GDPR · Privacy by design
Data protection impact assessment — DPIA
A DPIA is a structured assessment conducted before processing likely to create high risks to individuals’ rights and freedoms. It is neither an approval form nor a purely technical report: it must demonstrate necessity, proportionality, risks and effectiveness of planned measures.
When a DPIA becomes mandatory
Article 35 identifies situations such as systematic automated evaluation with significant effects, large-scale sensitive-data processing and systematic large-scale monitoring of publicly accessible areas. ANSPDCP Decision No. 174/2018 adds operations relevant to Romania.
A combination of criteria can also create high risk: new technology, profiling, vulnerable persons, database matching, inability to exercise a right or persistent monitoring. A decision not to conduct a DPIA should also be documented where a project shows serious indicators.
Assessment contents
The document must be developed with product, security and business teams. A superficial system description produces a useless assessment because risk arises from data, purpose, logic, people and context.
- Description: operations, flows, systems, actors, data and retention periods.
- Purpose and legal basis: the intended result and lawfulness of each use.
- Necessity: why data and scale are appropriate and proportionate.
- Risks: discrimination, exclusion, fraud, loss of confidentiality or control.
- Measures: prevention, detection, mitigation and response, with assigned owners.
- Residual risk: assessment after measures are applied and the launch decision.
Consulting the DPO, individuals and authority
The controller seeks the appointed DPO’s advice and documents how recommendations were addressed. Data subjects’ or representatives’ views may be useful or necessary unless disproportionate or contrary to protected interests.
If high risk remains uncontrolled after measures, Article 36 requires prior consultation with the authority. Launch must not be treated as a temporary solution while clarification is awaited.
A living document linked to changes
The model, datasets, cloud provider, audience, purpose or functions may change after launch. The DPIA must be reviewed when risks change and incorporated into change management.
Promised measures must be tested and evidenced: access controls, error rates, human intervention, explanations, decision challenges and deletion. A signed but unimplemented DPIA provides no real protection.
How we work together
- 01Collecting information
We establish the processes, systems, providers, data categories, roles and existing documents relevant to the DPIA.
- 02Risk and legality analysis
We check purposes, legal bases, proportionality, time limits, transfers, security and risks to data subjects.
- 03Documents and workflow
We draft the legal documents and align them with internal responsibilities, technical steps, evidence and response deadlines.
- 04Controlled implementation
We deliver the final version, practical instructions and clear priorities; compliance is reviewed periodically when processes or providers change.
Frequently asked questions
Is a DPIA mandatory for every large database?+
Not automatically. Nature, scale, context, purposes and risk are assessed. However, large-scale sensitive-data processing is expressly covered.
Can a provider give me its own DPIA?+
Provider information can help, but the controller remains responsible for a DPIA reflecting its own purposes, users, integration and risks.
Must the DPIA be sent to ANSPDCP?+
Not as a general rule. The authority is consulted before processing where high risk remains without sufficient measures, under Article 36.
Need a DPIA?
Send your documents for a legal assessment and a solution tailored to your commercial objective.
Aveți nevoie de asistență juridică urgentă sau de consultanță de specialitate?
Notă juridică și limitarea răspunderii
Informațiile și articolele publicate pe acest site web sunt puse la dispoziție de Avocatul „Basuc Cosmin Ștefan” exclusiv în scop informativ și educativ general. Materialele prezentate reprezintă analize teoretice și opinii de specialitate la data redactării lor, fără a constitui consultanță juridică, asistență legală sau o opinie aplicabilă unui caz concret. Lectura sau utilizarea acestui conținut nu creează o relație profesională avocat-client între cititor și Cabinet. Având în vedere dinamica legislativă și specificul fiecărei situații de fapt, interpretările conținute nu pot substitui analiza individuală a unei cauze. Pentru stabilirea cadrului juridic aplicabil problemei dumneavoastră și obținerea unei consultații profesionale dedicate, vă invităm să contactați Cabinetul prin mijloacele oficiale de comunicare afișate.
Linkuri utile și legislație
