Read when a DPIA is needed, how to identify high privacy risks and which steps to take before processing begins.
What is a DPIA?
A data protection impact assessment describes the processing, its necessity, risks to data subjects and measures to reduce those risks. It is not a form to complete afterwards, but a decision-making tool before processing begins or changes substantially.
The assessment considers impacts on people, such as discrimination, loss of control, financial loss, exclusion or unwanted disclosure.
- the nature, scale, context and purpose of processing
- necessity and proportionality
- risks to rights and freedoms
- existing and additional measures
- residual risk and the decision on whether to proceed
How do you identify a likely high risk?
Look for combinations of large-scale processing, sensitive data, systematic monitoring, profiling, vulnerable groups, new technology and decisions with significant consequences.
Also check the official Dutch Data Protection Authority list of processing activities requiring a DPIA. The list is not exhaustive: processing that is not listed may still be likely to result in a high risk. Record your assessment if you conclude that no DPIA is needed.
Also check specific statutory exceptions. Article 35(10) GDPR may, for example, apply to processing for a legal obligation or public task that was already assessed when the legislation was adopted. Check all the conditions; a statutory legal basis alone does not provide an exemption.
How do you carry out the assessment in practice?
Involve the process owner, privacy and security specialists, the supplier and representatives of the people doing the work. Describe the actual data flows, rather than just the contract or policy.
What if a high residual risk remains?
Does the DPIA show that a high risk remains, with no adequate measures available to reduce it? The controller must then consult the Dutch Data Protection Authority before processing begins. Internal acceptance of the risk does not replace this obligation.
Check whether processing still matches the DPIA, at least whenever the risks change. Changes to purposes, data, technology or suppliers may trigger this review. Update the assessment and measures where necessary.
Frequently asked questions
Must a DPIA take place before you start?+
Yes. Where there is likely to be a high risk, the assessment should take place before processing begins.
Is a supplier's DPIA sufficient?+
Not automatically. Your purpose, configuration, data and user context determine the risk.
Who owns the DPIA?+
The controller remains responsible; privacy specialists, the DPO and other experts provide advice.
Sources and further reading
We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.
- EUR-Lex: GDPR, Articles 35 and 36Accessed on 20 September 2026
- Dutch Data Protection Authority: official mandatory DPIA list (Staatscourant)Accessed on 20 September 2026
Related articles
This is general guidance and does not replace a legal assessment or the official standard.
