Data Protection Impact Assessment
A structured data-protection impact assessment under GDPR Article 35, documenting processing, necessity, proportionality, risks to individuals and the measures used to reduce them.
A DPIA is required where processing is likely to result in a high risk to individuals’ rights and freedoms. It also provides a practical method for improving privacy controls and demonstrating accountability.
We document the processing purpose and data flows, assess necessity and proportionality, identify risks, evaluate existing controls and define a treatment plan. Where residual high risk remains, we help prepare for consultation with the supervisory authority.
How it works
-
01
Preparation & scoping
Understand processing activities, stakeholders, data flows and timelines.
-
02
Assessment & analysis
Map flows, evaluate necessity/proportionality, verify legal basis and identify risks.
-
03
Risk treatment & reporting
Mitigations, residual-risk assessment, report and roadmap.
-
04
Implementation support
Help implement mitigations and verify effectiveness (optional).
Packages
- Essential
- DPIA for a single processing activity.
- Comprehensive Popular
- Multiple activities with mitigation planning.
- Enterprise
- Program-level DPIAs with ongoing support.
Frequently asked questions
How do we know if our processing requires a DPIA?
We begin with a screening assessment to determine whether the processing is likely to meet the high-risk criteria in GDPR Article 35 and applicable supervisory-authority guidance. The review considers the purpose, data categories, scale, technology, affected people and potential consequences.
How long does a DPIA typically take?
A standard DPIA for a single processing activity typically requires 2-4 weeks to complete. Complex assessments involving multiple stakeholders or technical systems may require 4-6 weeks. Timelines vary based on activity complexity and information availability.
When in the project lifecycle should we conduct a DPIA?
A DPIA should be started during design, before high-risk processing begins and while meaningful changes are still possible. For existing processing, complete or update the DPIA when a high-risk threshold is met or when the nature, scope, context, purpose or risk changes materially.
What if our DPIA identifies high residual risks?
If high residual risk remains after planned safeguards, GDPR Article 36 may require prior consultation with the competent supervisory authority before processing begins. We help document the residual risk and prepare the consultation material; the controller remains responsible for the decision and submission.
Can a DPIA cover multiple processing activities?
Yes, related processing activities with similar risk profiles can often be covered in a single DPIA. We help determine the appropriate scope based on your specific context, balancing thoroughness with efficiency.
Helpful tools
- Scope a test
Create a scoped brief in one minute
- NIS2 / DORA scope check
Check whether the regulations apply to your organization
- Security maturity assessment
Assess your organization across six domains
All services
- CISO-as-a-Service
Experienced security leadership without a full-time appointment.
- NIS2 & ISO 27001 Readiness
Assess gaps and prepare evidence for NIS2 and ISO/IEC 27001.
- DORA Compliance & Resilience Testing
DORA governance, resilience testing and TLPT support for financial entities.
Scope a test
[email protected] +371 2256 5353
Direct access to a senior specialist · Reply within 24 hours · NDA available on request