13.2 Completing Privacy and Data Protection Impact Assessments
Key Takeaways
GDPR Article 35 requires a DPIA before processing likely to result in a high risk, including systematic profiling with significant effects, large-scale special-category data, and large-scale monitoring of public areas.
European guidance lists nine criteria (such as evaluation or scoring, sensitive data, large scale, matching datasets, vulnerable people, and innovative technology); processing meeting two or more usually needs a DPIA.
A DPIA must describe the processing, assess necessity and proportionality, assess risks to individuals, and set out measures to address them (Article 35(7)).
If high residual risk remains, the controller must consult the supervisory authority before processing; the authority has up to eight weeks, extendable by six, to give advice (Article 36).
In the US, federal agencies conduct PIAs under the E-Government Act of 2002, many state laws require data protection assessments, and California's risk assessment rules have applied since January 1, 2026.
13.2 Completing Privacy and Data Protection Impact Assessments
Quick Summary: A privacy impact assessment (PIA) is a structured analysis of how a project collects, uses, shares, and protects personal data, what could harm individuals, and how to reduce that harm. The GDPR version, the data protection impact assessment (DPIA), is mandatory for high-risk processing. Privacy technologists supply the system description, data flows, threat analysis, and technical controls, and they verify that mitigations are actually built.
PIAs work best early, when design choices are still cheap to change. A PIA completed the week before launch can only document risk; one completed during design can remove it.
When Is an Assessment Required?
Under the GDPR
Article 35(1) requires a DPIA before processing that is "likely to result in a high risk to the rights and freedoms of natural persons," especially when using new technologies. Article 35(3) names three cases that always require one:
- (a) systematic and extensive evaluation of personal aspects based on automated processing, including profiling, that produces legal or similarly significant effects;
- (b) large-scale processing of special categories of data or criminal-offence data;
- (c) systematic monitoring of a publicly accessible area on a large scale.
Supervisory authorities also publish lists of processing types that require a DPIA. European guidance (WP29's WP248, endorsed by the EDPB) gives nine criteria; processing that meets two or more usually requires a DPIA:
| # | Criterion | Example |
|---|---|---|
| 1 | Evaluation or scoring, including profiling and prediction | Credit scoring, behavioral profiling |
| 2 | Automated decision-making with legal or similar effect | Automatic loan rejection |
| 3 | Systematic monitoring | Employee monitoring, public CCTV |
| 4 | Sensitive data or data of a highly personal nature | Health, biometric, location, financial data |
| 5 | Data processed on a large scale | National customer base |
| 6 | Matching or combining datasets | Joining purchase and location data |
| 7 | Data concerning vulnerable data subjects | Children, employees, patients |
| 8 | Innovative use or new technological solutions | Facial recognition, generative AI, IoT |
| 9 | Processing that prevents people from exercising a right or using a service | Blocklisting that denies service |
A threshold assessment (a short screening questionnaire) decides whether a full DPIA is needed and documents the decision either way.
In the United States
- Federal agencies must conduct PIAs for new or substantially changed systems that collect personally identifiable information under Section 208 of the E-Government Act of 2002, and usually publish them.
- State comprehensive privacy laws (for example, Virginia and Colorado) require data protection assessments before processing for targeted advertising, sale of personal data, certain profiling, and sensitive data, and regulators can request them. Colorado's rules specify detailed contents.
- California's CCPA regulations, effective January 1, 2026, require risk assessments for processing that presents significant risk, such as selling or sharing personal information, processing sensitive personal information, and using automated decision-making technology for significant decisions; businesses must submit summary information to the California Privacy Protection Agency, with the first submissions due by April 1, 2028.
Related Assessments
- Transfer impact assessments (TIAs) evaluate international transfers (Section 16.2).
- Fundamental rights impact assessments (FRIAs) are required by the EU AI Act for certain deployers of high-risk AI systems and can be combined with a DPIA.
- Legitimate interests assessments (LIAs) test whether legitimate interests can justify processing.
What a DPIA Must Contain
Under Article 35(7), a DPIA contains at least:
- A systematic description of the processing and its purposes, including any legitimate interest pursued.
- An assessment of the necessity and proportionality of the processing in relation to its purposes.
- An assessment of the risks to the rights and freedoms of data subjects.
- The measures envisaged to address the risks, including safeguards, security measures, and mechanisms to demonstrate compliance.
The controller must seek the advice of the DPO (Article 35(2)) and, where appropriate, the views of data subjects or their representatives (Article 35(9)). If the DPIA shows a high residual risk that the controller cannot mitigate, Article 36 requires prior consultation with the supervisory authority, which has up to eight weeks to give written advice, extendable by six weeks for complex cases.
A Practical PIA Workflow
Where the technologist contributes:
- Describe: data inventories, data flow diagrams, and lists of fields, systems, vendors, and retention periods.
- Identify risks: threat modeling with LINDDUN or PANOPTIC (Section 4.2), NIST's problematic data actions (Section 16.1), and attack scenarios such as re-identification or insider misuse.
- Evaluate: rate likelihood and severity of harm to individuals, not just to the organization.
- Mitigate: propose concrete controls such as minimization, pseudonymization, access restrictions, retention limits, consent flows, and transparency features, and estimate their effect on residual risk.
- Verify: confirm that controls were built and tested before launch, and link the DPIA to tickets and test results.
- Review: reassess when the processing changes, such as new data types, purposes, vendors, or AI features. A DPIA is a living document.
Useful tools include the UK ICO's DPIA template, the French CNIL's open-source PIA software, and NIST's Privacy Risk Assessment Methodology (PRAM) worksheets.
A retailer plans to combine loyalty-card purchases with app location data to score customers' likelihood of financial distress and adjust their credit offers automatically. How many WP248 DPIA criteria does this clearly meet, and what follows?
Several (scoring, automated decisions, combined datasets, sensitive data), so a DPIA is required.
The WP248 criteria apply only to public authorities, so a legitimate interests assessment is sufficient for a retailer.
None, because the retailer already holds both datasets, so combining them is not new processing that needs a DPIA.
Only one (large scale), so a DPIA is optional.
After completing a DPIA for a facial recognition entry system, a controller cannot reduce a high residual risk to employees to an acceptable level. What does the GDPR require next?
Notify affected employees within 72 hours after launch.
Proceed, because a completed DPIA is enough to show accountability.
Transfer the processing to a processor so the risk belongs to the vendor.
Consult the supervisory authority before starting the processing, under Article 36.
Which contribution from a privacy technologist adds the most value to a DPIA for a new data analytics platform?
Choosing the supervisory authority to consult based on the lowest fines
Producing accurate data flows, a threat analysis, concrete controls, and proof they were built
Writing the executive summary's legal conclusions on lawful basis and the balancing of interests
Approving the residual risk on behalf of the board so that the project can launch on schedule
Sections you finish are checked off in the contents.