Impact assessment (DPIA)

Impact assessment (DPIA)

How to start and complete a Data Protection Impact Assessment with Privacta.

When it is mandatory

A DPIA is mandatory when a processing activity may present a high risk to the rights and freedoms of natural persons. Privacta automatically flags the processing activities that may require a DPIA, based on the WP248 guidelines of the European Data Protection Board.

Privacta guides you through the DPIA step by step, pre-filling the sections based on the information already in the Records of Processing.

Phases of a DPIA

  1. Systematic description of the processing
  2. Assessment of necessity and proportionality
  3. Assessment of risks to data subjects
  4. Measures envisaged to address the risks
  5. DPO approval

📄 Add the guided DPIA procedure and risk assessment criteria