When is a DPIA legally required under GDPR?
A Data Protection Impact Assessment (DPIA) is legally required under the General Data Protection Regulation (GDPR) when a type of processing, particularly using new technologies, is “likely to result in a high risk to the rights and freedoms of natural persons.” This includes, but is not limited to, large-scale processing of special categories of data, systematic monitoring of a publicly accessible area, or processing operations involving automated decision-making with legal or similarly significant effects on individuals. The assessment must be conducted prior to the processing.
Practitioners must understand that the requirement for a DPIA is not merely a checklist item but a risk management exercise. The initial determination of whether a processing operation is 'likely to result in a high risk' often necessitates a preliminary screening, sometimes referred to as a 'threshold assessment.' This assessment helps identify triggers such as profiling, processing sensitive data, large-scale data collection, or combining datasets. Failure to conduct a legally required DPIA before processing, or conducting an inadequate one, can lead to significant regulatory scrutiny and penalties, as it demonstrates a lack of due diligence in protecting data subjects' rights.
Beyond the initial requirement, the DPIA serves as a critical tool for demonstrating accountability under GDPR Article 5(2). It forces organisations to proactively identify and mitigate data protection risks, fostering a 'privacy by design' approach. The process involves describing the processing, assessing necessity and proportionality, identifying and assessing risks, and outlining measures to address those risks. In cases where the DPIA indicates that the processing would still result in a high residual risk even after mitigation, organisations are obligated to consult with the relevant supervisory authority prior to commencing the processing, providing them with the DPIA results.
Sources
- GDPR Article 35(1)
- GDPR Article 35(3)
- GDPR Article 36(1)