A Data Protection Impact Assessment (DPIA) according to Art. 35 GDPR is a procedure used to assess the impact of certain processing operations on the protection of personal data. It is carried out to minimize the risks associated with data processing and to ensure that all data protection requirements are met. A practical example shows the importance of this procedure: by carrying out a data protection impact assessment, companies can reduce the risk of liability in the event of data leaks, cyberattacks or other data protection breaches. It also helps to avoid high fines from data protection authorities, which can occur if the rights of data subjects are not taken into account. Overall, the data protection impact assessment helps minimize both legal and financial consequences and strengthens the trust of data subjects.
The Data Protection Impact Assessment (DPIA) is of key importance for several reasons:
Article 35(1) of the GDPR states that a DPIA is necessary if the planned processing of personal data is likely to result in a high risk to the rights and freedoms of natural persons. To assess the risk of data processing, a group of experts has compiled a list of 9 criteria that increase the risk.
A Data Protection Impact Assessment is required if the risk to data subjects is high and at least two criteria are met Supervisory authorities are obliged to publish positive lists listing the necessary processing operations. Processing activities that meet only a few criteria can also pose a high risk and therefore also require a case-by-case assessment.
Article 35(7) of the GDPR states that a DPIA must include a systematic description of the intended processing operations, assessing the necessity and proportionality of the processing in relation to the purpose, and evaluating the risks to the rights and freedoms of the data subjects.
Our team of data protection experts has prepared a detailed guide on conducting a DPIA. From identifying data processing activities to documenting and reviewing your process, we'll walk you through it step-by-step.
The DPIA begins by identifying any processing activities that could pose a high risk to the rights and freedoms of individuals.
Assess the potential risks associated with these processing activities. Our experts will help you identify these risks and assess their consequences.
Develop measures to mitigate the identified risks. Our expert lawyers will assist you in selecting appropriate measures.
As companies increasingly introduce new technologies and cloud structures, a data protection impact assessment is useful to evaluate and mitigate the risks associated with the introduction of new technologies.
A DPIA becomes relevant if your company works with health data or plans to develop systems or apps that process sensitive data. As health data is particularly worthy of protection, the data protection requirements are particularly high at this point. It therefore not only helps to meet the legal requirements but also strengthens users' trust in the security of their data.
The frequency of carrying out a data protection impact assessment depends on several factors, including the type of data processing, the occurrence of changes or new risks, and the privacy relevance of the processing. In general, it is advisable to review and update the DPIA on a regular basis.
Article 35(2) of the GDPR states that the "controller" shall conduct the DPIA. As a rule, the data controller is responsible for carrying out the data protection impact assessment and for involving the advice of the data protection officer, internal or external.
Failure to conduct a required data protection impact assessment can result in significant penalties under the GDPR, including fines of up to €10 million or 2% of the global annual turnover of the previous fiscal year, whichever is greater.
The DPIA usually consists of three main parts:
A DPIA is necessary when data processing involves a high risk to the rights and freedoms of data subjects, such as sensitive data. The processing of sensitive data requires a careful assessment of the associated risks and potential impact on privacy to ensure compliance with data protection requirements, such as:
The data protection officer plays an essential role in the performance of the DPIA. He or she advises the controller or processor on how to conduct the DPIA, reviews the results, and ensures that the DPIA is conducted in compliance with the GDPR.
Not all companies are obliged to conduct a DPIA. The obligation to conduct a DPIA arises from Article 35 of the GDPR and only concerns processing operations that involve a high risk to the rights and freedoms of natural persons, in particular when using new technologies.
Although it is possible to perform a DPIA yourself, it is often advisable to consult a data protection law expert or a data protection officer due to the complexity of the requirements of the GDPR.
The GDPR provides a set of guidelines for conducting a DPIA. It is important that you familiarize yourself with these guidelines and incorporate them into your DPIA. In addition, consulting with an external data protection expert or data protection officer can help ensure compliance.