GDPR and privacy

When is a DPIA required?

A DPIA identifies high privacy risks before processing starts and helps you choose appropriate measures.

Read when a DPIA is needed, how to identify high privacy risks and which steps to take before processing begins.

What is a DPIA?

A data protection impact assessment describes the processing, its necessity, risks to data subjects and measures to reduce those risks. It is not a form to complete afterwards, but a decision-making tool before processing begins or changes substantially.

The assessment considers impacts on people, such as discrimination, loss of control, financial loss, exclusion or unwanted disclosure.

  • the nature, scale, context and purpose of processing
  • necessity and proportionality
  • risks to rights and freedoms
  • existing and additional measures
  • residual risk and the decision on whether to proceed

How do you identify a likely high risk?

Look for combinations of large-scale processing, sensitive data, systematic monitoring, profiling, vulnerable groups, new technology and decisions with significant consequences.

Also check the official Dutch Data Protection Authority list of processing activities requiring a DPIA. The list is not exhaustive: processing that is not listed may still be likely to result in a high risk. Record your assessment if you conclude that no DPIA is needed.

Also check specific statutory exceptions. Article 35(10) GDPR may, for example, apply to processing for a legal obligation or public task that was already assessed when the legislation was adopted. Check all the conditions; a statutory legal basis alone does not provide an exemption.

How do you carry out the assessment in practice?

Involve the process owner, privacy and security specialists, the supplier and representatives of the people doing the work. Describe the actual data flows, rather than just the contract or policy.

What if a high residual risk remains?

Does the DPIA show that a high risk remains, with no adequate measures available to reduce it? The controller must then consult the Dutch Data Protection Authority before processing begins. Internal acceptance of the risk does not replace this obligation.

Check whether processing still matches the DPIA, at least whenever the risks change. Changes to purposes, data, technology or suppliers may trigger this review. Update the assessment and measures where necessary.

Frequently asked questions

Must a DPIA take place before you start?+

Yes. Where there is likely to be a high risk, the assessment should take place before processing begins.

Is a supplier's DPIA sufficient?+

Not automatically. Your purpose, configuration, data and user context determine the risk.

Who owns the DPIA?+

The controller remains responsible; privacy specialists, the DPO and other experts provide advice.

Sources and further reading

We prioritise primary sources for factual and time-sensitive information. Always check the current official publication when making important decisions.

Related articles

AI Act and ISO 42001What does the AI Act mean for your organisation?Read article →NIS2 and the Dutch Cybersecurity ActNIS2 controls: what do you need to put in place?Read article →Audits and certificationHow do you prepare your organisation for an internal audit?Read article →

This is general guidance and does not replace a legal assessment or the official standard.