Skip to main content
Back to knowledge base
Step-by-step

Conducting a DPIA: step-by-step guide

A Data Protection Impact Assessment (DPIA) is mandatory when processing is likely to result in a high risk to data subjects' rights. This step-by-step guide helps you conduct a DPIA per GDPR Art. 35.

28 March 20269 min read

When is a DPIA mandatory?

Art. 35(1) GDPR requires a DPIA when processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons.

Art. 35(3) lists three situations where a DPIA is always required:

  • Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similar effects are based
  • Large-scale processing of special categories of data (health data, criminal records, biometric data, etc.)
  • Systematic large-scale monitoring of publicly accessible areas (CCTV, Wi-Fi tracking, etc.)

Step 1: Describe the processing

Document the following elements:

  • Which personal data are processed
  • Whose data (categories of data subjects)
  • For what purpose
  • By whom (controller, processors, sub-processors)
  • For how long (retention periods)
  • Which technology is used

Step 2: Assess necessity and proportionality

  • Is the processing necessary for the purpose? Could it be achieved with less data?
  • What is the legal basis?
  • Are retention periods proportionate?
  • Are data subjects adequately informed?
  • Can data subjects exercise their rights?

Step 3: Identify risks

Map risks to data subjects:

  • Unauthorised access — what if third parties access the data?
  • Data loss — what if data is lost?
  • Inaccurate data — what if decisions are based on incorrect information?
  • Discrimination — could the processing lead to unequal treatment?
  • Loss of autonomy — are data subjects restricted in their choices?

Assess the likelihood and severity of each risk.

Step 4: Determine measures

  • Technical measures: encryption, pseudonymisation, access controls, logging
  • Organisational measures: policies, training, confidentiality agreements
  • Legal measures: DPAs, strengthening legal basis

Step 5: Assess residual risk

After implementing measures, assess whether the residual risk is acceptable. If the risk remains high despite measures, you must consult the supervisory authority (Art. 36 GDPR: prior consultation).

Step 6: Document and monitor

Record the DPIA in a document covering all assessments, risks, measures and residual risk. Review periodically, especially when the processing changes significantly.

Role of the DPO

If your organisation has a DPO, their advice must be sought when conducting a DPIA (Art. 35(2) GDPR).

Practical tips

  • Conduct the DPIA before starting the processing, not afterwards
  • Involve relevant departments (IT, legal, the department carrying out the processing)
  • Use a structured template to ensure nothing is overlooked
  • Link your DPIA to your processing register for a complete overview
  • Use DPAkit to conduct DPIAs in a structured way and link them to your vendors and processing activities

Manage DPIAs with DPAkit

DPAkit includes a DPIA module that lets you conduct and document data protection impact assessments in a structured way.

Start for free