Data protection impact assessment procedure
When an impact assessment is required, how it is carried out, what it must contain, who signs it and when the authority is consulted.
How the register reads it
| Also called | PIA procedure, privacy impact assessment |
|---|---|
| Family | Privacy |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The data protection officer or privacy lead. |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | GDPR or ISO 27701 is ticked and no line resolves to it. |
| Template | Data protection impact assessment procedure. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 2 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
ISO/IEC 27701:2025
ISO 27701 A.1.2.6 Privacy impact assessmentThe organization must assess whether a privacy impact assessment is needed and carry one out where appropriate whenever new processing of personal data or a change to existing processing is planned, determining the elements the assessment needs, which can include the types of personal data processed, where it is stored and where it may be transferred, supported by data flow diagrams and data maps, and recognising that some jurisdictions mandate an assessment for cases such as automated decisions with legal effect, large scale processing of special categories, or systematic large scale monitoring of public areas.
Common gap: Assessment performed only for projects that reach a funding threshold, so small high risk changes escape
Source: ISO/IEC 27701:2025
GDPR (Regulation (EU) 2016/679)
GDPR Art. 35 Data protection impact assessmentWhere a type of processing, in particular using new technologies and taking account of the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data before the processing begins; a single assessment may address a set of similar operations presenting similar risks. An assessment is required in particular for systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions producing legal or similarly significant effects are based, for large scale processing of special category or criminal offence data, and for systematic monitoring of a publicly accessible area on a large scale. Seek the advice of the data protection officer where one is designated, and where appropriate seek the views of data subjects or their representatives. The assessment must contain at least a systematic description of the envisaged operations and purposes including any legitimate interest pursued, an assessment of the necessity and proportionality of the operations in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance. Carry out a review where necessary and at least when the risk represented by the processing operations changes.
Common gap: An assessment opened at project start and never revisited, so its residual risk conclusion is never tested against how the processing actually turned out
Source: GDPR (Regulation (EU) 2016/679)
GDPR Art. 36 Prior consultationConsult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate that risk. When consulting, provide the respective responsibilities of the controller, any joint controllers and the processors involved, the purposes and means of the intended processing, the measures and safeguards provided to protect the rights and freedoms of data subjects, the contact details of the data protection officer where applicable, the impact assessment itself, and any other information the authority requests. The authority has up to eight weeks to provide written advice where it considers the intended processing would infringe the Regulation, extendable by six weeks with notification of the extension and its reasons, and may use its Article 58 powers. Member State law may additionally require consultation and prior authorisation for processing carried out for a public interest task.
Common gap: Residual risk written down to medium in the assessment precisely to avoid the consultation trigger, with no measure actually added to justify the reduction
Source: GDPR (Regulation (EU) 2016/679)
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerData processing agreement · Data protection officer and privacy roles