When it's mandatory
Large-scale processing, sensitive data, or systematic monitoring, among the cases requiring a DPIA.
Assessment contents
Description of the processing, assessment of necessity and proportionality, and measures to mitigate identified risks.
Prior consultation
The obligation to consult the supervisory authority if a high residual risk remains after the assessment.
What an auditor usually asks for
- Criteria to determine whether a DPIA is mandatory
- DPIA carried out for high-risk processing
- Risk mitigation measures documented
- Prior consultation with the authority carried out where applicable
How to cover this block in Kimobox
- 1Document each DPIA as a version-controlled record linked to the assessed processing activity.
- 2Log risk mitigation measures with their owner.
- 3Keep evidence of the prior consultation when required.
Every impact assessment stays linked to the processing activity that triggered it, with its mitigation measures traceable.
Where each figure comes from
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
- Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
- Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
- Spanish Data Protection Agency AEPD · Supervisory authority