Regulation · Filed · London · 7 min read
GDPR DPIA: When You Need One and How to Run It
A working guide to Data Protection Impact Assessments under GDPR Article 35 — triggers, methodology, consultation with supervisory authorities, and documentation.
By Cyber Inspect Editorial Board
The Article 35 trigger
A DPIA is required when processing is 'likely to result in a high risk to the rights and freedoms of natural persons' — especially systematic evaluation, large-scale sensitive data, or systematic monitoring.
A workable methodology
- Describe the processing operations and purposes.
- Assess necessity and proportionality.
- Assess risks to data subjects.
- Identify measures to mitigate those risks.
- Consult the DPO and, where residual risk is high, the supervisory authority.
- Document the DPIA and retain it for the life of the processing.