From Microsoft to Adobe: a selection of public DPIAs

What is a DPIA?
A DPIA (Data Protection Impact Assessment) is a mandatory assessment that organisations and public bodies must carry out if they intend to process personal data. This is because data processing often involves new systems, processes or newly acquired software that may collect data. It is mandatory to assess whether this is done correctly.
Would you like to know more about exactly what a DPIA is, when you need to carry one out and what is involved? Then read our blog: DPIA explained: when do you need one?
Umbrella DPIAs
Many of the DPIAs in the overview below are so-called ‘umbrella DPIAs’. This means that we base our assessment on the general use of the software in question. In other words, these DPIAs assess the risks associated with the general use of the software in question.
These ‘umbrella DPIAs’ often also include a technical analysis. This is because we look not only at whether organisations comply with the legal texts, but also at what actually happens to data. Sometimes this is not in line with the legal texts, which is why some reports are very comprehensive. That does not mean that a DPIA for your organisation will be equally comprehensive.
An organisation can then use the results as a basis for a DPIA tailored to its own situation – that is, for the data processing activities it carries out in daily practice using the software. An umbrella DPIA provides an important starting point for this.
Of course, we can also help organisations carry out a DPIA for their specific situation. After all, DPIAs can be complex. Read more about our DPIA services.
Public DPIAs
Below is a selection of DPIAs we have worked on that are publicly available:
- 2026 | Salesforce for the strategic supplier management of the Dutch government
- 2026 | Nextcloud Enterprise software for SURF
- 2026 | ESET for SLM Cloud
- 2026 | Adobe Creative Cloud & Document Cloud for SURF
- 2026 | Webex for the Dutch government
- 2026 | TOPdesk for SURF
- 2025 | AnsExam for SURF
- 2025 | Microsoft Copilot for SLM Rijk
- 2025 | Microsoft Copilot for SURF
- 2025 | Microsoft 365 Copilot (update) for SURF
- 2025 | EduGenAI for SURF
- 2025 | RedHat OpenShift for SLM Central Government
- 2024 | Google Workspace (audit) for SIVON and SURF
- 2024 | Google Chromebooks for education for SIVON and SURF
- 2024 | Zoom (update) for SURF
- 2024 | Microsoft 365 CoPilot for SURF
- 2024 | Amazon Web Services (AWS) for SLM Rijk
- 2022 | Facebook Pages for the Ministry of the Interior and Kingdom Relations + human rights impact assessment (HRIA)
- 2022 | Microsoft Teams, OneDrive and SharePoint Online for the Ministry of Justice and Security and SURF
- 2021 | Google Workspace for Education for SIVON and SURF
- 2020 | Microsoft Intune for the Ministry of Justice and Security
- 2020 | Microsoft Office 365 for the Ministry of Justice and Security
- 2019 | Microsoft Office 365 ProPlus (read the summary here)
- 2019 | Microsoft Office 365 online and mobile apps
- 2019 | Microsoft Windows 10 Enterprise (read the summary here)
The DPIAs in this overview show only part of our experience. In recent years, we have also carried out assessments of many systems and data processing operations that have not been made public. Examples include: TikTok, Salesforce, VMware and various sector-specific applications and data processing operations.
Want to know more?
Would you like to know more about DPIAs and our services? Please feel free to contact us at info@privacycompany.nl.
Last updated on 20 August 2026

