Regulation · Filed · London · 7 min read

GDPR DPIA: When You Need One and How to Run It

A working guide to Data Protection Impact Assessments under GDPR Article 35 — triggers, methodology, consultation with supervisory authorities, and documentation.

By Cyber Inspect Editorial Board

The Article 35 trigger

A DPIA is required when processing is 'likely to result in a high risk to the rights and freedoms of natural persons' — especially systematic evaluation, large-scale sensitive data, or systematic monitoring.

A workable methodology

  • Describe the processing operations and purposes.
  • Assess necessity and proportionality.
  • Assess risks to data subjects.
  • Identify measures to mitigate those risks.
  • Consult the DPO and, where residual risk is high, the supervisory authority.
  • Document the DPIA and retain it for the life of the processing.