Skip to content
Call, 0511 – 47 55 58 11

Data protection impact assessment

An impact assessment is required where processing is likely to result in a high risk to the rights and freedoms of natural persons. Where a high residual risk remains, the supervisory authority has to be consulted beforehand.

The impact assessment is not a form but a look at risk from the perspective of the people affected. It belongs at the start of a project rather than at its end, because otherwise all it can do is confirm what has already been built.

The process

  1. Step 1: Check the threshold

    Is a high risk likely? That assessment has to be documented even where it comes out against carrying out a full impact assessment.

  2. Step 2: Describe the processing

    Purposes, categories of data, data subjects, recipients, retention and the legitimate interests where they are relied on.

  3. Step 3: Assess necessity and proportionality

    Is the processing needed in this form, or is there a less intrusive means that achieves the purpose just as well?

  4. Step 4: Risks and mitigations

    Name the risks from the perspective of data subjects and assign the measures that reduce them.

  5. Step 5: Residual risk and consultation

    Where a high risk remains, the authority has to be consulted before processing starts. Otherwise the assessment is documented and updated as things change.

Typical triggers

A project in planning?

The impact assessment belongs at the start, not before go-live.

Get in touch

Frequently asked questions

How do we know whether an assessment is required?

Art. 35(3) GDPR sets out standard examples, among them large-scale processing of special categories and systematic large-scale monitoring of publicly accessible areas. Alongside that, the supervisory authorities keep lists of processing for which they require an assessment. Where your project falls into no category, the assessment of that question still has to be documented.

Who carries out the impact assessment?

The controller is responsible. The advice of the data protection officer has to be sought, but the task cannot be pushed across to them. In practice it comes together from the business unit, IT and legal.

What does prior consultation mean?

Where a high risk remains despite the measures planned, the supervisory authority has to be involved before processing begins. That costs time and is regularly forgotten in project plans. Assessing early usually allows the project to be designed so that it does not come to that.

Related