The data protection impact assessment is a structured risk analysis for processing operations that are likely to result in a high risk to data subjects.
When is a DPIA mandatory?
It is mandatory, for example, for large-scale monitoring or the processing of sensitive data. The outcome is a set of documented measures that reduce the risk to an acceptable level.
The GDPR cites as typical examples the systematic evaluation of personal aspects with significant effects, for example through profiling, large-scale processing of special categories and systematic large-scale monitoring of publicly accessible areas. The German supervisory authorities have also published a list of processing operations for which a DPIA must always be carried out.
Content and procedure
- systematic description of the processing and its purposes
- assessment of necessity and proportionality
- assessment of the risks to data subjects
- planned measures to address the risks
The data protection officer must be involved. If a high risk remains despite the measures, the supervisory authority must be consulted before processing begins.
Legal provisions
- Art. 35 GDPR
- Obligation, triggers and minimum content of the data protection impact assessment.
- Art. 36 GDPR
- Prior consultation of the supervisory authority.
- Art. 35(4) GDPR
- Supervisory authorities' lists of processing operations requiring a DPIA.