Analysis

The DPIA: whether it is required is the easy question

Working out whether a data protection impact assessment is required takes an hour. Working out who runs it, and on what information, takes a great deal longer.

Overhead view of four people seated in a circle in a lobby, around a low table covered with documents
The assessment is a joint effort, but someone has to own it

The data protection impact assessment has a poor reputation. It is treated as a formality triggered by a threshold, handed to the supplier implementing the processing, and filed away.

Yet the threshold is the easy part. The regulation requires one where processing is likely to result in a high risk to people’s rights and freedoms; the supervisory authority publishes a list of processing that requires one and a list of processing that does not. An hour’s reading is enough to place yourself.

What the exercise actually demands

The difficulty is not knowing whether to do it. It is bringing together information that is never held in one place:

  • the exact purpose of the processing, stated by the business and not by IT
  • the data actually collected, almost always more than was planned
  • the retention periods actually applied, which usually differ from those stated
  • the security measures actually in place at the processor, not the ones in its brochure

Not one of these four is held by a single person. That is what makes the exercise uncomfortable, and it is also what makes it useful.

Who should carry it

The controller. Not the supplier, which has a direct interest in concluding that the measures it proposes are sufficient. Not the data protection officer alone, whose role is to advise and verify, not to decide in the business’s place.

Handing the assessment to whoever implements the processing amounts to asking them to mark their own work. It does not produce a false document: it produces an honest one that never asks the awkward questions.

An impact assessment handed to whoever implements the processing does not lie. It simply never asks whether the processing was necessary.

What to expect from it

A useful assessment ends in decisions, not a score. It may lead to collecting less data, shortening a retention period, requiring encryption or a location, sometimes to dropping a feature whose benefit does not justify the risk.

An impact assessment assumes you know which processing activities exist and which are entrusted to third parties. That inventory is not a legal exercise: it is what a GDPR audit run as a gap analysis produces.

If it changes nothing about the project, that does not mean it endorses it: it means it was never really carried out. An assessment whose conclusion was settled before it began has documented nothing but the clear conscience of whoever commissioned it.

Common questions

When is a data protection impact assessment (DPIA) mandatory?

When processing is likely to result in a high risk to people’s rights and freedoms. The supervisory authority publishes a list of processing operations that require one and a list of those exempt: an hour’s reading is enough to know where you stand.

Who should carry out the data protection impact assessment?

The controller. Not the provider implementing the processing, which has an interest in concluding its measures are sufficient, nor the data protection officer alone, whose role is to advise and check, not to decide on the business’s behalf.

What should a DPIA produce?

Decisions, not a score: collecting less data, shortening a retention period, requiring encryption or a specific location, sometimes dropping a feature. An assessment that changes nothing in the project has, in practice, not been carried out.


Next article

IT strategy: three costed scenarios beat one inventory

Read

A transformation to support?