Regulation (EU) 2016/679

When a DPIA becomes operating evidence

A DPIA is a living decision record for high-risk personal-data processing, not a launch checklist.

Written and reviewed by Fredrik Surtell ·

When is a DPIA required?

A controller must carry out a DPIA before processing likely to result in a high risk to people’s rights and freedoms, especially for systematic evaluation, large-scale sensitive data, or systematic public monitoring.

Operating sequence

  1. 01

    Screen the processing before design decisions become expensive to change.

  2. 02

    Describe necessity, proportionality, risks to people, controls, residual risk, consultation, and approval.

  3. 03

    Set review triggers for purpose, model, data, scale, recipients, technology, incidents, and law.

Failure modes to avoid

  • Scoring only organisational risk instead of risk to people.
  • Completing the document after the system is already operating.
  • Leaving residual high risk without prior supervisory consultation.

The source remains the authority.

GDPR Article 35 — EUR-Lex