Our own servers in Europe · GDPR · Support in your language

Module 5 of 6 · GDPR · Block 5

Data protection impact assessment (DPIA)

When a processing activity poses a high risk to people's rights, the GDPR requires a data protection impact assessment (DPIA).

Content reviewed on

When it's mandatory

Large-scale processing, sensitive data, or systematic monitoring, among the cases requiring a DPIA.

Assessment contents

Description of the processing, assessment of necessity and proportionality, and measures to mitigate identified risks.

Prior consultation

The obligation to consult the supervisory authority if a high residual risk remains after the assessment.

What an auditor usually asks for

  • Criteria to determine whether a DPIA is mandatory
  • DPIA carried out for high-risk processing
  • Risk mitigation measures documented
  • Prior consultation with the authority carried out where applicable

How to cover this block in Kimobox

  1. 1Document each DPIA as a version-controlled record linked to the assessed processing activity.
  2. 2Log risk mitigation measures with their owner.
  3. 3Keep evidence of the prior consultation when required.

Every impact assessment stays linked to the processing activity that triggered it, with its mitigation measures traceable.

See risk management in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Regulation (EU) 2016/679, General Data Protection Regulation EUR-Lex · Applicable since 25 May 2018
  2. Organic Law 3/2018 on Data Protection and guarantee of digital rights BOE-A-2018-16673 · 6 December 2018
  3. Spanish Data Protection Agency AEPD · Supervisory authority