Data protection impact assessment (DPIA)
An impact assessment for high-risk processing, and checkpoints that build privacy into projects, systems and procurement from the start rather than correcting it afterwards.
Who it is for and when
Suits organisations about to introduce a new system or a new high-risk processing activity, or that have been asked to produce an impact assessment before signing a contract.
- You are introducing a system that processes sensitive personal data or monitors systematically.
- A customer or procurement requires a DPIA and documentation before contract.
- You want to know whether a planned processing activity even requires an impact assessment.
- Privacy questions come up too late in your projects, once the solution is already built.
What we do
- Is an impact assessment required?. We assess whether the processing requires an impact assessment under Article 35, and document that assessment even when the conclusion is that it is not required.
- Describing the processing. Purpose, legal basis, categories of personal data and data subjects, recipients, transfers and retention periods are documented.
- Risk to data subjects. We assess the risks to the people the data is about, not only the risk to the business. That is the assessment Article 35 asks for.
- Safeguards and residual risk. Measures are proposed to reduce the risks: data minimisation, pseudonymisation, encryption, access restriction and retention limits, with residual risk assessed after the measures.
- Checkpoints in the project flow. We add the assessment as a checkpoint in your project and procurement flows, so that the next processing activity is caught before it goes live.
What you get
- A completed and documented impact assessment
- A risk assessment from the data subjects’ perspective
- Proposed safeguards with residual risk assessed
- Privacy checkpoints in projects and procurement
- Documentation that holds up to a question from a customer or supervisory authority
Scope and price
Per assessment, or as part of a project where several processing activities are reviewed. The scope is driven above all by how well the processing is described when we start.
The price varies with the complexity of the processing. You get an estimated cost proposal and, where possible, a fixed price.
How it works
- A first conversation. We listen to your situation and explain how we usually set up the work. You get our assessment straight away, free of charge.
- A proposal with scope and price. A short written proposal with what is included, what you get, who does the work and what it costs.
- Delivery and handover. We work together with your organisation, report continuously and hand over so that you can maintain the result yourselves.
Frequently asked questions
When is an impact assessment required?
When processing is likely to result in a high risk to data subjects, under Article 35. Systematic monitoring, sensitive data at scale and new technology are typical cases. We make the assessment and document it even when the conclusion is that a DPIA is not required.
How long does a DPIA take?
It depends on how well the processing is described. If purpose, data and recipients are known it goes quickly. If they are not, the mapping is the largest part of the work.
Can you produce the assessment ahead of a procurement?
Yes. It is common for a customer or procurement to require it before contract, and we then produce it in the form requested.
Do you have a processing activity that needs assessing?
Contact us