RSI Security

Introduction to Data Protection Impact Assessments – How do you perform a DPIA?

DPIA

The global impact of the GDPR continues to increase. Companies no longer operate solely in one country; rather, they have an international network. Consequently, the GDPR pertains to US companies just as much as EU members. DPIAs, Data Protection Impact Assessments, serve as one component of the GDPRs risk assessment line-up. Read on to learn more about when a DPIA is needed.

 

What Is a DPIA?

A DPIA is simply a more specific type of risk assessment. The GDPR requires a DPIA for high-risk data such as Personally Identifiable Information (PII). The GDPR’s requirements highlight the shift from reactive cybersecurity strategies to more proactive, preventive measures. Specifically, Regulation 2016/6791 (GDPR), Article 35 of the GDPR introduces the concept of a Data Protection Impact Assessment (DPIA2), as does Directive 2016/6803.

 

Why Is a DPIA Important?

A DPIA looks at how data is processed and how that processing puts the rights and freedoms of individuals at risk. In other words, a DPIA is a process for building and demonstrating compliance and encompasses that origin, nature, particularity, and severity of risks to personal data. For example, a DPIA may address the collection necessity and proportionality (to a company’s size) in order to better manage the risks of personal data. DPIAs serve as tools for maintaining accountability, as they help controllers not only comply with GDPR requirements but also to demonstrate that appropriate measures have been taken to ensure compliance.

 

Non-Compliance Consequences?

Under the GDPR, non-compliance with DPIA requirements may result in fines imposed by the competent supervisory authority. Fines may occur in the following scenarios

  1. Failure to carry out a DPIA when required by GDPR guidelines. the processing is subject to a DPIA (Article 35(1) and (3)-(4)), carrying out a DPIA in an incorrect way (Article 35(2) and (7) to (9)), or
  2. Failing to consult the competent supervisory authority where required. (Article 36(3)(e)), can result in an administrative fine of up to 10M€, or in the case of an undertaking, up to 2 percent of the total worldwide annual turnover of the preceding financial year, whichever is higher.

 

Assess your cybersecurity

 

How Do I Know If I Need a DPIA?

A DPIA may seem like just another acronym in the growing pool of risk assessments, but it doesn’t have to be confusing. The first step is understanding when a DPIA is required. It’s important to keep in mind that a DPIA is not mandatory for every processing operation; rather, it is only required when the processing is “likely to result in a high risk to the rights and freedoms of natural persons” (Article 35(1). In cases where it is not clear whether a DPIA is required, the WP29 recommends that a DPIA is carried out nonetheless as a DPIA is a useful tool to help controllers comply with data protection law. Basically, it is better to be safe than sorry.

 

What is High Risk?

At first, the definition of high risk appears rather subjective; however, article 35(3) of the GDPR provides some examples to more easily identify what processing operations  are likely to result in high risk:

The difficulty in determining “high risk” is that the GDPR doesn’t provide concrete boundaries for when a DPIA is necessary. However, the GDPR does specify that if data processing includes profiling, large-scale use of sensitive data, or public monitoring, a DPIA should be conducted. Other scenarios that would require a DPIA include:

In most cases, a data controller can consider that a processing meeting two criteria would require a DPIA to be carried out. However, in some cases, a data controller may deem that a processing meeting only one of these criteria requires a DPIA.

For more clarification, the chart below breaks down types of processing that will likely require a DPIA and provides related examples.

 

Image Source: https://www.itgovernance.co.uk/blog/gdpr-six-key-stages-of-the-data-protection-impact-assessment-dpia

 

Other DPIA Impacting Factors

 

DPIA Resources

Like many risk assessments, a DPIA is scalable and changes on a case-by-case basis. The International Association of Privacy Professionals (IAPP) provides a DPIA template to determine whether a DPIA is necessary.  When it comes to tackling a DPIA, there are a few options.

  1. A company can single-handedly research and identify if a DPIA is required
  2. A company can  hire a third-party evaluator
  3. Or a company can utilize only software to assist in determining the necessity of a DPIA.

In all likelihood, some combination of these three options will be the most beneficial.

 

DPIA Components

To help mitigate ambiguity and create some level of uniformity when composing a DPIA, the European Commission released Guidelines on Data Protection Impact Assessments. In general, a DPIA should have the seven sections outlined below:

    1. Identify the DPIA Need – summarize why there is a need for a DPIA and what processes are involved
    2. Describe the Processing – This section should outline the collection, use, and deletion of data, as well as the reasoning behind the data collection. Additionally, include what kind of processing is used and why it constitutes a high risk.

 

 

  1. Assess Necessity and Proportionality – Identify the processing lawfulness and data quality/minimization while also limiting function creep and respecting personal/consumer rights.
  2. Identify and Assess Risks – List the likely sources of risk and the potential impact on individuals.
  3. Identify measures to reduce risk – Options to reduce or eliminate the risk and to what extent the risk will be limited.
  4. Signatures and Notes – Lastly, have official signatures (such as department leads or consulting parties) and include any additional comments.

 

Need Help?

DPIAs provide companies with an opportunity to assess what data is being collected and how that data plays a role in operations. Although it may seem like just another assessment, a DPIA can help better allocate resources and improve efficiency, in addition to strengthening security measures. If you need assistance identifying if a DPIA is necessary or creating a DPIA template, contact RSI Security today.

 

 

Exit mobile version