When it is required
Article 35 of the GDPR requires a DPIA for processing likely to result in a high risk, and gives three examples: systematic and extensive profiling with significant effects on people, large scale processing of special categories of data, and large scale systematic monitoring of publicly accessible areas. The AEPD publishes a list of processing types that require one in Spain, such as large scale use of biometric data, employee monitoring or the use of new technologies on personal data.
What it contains
A systematic description of the processing and its purposes, an assessment of whether it is necessary and proportionate, an analysis of the risks to the people whose data is processed, and the measures planned to address them, including security measures. The DPO, if there is one, must be consulted.
If the risk remains high
When the DPIA concludes that a high risk remains after the planned measures, the organisation must consult the supervisory authority before starting the processing (Article 36).
DPIA and security risk assessment
A DPIA looks at risks to people, while a security risk assessment looks at risks to the organisation's information. They overlap and should feed each other: many DPIA measures are security controls such as encryption, access control and logging. New uses of AI are a frequent trigger for a DPIA, alongside obligations under the EU AI Act.




