Sign up for free for our Privacy & Security event on 28 May

From Microsoft to Adobe: a selection of public DPIAs

July 23, 2026
Privacy Company has been carrying out DPIAs for a wide range of organisations for many years. Several large organisations have published the DPIAs we have carried out. We have included a selection of these in this blog. This will give you an idea of the organisations for which we carry out DPIAs, the different types of software we assess, and the quality of our work.

What is a DPIA?

A DPIA (Data Protection Impact Assessment) is a mandatory assessment that organisations and public bodies must carry out if they intend to process personal data. This is because data processing often involves new systems, processes or newly acquired software that may collect data. It is mandatory to assess whether this is done correctly.

Would you like to know more about exactly what a DPIA is, when you need to carry one out and what is involved? Then read our blog: DPIA explained: when do you need one?

Umbrella DPIAs

Many of the DPIAs in the overview below are so-called ‘umbrella DPIAs’. This means that we base our assessment on the general use of the software in question. In other words, these DPIAs assess the risks associated with the general use of the software in question.

These ‘umbrella DPIAs’ often also include a technical analysis. This is because we look not only at whether organisations comply with the legal texts, but also at what actually happens to data. Sometimes this is not in line with the legal texts, which is why some reports are very comprehensive. That does not mean that a DPIA for your organisation will be equally comprehensive.

An organisation can then use the results as a basis for a DPIA tailored to its own situation – that is, for the data processing activities it carries out in daily practice using the software. An umbrella DPIA provides an important starting point for this.

Of course, we can also help organisations carry out a DPIA for their specific situation. After all, DPIAs can be complex. Read more about our DPIA services.

Public DPIAs

Below is a selection of DPIAs we have worked on that are publicly available:

The DPIAs in this overview show only part of our experience. In recent years, we have also carried out assessments of many systems and data processing operations that have not been made public. Examples include: TikTok, Salesforce, VMware and various sector-specific applications and data processing operations.

Want to know more?

Would you like to know more about DPIAs and our services? Please feel free to contact us at info@privacycompany.nl.

Last updated on 20 August 2026

Download
Frank
Director