Skip to content

DPIA and ISO 27701

A DPIA assesses privacy risks before processing likely to create high risk. Connect decisions and safeguards to your PIMS and revisit the assessment when risks change.

Book an informal conversation

ISO Ready helps you align policy, risk, and evidence, without endless document churn.

Get started with ISO Ready

When is a DPIA required?

A data protection impact assessment examines how intended processing may affect people. GDPR Article 35 requires the controller to conduct a DPIA before processing that is likely to result in a high risk to individuals’ rights and freedoms. Its nature, scale, context and purposes matter. Check the applicable lists and guidance from the competent supervisory authority. An ISO certificate does not determine whether this legal obligation applies.

What should the assessment cover?

Article 35 includes a description of processing and purposes, an assessment of necessity and proportionality, risks to individuals, and measures to address those risks. Seek advice from the data protection officer where one is designated. Where appropriate, seek views from affected individuals or their representatives. Retain the reasoning behind decisions, including why an alternative approach was rejected.

AreaPractical working question
ProcessingWhat data moves where, for what purpose and under whose responsibility?
NecessityCould the purpose be achieved with less data or a less intrusive approach?
ImpactWhat harm or restrictions could individuals experience?
SafeguardsWho implements the chosen measures and how will their operation be checked?
DecisionWhat risks remain and what needs to happen next?

Connect the DPIA to privacy management

ISO/IEC 27701:2025 is an independent privacy information management system (PIMS) standard. In your own records, use the same processing identifier in the processing register, DPIA and action tracker. This helps you trace a supplier change through the relevant assessments. It is a practical arrangement, not a prescribed software template. Keep legal grounds and consequences for individuals visible; a security risk assessment does not automatically answer every privacy question.

Fictional example: employee monitoring

A fictional employer plans to introduce software that records work activities. The project team first describes the data collected, who sees the results and what decisions use them. It considers a less intrusive alternative and involves privacy expertise. The action tracker includes access restrictions, retention periods and checks before launch. The team assesses the DPIA obligation against the specific design. This example does not determine whether an existing organisation’s processing is lawful.

Decide before launch and review changes

Where high risk remains without sufficient measures to mitigate it, prior consultation with the supervisory authority under Article 36 is relevant. Internal approval does not replace that step. Article 35 calls for review where necessary, at least when the risk associated with processing changes. Compare changes to purposes, data, suppliers and technology with the earlier assessment. See also records of processing and the comparison of GDPR and ISO 27701.

Primary sources for this topic

Frequently asked questions

Does ISO 27701 replace a DPIA?
No. The DPIA obligation comes from GDPR and the specific processing, not from holding a certificate. A PIMS can help organise assessments, advice and follow-up actions. Separately determine whether Article 35 applies and record how findings are addressed before processing starts, including any need for prior consultation with the supervisory authority.
When should an existing DPIA be reviewed?
Article 35 calls for review where necessary, at least when the risk associated with processing changes. Treat changes to purposes, data, recipients or technology as triggers to consider a review. Record what changed, how that affects the earlier conclusions and who will implement and check any actions that are needed.

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)