Skip to content
Glossary

Data protection impact assessment (DPIA)

What is a data protection impact assessment?

A data protection impact assessment (DPIA) is a procedure used by companies or organizations to check whether planned data processing entails particular risks to the rights and freedoms of data subjects (Art. 35 para. 1 GDPR). It is mandatory if such risks are likely to be significant, for example in the case of extensive processing of sensitive data or systematic monitoring.

 

How do you carry out a data protection impact assessment?

As part of the DPIA, the planned processing operations are described and evaluated. Suitable measures are then defined to minimize the risks and comply with the requirements of the General Data Protection Regulation (GDPR). The results must be documented and submitted to the supervisory authority upon request.

What are examples of processing operations subject to DPIA?

  • Tracking systems for employees (GPS tracking)
  • Big data analyses with personal data
  • AI-based applicant selection
  • Health data processing through apps or wearables
  • Use of facial recognition