Expertise

DPIA: Data Protection Impact Audit

Specialized legal assistance for entrepreneurs, directors, and organizations

Technological innovations and data offer unprecedented opportunities. The more data, the better, as data increases the value of the organization. Due to strict privacy regulations, legal risks have increased enormously, which can have serious consequences for the continuity of the organization. A large amount of data can also lead to increased liability. Our Privacy Team helps the organization navigate the complex data protection regulations.

  • We worked for, among others:
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner
  • MKBjuristen.nl partner

What we do

In certain cases, a data protection impact audit (DPIA) will need to be conducted within an organization. The privacy specialists within our practice group can provide legal support for a DPIA. The organization's risks and measures stem from a DPIA. Consequently, measures can be taken following a DPIA to minimize these risks. Our practice group can also provide advice regarding the implementation of these measures.

Questions about a DPIA? Please contact us.

What is a DPIA (Data Protection Impact Assessment)?

A DPIA – referred to as a Data Protection Impact Assessment in the General Data Protection Regulation (GDPR) – is a tool to identify and assess privacy risks prior to data processing. This obligation follows from Article 35 of the General Data Protection Regulation. A DPIA is not a formality after the fact: you carry it out before processing begins, precisely to identify risks to the rights and freedoms of data subjects in a timely manner and to take appropriate measures. Whether you are an international group launching a new customer platform or the baker on the corner considering camera surveillance: the legal standard is the same, only the scale differs. This page falls within our Privacy and Data Protection.

When is a DPIA mandatory?

Pursuant to Article 35(1) of the General Data Protection Regulation, a DPIA is mandatory when processing – particularly when using new technologies – is likely to entail a high risk to the rights and freedoms of natural persons. Article 35(3) lists three situations in which a DPIA is mandatory in any case:

  • systematic and extensive assessment of personal aspects based on automated processing, including profiling, to which legal consequences are attached;
  • large-scale processing of special categories of personal data (Article 9 GDPR) or of data concerning criminal convictions (Article 10 GDPR);
  • systematic and large-scale monitoring of publicly accessible spaces.

In addition, the European Data Protection Board (EDPB) has established nine criteria; if two or more of these are met, a DPIA is in principle required. Furthermore, the Dutch Data Protection Authority has established a list of processing activities for which a DPIA is always mandatory, such as covert investigations, blacklists, fraud prevention, credit scoring, processing of health or genetic data, camera surveillance, employee monitoring, location and communication data, the Internet of Things, profiling, and biometric data. Are you unsure whether your processing falls under these categories? Our lawyers and in-house counsel will assess this based on your specific situation.

What must a DPIA contain?

Article 35, paragraph 7 of the General Data Protection Regulation stipulates that a DPIA must contain at least:

  • a systematic description of the intended processing operations and the purposes of the processing;
  • an assessment of the necessity and proportionality of the processing operations in relation to those purposes;
  • an assessment of the risks to the rights and freedoms of the persons concerned;
  • the intended measures to address those risks, including safeguards, security measures and mechanisms to ensure the protection of personal data.

If your organization has appointed a Data Protection Officer, you must seek their advice pursuant to Article 35(2) of the General Data Protection Regulation. See also our page on the Data Protection Officer (DPO).

The step-by-step plan: this is how a DPIA works

A thorough DPIA follows a fixed structure. We guide that process from start to finish:

  1. describe the processing, the data flows, the parties involved and the purposes of the processing;
  2. assess whether there is a lawful basis and whether the processing is necessary and proportionate;
  3. identifying and assessing the risks for stakeholders;
  4. establishing appropriate technical and organizational measures to mitigate the risks;
  5. recording the outcomes and, where appropriate, consulting the parties involved or their representatives;
  6. periodically reviewed when the risk of processing changes.

We tailor the depth to your organization – from a comprehensive assessment for an international group to a workable, proportionate approach for the small business owner.

Prior consultation with the Dutch Data Protection Authority

If the DPIA indicates that a processing operation poses a high risk that you cannot mitigate through reasonable measures, you are required under Article 36 of the General Data Protection Regulation to consult the Data Protection Authority before commencing the processing. Our lawyers handle this prior consultation, conduct the discussions with the supervisory authority, and translate the response into concrete next steps.

Risks of omitting a DPIA

The wrongful failure to conduct a mandatory DPIA is punishable by a fine in itself. Pursuant to Article 83(4) of the General Data Protection Regulation, the Dutch Data Protection Authority may impose a fine of up to €10 million or, for enterprises, up to 2% of global annual turnover – in addition to potential liability towards data subjects and reputational damage. Moreover, a well-documented DPIA is important evidence for the accountability obligation (Article 5(2) GDPR). A DPIA often goes hand in hand with a broader privacy audit and a comprehensive data breachprotocol.

How MKB Juristen helps you with a DPIA

At MKB Juristen, lawyers and in-house counsel work together in mixed teams. This means you receive both a high-quality legal assessment and practical, implementable guidance. We help you determine whether a DPIA is mandatory, conduct the DPIA together with you, advise on the measures to be taken, and guide their implementation. Whether you are an international group or the baker on the corner, we translate the requirements of the General Data Protection Regulation to your scale and sector.

Frequently asked questions about the DPIA

Is a DPIA mandatory for every organization?

No. A DPIA is only mandatory when a processing operation is likely to pose a high risk to data subjects, or when the processing is on the list of the Dutch Data Protection Authority. For many small processing operations, a DPIA is not necessary, but it is advisable to document that assessment.

Who carries out the DPIA?

The controller is responsible for the DPIA. If there is a Data Protection Officer, their advice is sought. We provide legal and substantive support for the implementation.

How often must a DPIA be reviewed?

A DPIA is reviewed when the risk of processing changes, for example due to new technology, new purposes, or a changed data flow.

What is the difference between a DPIA and a privacy audit?

A DPIA focuses on the risk assessment of a specific (intended) processing activity, while a privacy audit tests your organization's broader GDPR compliance. Both complement each other.

Questions about a DPIA?

Please feel free to contact us. Our privacy specialists are happy to assist you – from the initial assessment of whether a DPIA is necessary through to the implementation of the measures.

Mr. Jaime Boogaers
Mr. Jaime Boogaers
Corporate Law · Lawyer

In specialized legal cases, it is not just about the legal rule. It is also about evidence, timing, negotiating position, and the business implications of every step.

What we help with

We assist entrepreneurs and organizations with legal questions where careful assessment, strategy, and execution are important.

  • Assessment of your legal position
  • Analysis of contracts, decisions, correspondence, and supporting documents
  • Advice on liability, defense, and strategy
  • Drafting or reviewing legal correspondence
  • Negotiation with counterparty, trustee, shareholder or advisor
  • Guidance during escalation, proceedings, or settlement

When should you call in a specialist?

Legal assistance is particularly valuable when the stakes are high, deadlines are running, or when an incorrect response could weaken your position.

  • There is a claim, demand, or notice of liability
  • You are unsure whether to respond, negotiate, or litigate
  • There are major financial or reputational risks
  • The other party exerts pressure or uses short deadlines
  • You want to prevent a response from being used against you later
  • You want to know in advance what is legally and commercially sound

Assess first, then respond

In specialized cases, an initial response can be decisive for the subsequent course of action. An admission, incomplete explanation, or the wrong tone could be used against you later. Therefore, we first assess exactly what is being alleged, which facts have been established, which documents are missing, and which strategy aligns with your best interests.

Our approach

You will not receive an abstract legal account, but a practical assessment of your position, risks, and next steps.

01

Intake and initial assessment

We will briefly discuss the situation, the available documents, and your primary interests.

02

Analysis of position and risks

We assess your legal position, supporting documents, deadlines, and possible next steps.

03

Strategic advice

You will receive concrete advice on the best course of action: responding, negotiating, settling, or litigating.

04

Execution

We assist with correspondence, negotiation, litigation strategy, or further legal assistance.

Specialists for entrepreneurs

We combine legal analysis with practical experience in cases for entrepreneurs, directors, and organizations.

Our team is engaged to provide legal and strategic support in the field of privacy and data protection. We offer this support to a wide variety of clients, ranging from companies to non-profit organizations. Our practice group's excellent knowledge of privacy law and data protection results in sound and pragmatic advice. In addition to outlining the legal framework, our lawyers and legal experts specialize in implementing this advice within the organization.

Frequently asked questions about DPIA: data protection impact audit

Below, we answer frequently asked questions about this area of ​​law, our approach, and seeking legal assistance.

When is legal advice advisable?

Legal advice is wise as soon as pressure arises, deadlines are running, an opposing party takes a position, or when the financial or strategic interests are significant.

Can MKB Juristen also help if there is already a conflict?

Yes. We assess your legal position, advise on strategy, and can assist with correspondence, negotiation, defense, or further legal steps.

How much does specialist legal advice cost?

Specialist advice is provided on an hourly basis in principle. Where possible, we provide clarity in advance regarding the expected approach, costs, and next steps.

Can I have a no-obligation consultation first?

Yes. You can request a free consultation. We will briefly discuss your situation and indicate which course of action is likely the sensible one.

Discuss your position

Do you want to know where you stand legally or what step is sensible? Discuss your situation with a lawyer or in-house counsel.

Contact us

Contact us

Leave your details. We will contact you to briefly discuss your situation.

Contact us

Jaime Boogaers

Want to know more about our services?
Then contact our specialists.

Newsletter for entrepreneurs

Receive practical legal tips in your mailbox

Register now

Enter your email address and receive our newsletter.

No spam. Only legal tips.
By registering, you agree to our privacy statement.
SME Lawyers at the Chamber of Commerce Source: Chamber of Commerce 2019
Free consultation