiling with legal effects, large-scale processing of special categories of data, and systematic monitoring of public spaces. The Dutch Data Protection Authority also has a list of mandatory cases.
The controller is responsible for the DPIA. If there is a Data Protection Officer, you seek advice from him (Article 35(2) GDPR). The DPO advises and assesses, but does not bear final responsibility.
The DPO monitors compliance with the GDPR, advises on the DPIA, and serves as the point of contact for the supervisory authority. These tasks are set out in Article 39 of the GDPR. The DPO does not carry out the DPIA themselves.
In that case, Article 36 of the GDPR requires you to consult the Data Protection Authority in advance before you start processing. The supervisory authority may advise or intervene and, in principle, responds within eight weeks.
Yes. A DPIA is not a one-off document. If the processing changes materially, for example due to new technology or additional purposes, you must revise the assessment. A periodic review is recommended.
Not always. For ordinary customer and employee data without profiling or special categories of data, a DPIA is often not mandatory. However, if it concerns special categories of data, profiling, or large-scale monitoring, a legal review is advisable, as an incorrect assessment can lead to fines.