The data protection impact assessment has a poor reputation. It is treated as a formality triggered by a threshold, handed to the supplier implementing the processing, and filed away.
Yet the threshold is the easy part. The regulation requires one where processing is likely to result in a high risk to people’s rights and freedoms; the supervisory authority publishes a list of processing that requires one and a list of processing that does not. An hour’s reading is enough to place yourself.
What the exercise actually demands
The difficulty is not knowing whether to do it. It is bringing together information that is never held in one place:
- the exact purpose of the processing, stated by the business and not by IT
- the data actually collected, almost always more than was planned
- the retention periods actually applied, which usually differ from those stated
- the security measures actually in place at the processor, not the ones in its brochure
Not one of these four is held by a single person. That is what makes the exercise uncomfortable, and it is also what makes it useful.
Who should carry it
The controller. Not the supplier, which has a direct interest in concluding that the measures it proposes are sufficient. Not the data protection officer alone, whose role is to advise and verify, not to decide in the business’s place.
Handing the assessment to whoever implements the processing amounts to asking them to mark their own work. It does not produce a false document: it produces an honest one that never asks the awkward questions.
An impact assessment handed to whoever implements the processing does not lie. It simply never asks whether the processing was necessary.
What to expect from it
A useful assessment ends in decisions, not a score. It may lead to collecting less data, shortening a retention period, requiring encryption or a location, sometimes to dropping a feature whose benefit does not justify the risk.
An impact assessment assumes you know which processing activities exist and which are entrusted to third parties. That inventory is not a legal exercise: it is what a GDPR audit run as a gap analysis produces.
If it changes nothing about the project, that does not mean it endorses it: it means it was never really carried out. An assessment whose conclusion was settled before it began has documented nothing but the clear conscience of whoever commissioned it.
Common questions
When is a data protection impact assessment (DPIA) mandatory?
When processing is likely to result in a high risk to people’s rights and freedoms. The supervisory authority publishes a list of processing operations that require one and a list of those exempt: an hour’s reading is enough to know where you stand.
Who should carry out the data protection impact assessment?
The controller. Not the provider implementing the processing, which has an interest in concluding its measures are sufficient, nor the data protection officer alone, whose role is to advise and check, not to decide on the business’s behalf.
What should a DPIA produce?
Decisions, not a score: collecting less data, shortening a retention period, requiring encryption or a specific location, sometimes dropping a feature. An assessment that changes nothing in the project has, in practice, not been carried out.