DPIA explained: when do you need one?

DPIA: what and when?
A DPIA is a structured risk assessment used to identify the privacy risks associated with a new or modified data processing activity and to define appropriate measures to mitigate those risks. Conducting a DPIA is a legal requirement when a processing activity is likely to result in a high risk to the rights and freedoms of individuals. In practice, a DPIA is often triggered by the implementation of new applications, systems, or business processes.
To determine whether your new or modified processing activity is likely to pose a high risk, there are two key points of reference. The first is the mandatory DPIA list published by the Dutch Data Protection Authority (AP), which specifies processing activities for which a DPIA is always required. The second is the set of 9 criteria established by the European supervisory authorities (EDPB). If your processing activity meets two or more of these criteria, a DPIA is generally required. For example, if you plan to process sensitive personal data, process personal data on a large scale, or use profiling, a DPIA is likely to be mandatory. Not sure whether your processing activity poses a high risk? We'd be happy to help you assess the situation.
1. Description of the processing activity
A DPIA begins with a factual description of the processing activity, whether it concerns a system or a business process. Which personal data is being processed, whose data is involved, and for what purpose? Who has access to the data, both within and outside the organisation, and what security measures are in place to protect it? To build a complete and accurate picture, our privacy experts review the documentation you provide, such as contracts, user manuals, and privacy notices. We also interview employees from across your organisation. As external advisors, we often identify issues that have become routine or overlooked internally. This fresh perspective can reveal information and risks that might otherwise go unnoticed. This factual description forms the foundation for the following stages of the DPIA.
2. Assessing the lawfulness of the processing activities
The second stage of a DPIA consists of a legal assessment. Our privacy experts evaluate whether the processing activity is lawful. They do this by determining whether there is a valid legal basis, whether the processing complies with the principles of the General Data Protection Regulation (GDPR) such as data minimisation, purpose limitation, and integrity and confidentiality and whether the rights of data subjects are adequately protected. If there is no valid legal basis, or if the processing is otherwise found to be unlawful, this in itself constitutes a privacy risk. Although the GDPR is the primary legal framework for assessing processing activities, it is not the only relevant legislation. Depending on your organisation's sector and the nature of the processing, our privacy experts also consider other applicable laws and regulations, as well as sector-specific guidelines and industry standards.
3. Identifying potential risks to data subjects
Based on the factual description and the legal assessment, we identify the risks associated with the processing activity. A DPIA focuses on the risks to the rights and freedoms of data subjects. These may include risks such as discrimination, exclusion, or unfair profiling. A DPIA also considers technical risks, such as the absence of two-factor authentication, a lack of logging, or storing logs for too long.
4. Measures to mitigate privacy risks
For every privacy risk identified during the DPIA, we define appropriate mitigation measures. These measures may be either technical or organisational in nature. Technical measures focus on protecting personal data and may include encryption, logging, monitoring, and access controls to prevent unauthorised access or misuse. Organisational measures focus on people and processes, such as implementing clear privacy policies, training employees, and establishing documented work instructions.
A DPIA is not an end point. Once the assessment has been completed, your organisation can begin implementing the recommended measures. Privacy Company and our partner PuraSec can also support your organisation with the implementation and any follow-up actions after a DPIA.
How we can help
Privacy Company has extensive experience conducting DPIAs for organisations across a wide range of sectors. From tailored assignments to assessments of widely used services.
Curious about what we can do for your organisation? We'd be happy to discuss your needs. Feel free to contact us without obligation.

