When is a DPIA required?
A data protection impact assessment examines how intended processing may affect people. GDPR Article 35 requires the controller to conduct a DPIA before processing that is likely to result in a high risk to individuals’ rights and freedoms. Its nature, scale, context and purposes matter. Check the applicable lists and guidance from the competent supervisory authority. An ISO certificate does not determine whether this legal obligation applies.
What should the assessment cover?
Article 35 includes a description of processing and purposes, an assessment of necessity and proportionality, risks to individuals, and measures to address those risks. Seek advice from the data protection officer where one is designated. Where appropriate, seek views from affected individuals or their representatives. Retain the reasoning behind decisions, including why an alternative approach was rejected.
| Area | Practical working question |
|---|---|
| Processing | What data moves where, for what purpose and under whose responsibility? |
| Necessity | Could the purpose be achieved with less data or a less intrusive approach? |
| Impact | What harm or restrictions could individuals experience? |
| Safeguards | Who implements the chosen measures and how will their operation be checked? |
| Decision | What risks remain and what needs to happen next? |
Connect the DPIA to privacy management
ISO/IEC 27701:2025 is an independent privacy information management system (PIMS) standard. In your own records, use the same processing identifier in the processing register, DPIA and action tracker. This helps you trace a supplier change through the relevant assessments. It is a practical arrangement, not a prescribed software template. Keep legal grounds and consequences for individuals visible; a security risk assessment does not automatically answer every privacy question.
Fictional example: employee monitoring
A fictional employer plans to introduce software that records work activities. The project team first describes the data collected, who sees the results and what decisions use them. It considers a less intrusive alternative and involves privacy expertise. The action tracker includes access restrictions, retention periods and checks before launch. The team assesses the DPIA obligation against the specific design. This example does not determine whether an existing organisation’s processing is lawful.
Decide before launch and review changes
Where high risk remains without sufficient measures to mitigate it, prior consultation with the supervisory authority under Article 36 is relevant. Internal approval does not replace that step. Article 35 calls for review where necessary, at least when the risk associated with processing changes. Compare changes to purposes, data, suppliers and technology with the earlier assessment. See also records of processing and the comparison of GDPR and ISO 27701.