Skip to content
Call, +49 511 47 55 58 10
lexICT GmbH, Home

Procedure

The data protection impact assessment

An impact assessment under Art. 35 GDPR is not a formality at the end of a project. It comes before the means of processing are determined, and the decision against it has to be documented just as its performance would be. What is assessed is the risk to the data subjects and not the risk to the organisation.

The choice is made, the assessment is missing

The department presents a new recruitment system. The choice has been made, the contract is ready for signature, the launch date is set. The question asked is whether anything speaks against it from a data protection point of view.

The decision against an assessment also needs reasons

What decides whether an impact assessment is required is set out in Art. 35(1) GDPR. The trigger is a likely high risk to the rights and freedoms of natural persons, and paragraph 3 names three standard cases.

The three standard cases in Art. 35(3) GDPR

Systematic and extensive evaluation of personal aspects

What is required is automated processing including profiling which in turn forms the basis for decisions producing legal effects or similarly significant effects. Pre-selection of applicants by a scoring system falls within this as soon as the selection follows the score.

Processing on a large scale of special categories

Special categories under Art. 9(1) GDPR or data on criminal convictions under Art. 10 GDPR. Large scale is not a fixed number but a question of volume, duration, geographical extent and the number of data subjects.

Systematic monitoring of publicly accessible areas on a large scale

The camera surveillance case, once it is systematic and covers a publicly accessible area. A customer area is publicly accessible even where it is private property.

The standard cases are not exhaustive. Alongside them stands the list each supervisory authority publishes under Art. 35(4) GDPR, and the binding one is the list of the authority competent for your own establishment.

Beforehand means before the means are determined

When in a project the assessment has to take place follows from two provisions. Art. 35(1) GDPR requires it prior to the processing. Art. 25(1) GDPR fixes the moment more precisely, namely at the time of determining the means of processing, and thus before the system is chosen.

Four moments, and only the first is the right one

  1. The need is settled

    Purpose, categories of data and data subjects are known, the system is not. Here the impact assessment shapes the requirements list.

  2. Vendor selected

    The impact assessment can still influence the configuration and the contract. The shape of the processing is already fixed.

  3. Contract signed

    From here what remains are measures that cost nothing. Changing vendor is out of the question in commercial terms.

  4. System live

    If the impact assessment takes place only after the fact, it merely describes the current state. Its power to shape the project is lost.

A late assessment is still better than none. It closes the gap in accountability and provides the basis for updating once something about the project changes.

What is assessed is the risk to the data subjects

Whose risk the assessment measures is regularly confused in practice. Art. 35(7)(c) GDPR names the risks to the rights and freedoms of data subjects. Downtime, fines and reputational loss for the organisation are a different subject.

Two notions of risk that do not coincide

Risk to the data subjectMerkmalRisk to the organisation
Rights and freedomsDiscrimination, identity theft, financial loss, damage to reputation, loss of confidentiality.Subject matterOperations and balance sheetDowntime, recovery costs, fines, standing.
Likelihood and severityFrom the perspective of the person who would be affected.YardstickLoss amount and frequencyFrom the perspective of the organisation doing the processing.
Lowers it considerablyThe data stays unreadable if it leaks.Effect of encryptionBarely lowers itThe system still goes down.
Barely lowers itA copy does not help against unauthorised disclosure.Effect of a backupLowers it considerablyOperations resume after a short time.

The last two rows show why the confusion matters. The same measure works in opposite directions in the two assessments, so an assessment written from the operational perspective recommends the wrong measures.

If the risk stays high, the project goes to the supervisory authority

What follows where the risk remains high despite the measures envisaged is governed by Art. 36(1) GDPR. The controller then consults the supervisory authority prior to processing. The consultation is not an approval procedure, and silence from the authority is not clearance.

What the consultation requires

Liste zu erledigender Punkte

  • The respective responsibilities of the controllers and the processors involved, in particular within a group of undertakings
  • The purposes and means of the intended processing
  • The measures and safeguards envisaged
  • The contact details of the data protection officer
  • The impact assessment itself

The authority responds within up to eight weeks, extendable by six. It may exercise its powers under Art. 58 GDPR, which include limiting and banning the processing.

How we support you with the impact assessment

The threshold assessment works best where new procedures are reviewed or released anyway. With little effort, it clarifies whether a data protection impact assessment is required. The information it needs already sits in the record of processing activities.

Frequently asked questions

When is an impact assessment required?

Where the processing is likely to result in a high risk, Art. 35(1) GDPR. Paragraph 3 names three standard cases, namely systematic and extensive evaluation of personal aspects, processing on a large scale of special categories, and systematic monitoring of publicly accessible areas on a large scale. Alongside these stands the list published by the competent supervisory authority under paragraph 4.

Does it have to be documented that no assessment was needed?

Yes. Accountability under Art. 5(2) GDPR covers the outcome of the check and not only its performance. A one-page threshold assessment suffices if it names the criteria considered and the result.

How long does a consultation under Art. 36 GDPR take?

The supervisory authority responds within up to eight weeks of receiving the request, extendable by six weeks for complex projects. The period is suspended while requested information is outstanding.

Can one assessment cover several systems?

Art. 35(1) sentence 2 GDPR allows a single assessment for a set of similar processing operations that present similar high risks. The test is the similarity of the operations and not whether they belong to the same system.

Get in touch!

Have we sparked your interest? Do you have questions? Would you like a quote without obligation? We look forward to hearing from you!

Contact us

Alternatively you can request a call back.