{"id":2926,"date":"2017-10-10T14:14:00","date_gmt":"2017-10-10T20:14:00","guid":{"rendered":"https:\/\/trustarc.com\/?post_type=resource&#038;p=2926"},"modified":"2025-05-22T11:06:18","modified_gmt":"2025-05-22T16:06:18","slug":"data-protection-impact-assessment-article35","status":"publish","type":"resource","link":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/","title":{"rendered":"Your EU GDPR Article 35: Data Protection Impact Assessment (DPIA) Cheat Sheet"},"content":{"rendered":"\t\t<section id=\"block_e5403a2a78705764d2b67e6d9b0a533f\" class=\"resource-intro intro-simple\">\n\t\t\t<div class=\"container\">\n\t\t\t\t\t\t\t\t\t<strong class=\"sub-title block uppercase\">Articles<\/strong>\n\t\t\t\t\t\t\t\t\t\t<h1>Your EU GDPR Article 35: Data Protection Impact Assessment (DPIA) Cheat Sheet<\/h1>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\n\n\t<section id=\"block_82b9586d965c1919cb6d42501a41b16b\" class=\"columns-content\">\n\t\t<div class=\"container\">\n\t\t\t<div class=\"left\">\n\t\t\t\t\t\t<div class=\"person-wrap\">\n\t\t\t<span>\t\t\t\t\t\t\t<div class=\"img-holder\">\n\t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"110\" height=\"110\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/people-placeholder-lt-blue.png\" class=\"attachment-full size-full wp-post-image\" alt=\"\" \/>\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"text-holder\">\n\t\t\t\t\t\t\t\t\t\t\t<strong class=\"block name\">Annie Greenley-Giudici<\/strong>\n\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/span>\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t<div class=\"middle\">\n\t\t\t\t<div class=\"content\">\n\t\t\t\t\t<h2>Data Protection Impact Assessment introduction and background<\/h2>\n<p>The <a href=\"\/regulations\/gdpr\/\">GDPR compliance<\/a> deadline has passed, so organizations should have a documented process for conducting Data Protection Impact Assessments (DPIAs) and Privacy Impact Assessments (PIAs).<\/p>\n<p>However, before building a DPIA program, it is useful to review and understand what a DPIA is, when it is needed, and how it should be conducted.<\/p>\n<h2>What is Data Protection Impact Assessment (DPIA)?<\/h2>\n<p>A DPIA is designed to help an organization with risk assessment associated with data processing activities that may pose a threat or high risk to the rights and freedoms of individuals.<\/p>\n<p>A privacy impact assessment helps to identify privacy risks during the development of a program life cycle.<\/p>\n<p>A PIA outlines how personal information will be handled and secured to maintain privacy.<\/p>\n<h2>When is a DPIA required?<\/h2>\n<p>The GDPR requires that DPIAs be conducted before a processing activity takes place that may pose a \u201chigh risk\u201d to the rights and freedoms of individuals.<\/p>\n<p>The GDPR does not define the types of processing that are likely to result in such a risk.<\/p>\n<p>The\u00a0<a href=\"https:\/\/edpb.europa.eu\/about-edpb\/more-about-edpb\/article-29-working-party_en\" target=\"_blank\" rel=\"noopener\">Article 29 Working Party<\/a>\u00a0has, however, provided sample categories of high-risk processing, which can serve as a guide.<\/p>\n<p>The categories include profiling and predictive processing, automated-decision making that has legal effects, systematic monitoring, the processing of sensitive data, and processing that relies on new technology.<\/p>\n<p>One example of high-risk processing in the evaluation or scoring category would be conducting credit checks.<\/p>\n<p><strong>While the GDPR does not dictate the specific requirements of how organizations are supposed to conduct DPIAs, it does provide four elements that a DPIA assessment must contain:<\/strong><\/p>\n<ul>\n<li>a systematic description of the processing operations and their purposes;<\/li>\n<li>an assessment of the necessity and proportionality;<\/li>\n<li>an assessment of the risks; and<\/li>\n<li>the measures needed to address the risks.<\/li>\n<\/ul>\n<p><strong>Benefits of privacy by design or embedding data privacy features early in design:<\/strong><\/p>\n<ul>\n<li>Early identification of potential threats and problems.<\/li>\n<li>Early reduction of problems can save time and money.<\/li>\n<li>Increased privacy and data protection across the organization.<\/li>\n<li>GDPR compliancy.<\/li>\n<\/ul>\n<h2>DPIA suggested practices<\/h2>\n<h3>Data flow mapping and data inventory<\/h3>\n<p>Before creating a DPIA process, it is useful to have a picture of what information your organization has, where the data is located, and how it flows through the organization.<\/p>\n<p>With that in mind, it is essential to develop a\u00a0<a href=\"https:\/\/blog.trustarc.com\/2022\/07\/05\/data-inventory-mapping-compliance\/\" target=\"_blank\" rel=\"noopener\">data inventory<\/a>\u00a0and map the organization\u2019s business process flows or systems.<\/p>\n<h3>Use assessments appropriate for processing risk<\/h3>\n<p>Not all systems and processes require the same type of assessment. The\u00a0<a href=\"https:\/\/blog.trustarc.com\/2019\/02\/19\/compliance-privacy-assessments\/\" target=\"_blank\" rel=\"noopener\">type of assessment conducted<\/a>\u00a0is dependent on the type of processing activity assessed, and the privacy and data protection compliance goals of an organization.<\/p>\n<p>Assessments are designed to address varying levels of data processing risk and complexity. They can be focused around specific regulations such as EU GDPR, or CCPA, and specific products and services.<\/p>\n<p>Make sure the assessment you choose will help you with your EU GDPR Article 35 compliance goals.<\/p>\n<p><strong>Personal data processing where a DPIA is likely required:<\/strong><\/p>\n<ul>\n<li>Hospital processing -patients\u2019 genetic and health data.<\/li>\n<li>Personal sensitive data from research projects or clinical trials.<\/li>\n<li>An organization using an intelligent video analysis system to single out cars and automatically recognize registration plates.<\/li>\n<li>An organization that monitors publicly accessible areas via CCTV, body-devices, CCTV.<\/li>\n<li>Companies that monitor employees\u2019 activities, including their workstations and Internet activity.<\/li>\n<li>Gathering of public social media data for generating profiles.<\/li>\n<li>Institutions that create national-level credit rating or fraud databases.<\/li>\n<li>Organizations that process large-scale special categories of data (e.g. health, religion or ethnic origin)<\/li>\n<li>Legal processing of personal data relating to criminal convictions and offenses.<\/li>\n<li>Evaluation of personal data based on automated decisions such as a denial of online credit applications or e-recruiting without a human based decision.<\/li>\n<\/ul>\n<h2>DPIA program essential elements<\/h2>\n<p>The six essential elements that make up a sustainable DPIA program are: integrated governance, risk assessment, resource allocation, policies &amp; standards, processes, and awareness &amp; training.<\/p>\n<h3>Integrated governance<\/h3>\n<p>The first step in building a sustainable program is establishing program leadership. Depending upon your organization\u2019s goals, the structure may vary.<\/p>\n<p>For example, a global corporation may have one global stakeholder along with several regional stakeholders.<\/p>\n<h3>Risk assessment<\/h3>\n<p>Classifying data-related risks will require taking a collaborative approach because stakeholders view risk differently. Do not forget to consider unstructured data when assessing risk.<\/p>\n<h3>Resource allocation<\/h3>\n<p>Assign knowledgeable and trained personnel to defined roles and responsibilities. Outlining the resources needed will help establish a budget.<\/p>\n<h3>Policies and standards<\/h3>\n<p>Set procedures and guidelines to define and deploy effective and sustainable governance and controls for managing data-related risks.<\/p>\n<p>The assessment process will help determine whether there are any gaps between the standards and the implemented practices.<\/p>\n<h3>Processes<\/h3>\n<p>Develop a process that fits the organization\u2019s size and privacy maturity level. Following a documented process, especially for PIAs\/DPIAs will ensure consistency.<\/p>\n<h3>Awareness and training<\/h3>\n<p>This step is crucial to ensure that the program continually evolves and improves. Communicate expectations to the stakeholders and organization, provide contextual training, and establish training cycles.<\/p>\n<h2>Who should conduct a DPIA?<\/h2>\n<p>A designated data controller, data protection officer, or someone with data protection knowledge and expertise should be responsible for the DPIA. Or select a reputable outsourced data privacy expert.<\/p>\n\t\t\t\t\t\t\t\t\t<div class=\"question-box-multiple\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Pages_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>General Data Protection Regulation (GDPR)<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>Understand the requirements of the world\u2019s most comprehensive data privacy and protection law.<\/p>\n<a href=\"https:\/\/trustarc.com\/regulations\/gdpr\/\" class=\"cta\">Learn more<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"question-box bg-dark\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"icon\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/02\/icon_Product-Update_Small.svg\" class=\"attachment-full size-full\" alt=\"\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<h4>Assessment Manager<\/h4>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<p>Automate and score privacy assessments like PIAs and AI Risk, streamlining your compliance workflow.<\/p>\n<a href=\"https:\/\/trustarc.com\/products\/privacy-data-governance\/assessment-manager\/\" class=\"cta\">Learn more<\/a>\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t<div class=\"right sm\">\n\t\t\t\t<div class=\"share-it\">\n\t\t\t\t\t<strong class=\"title block uppercase\">Follow us<\/strong>\n\t\t\t\t\t<div class=\"soc-list\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.linkedin.com\/company\/trustarc\/\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/li-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"\nhttps:\/\/twitter.com\/TrustArc\" target=\"_blank\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/tw-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<a href=\"javascript:;\" id=\"copy-url\"><img decoding=\"async\" src=\"https:\/\/trustarc.com\/wp-content\/themes\/trustarc\/assets\/dist\/images\/link-dark.svg\" alt=\"\" \/><\/a>\n\t\t\t\t\t\t<span class=\"copied\" style=\"display:none;\">Link Copied!<\/span>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<div class=\"key-topics\">\n\t\t\t\t\t\t<strong class=\"title block uppercase\">Key Topics<\/strong>\n\t\t\t\t\t\t<ul>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<li><a href=\"https:\/\/trustarc.com\/topic-resource\/privacy-assessments\/\" class=\"badge\">Privacy Assessments<\/a><\/li>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/ul>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<div class=\"cta-area\">\n\t\t\t\t\t<p>Get the latest resources sent to your inbox<\/p>\n\t\t\t\t\t<a href=\"\/subscription-center\/\" class=\"cta\">Subscribe<\/a>\n\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t<\/div>\n\t<\/section>\n\t","protected":false},"excerpt":{"rendered":"<p>The GDPR compliance deadline has passed, and if you don&#8217;t have a documented process for conducting Data Protection Impact Assessments (DPIAs) for Article 35 compliance, here&#8217;s what to do.<\/p>\n","protected":false},"featured_media":1250,"template":"","topic-resource":[71],"type-resource":[6],"class_list":["post-2926","resource","type-resource","status-publish","has-post-thumbnail","hentry","topic-resource-privacy-assessments","type-resource-articles"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Your EU GDPR Article 35: Data Protection Impact Assessment (DPIA) Cheat Sheet | TrustArc<\/title>\n<meta name=\"description\" content=\"The GDPR compliance deadline has passed, and if you don&#039;t have a documented process for conducting Data Protection Impact Assessments (DPIAs) for Article 35 compliance, here&#039;s what to do.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/data-protection-impact-assessment-article35\\\/\",\"url\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/data-protection-impact-assessment-article35\\\/\",\"name\":\"Your EU GDPR Article 35: Data Protection Impact Assessment (DPIA) Cheat Sheet | TrustArc\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/data-protection-impact-assessment-article35\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/data-protection-impact-assessment-article35\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-pink-test.png\",\"datePublished\":\"2017-10-10T20:14:00+00:00\",\"dateModified\":\"2025-05-22T16:06:18+00:00\",\"description\":\"The GDPR compliance deadline has passed, and if you don't have a documented process for conducting Data Protection Impact Assessments (DPIAs) for Article 35 compliance, here's what to do.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/trustarc.com\\\/resource\\\/data-protection-impact-assessment-article35\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/resource\\\/data-protection-impact-assessment-article35\\\/#primaryimage\",\"url\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-pink-test.png\",\"contentUrl\":\"https:\\\/\\\/trustarc.com\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/res-feat-city-pink-test.png\",\"width\":610,\"height\":152},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustarc.com\\\/#website\",\"url\":\"https:\\\/\\\/trustarc.com\\\/\",\"name\":\"TrustArc\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/trustarc.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Your EU GDPR Article 35: Data Protection Impact Assessment (DPIA) Cheat Sheet | TrustArc","description":"The GDPR compliance deadline has passed, and if you don't have a documented process for conducting Data Protection Impact Assessments (DPIAs) for Article 35 compliance, here's what to do.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/","url":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/","name":"Your EU GDPR Article 35: Data Protection Impact Assessment (DPIA) Cheat Sheet | TrustArc","isPartOf":{"@id":"https:\/\/trustarc.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/#primaryimage"},"image":{"@id":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/#primaryimage"},"thumbnailUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-pink-test.png","datePublished":"2017-10-10T20:14:00+00:00","dateModified":"2025-05-22T16:06:18+00:00","description":"The GDPR compliance deadline has passed, and if you don't have a documented process for conducting Data Protection Impact Assessments (DPIAs) for Article 35 compliance, here's what to do.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trustarc.com\/resource\/data-protection-impact-assessment-article35\/#primaryimage","url":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-pink-test.png","contentUrl":"https:\/\/trustarc.com\/wp-content\/uploads\/2024\/01\/res-feat-city-pink-test.png","width":610,"height":152},{"@type":"WebSite","@id":"https:\/\/trustarc.com\/#website","url":"https:\/\/trustarc.com\/","name":"TrustArc","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustarc.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource\/2926","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/resource"}],"about":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/types\/resource"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media\/1250"}],"wp:attachment":[{"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/media?parent=2926"}],"wp:term":[{"taxonomy":"topic-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/topic-resource?post=2926"},{"taxonomy":"type-resource","embeddable":true,"href":"https:\/\/trustarc.com\/wp-json\/wp\/v2\/type-resource?post=2926"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}