GlossaryCompliance operations

DPIA

Short answer

A DPIA (Data Protection Impact Assessment) is the analysis the GDPR requires before starting any processing of personal data that is likely to result in a high risk to people's rights and freedoms. It describes the processing, assesses its necessity and risks, and defines the measures to reduce them.

When it is required

Article 35 of the GDPR requires a DPIA for processing likely to result in a high risk, and gives three examples: systematic and extensive profiling with significant effects on people, large scale processing of special categories of data, and large scale systematic monitoring of publicly accessible areas. The AEPD publishes a list of processing types that require one in Spain, such as large scale use of biometric data, employee monitoring or the use of new technologies on personal data.

What it contains

A systematic description of the processing and its purposes, an assessment of whether it is necessary and proportionate, an analysis of the risks to the people whose data is processed, and the measures planned to address them, including security measures. The DPO, if there is one, must be consulted.

If the risk remains high

When the DPIA concludes that a high risk remains after the planned measures, the organisation must consult the supervisory authority before starting the processing (Article 36).

DPIA and security risk assessment

A DPIA looks at risks to people, while a security risk assessment looks at risks to the organisation's information. They overlap and should feed each other: many DPIA measures are security controls such as encryption, access control and logging. New uses of AI are a frequent trigger for a DPIA, alongside obligations under the EU AI Act.

Related terms

Keep reading on this topic

Running security as a repeatable process: policy management, risk registers, evidence upkeep, supplier assessment and audit readiness between cycles.

Go to the topic hub