When is a DPIA required?
A controller must carry out a DPIA before processing likely to result in a high risk to people’s rights and freedoms, especially for systematic evaluation, large-scale sensitive data, or systematic public monitoring.
Operating sequence
- 01
Screen the processing before design decisions become expensive to change.
- 02
Describe necessity, proportionality, risks to people, controls, residual risk, consultation, and approval.
- 03
Set review triggers for purpose, model, data, scale, recipients, technology, incidents, and law.
Failure modes to avoid
- Scoring only organisational risk instead of risk to people.
- Completing the document after the system is already operating.
- Leaving residual high risk without prior supervisory consultation.
The source remains the authority.
GDPR Article 35 — EUR-Lex