Data protection impact assessments.
Data Protection Impact Assessments (DPIAs)
A Data Protection Impact Assessment (DPIA) is a structured process used by an organisation to identify, assess, and reduce privacy and data-protection risks arising from a proposed processing activity. It is particularly important where processing is likely to create a high risk to individuals, such as through large-scale monitoring, profiling, biometric identification, artificial intelligence, or processing sensitive personal data.
A DPIA is not merely a compliance document. It is intended to be a practical risk-management mechanism that helps an organisation determine whether proposed processing is necessary, proportionate, secure, and legally justified.
1. Meaning of DPIA
A DPIA generally examines:
- what personal data will be collected;
- why the data will be processed;
- the legal basis for processing;
- whose data will be processed;
- how the data will be collected, stored, transferred and deleted;
- the risks to individuals;
- the safeguards available to reduce those risks; and
- whether the remaining risk is acceptable.
Under the EU General Data Protection Regulation (GDPR), Article 35 requires a DPIA where a type of processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons.
2. Objectives of a DPIA
The principal objectives are:
Risk identification:
The organisation identifies possible privacy harms before processing begins.
Risk assessment:
The likelihood and severity of possible harm are evaluated.
Risk mitigation:
Technical and organisational safeguards are introduced to reduce identified risks.
Accountability:
The organisation demonstrates that it considered its data-protection responsibilities.
Privacy by design:
Privacy considerations are incorporated into a system or process from the beginning rather than after a problem occurs.
3. When is a DPIA generally required?
A DPIA is particularly relevant where processing involves:
- systematic and extensive evaluation or profiling;
- automated decision-making producing significant effects;
- large-scale processing of sensitive or special-category data;
- large-scale monitoring of publicly accessible areas;
- biometric identification;
- facial-recognition technology;
- employee monitoring systems;
- artificial intelligence systems involving personal information;
- extensive location tracking;
- combining datasets from different sources; or
- processing that could substantially affect an individual's rights or opportunities.
For example, an employer introducing an AI system that analyses employees' performance, attendance, communications and behavioural patterns may need to conduct a DPIA because the processing could significantly affect employees.
4. Main Components of a DPIA
A comprehensive DPIA normally contains the following elements.
A. Description of the processing
The organisation should describe:
- the nature of processing;
- the purpose;
- categories of personal data;
- categories of data subjects;
- recipients of the information;
- retention periods; and
- international transfers.
B. Assessment of necessity and proportionality
The organisation should establish that the proposed processing is genuinely necessary for its objective.
It should consider whether the same objective can be achieved through:
- less personal data;
- less intrusive technology;
- shorter retention;
- limited access; or
- anonymised or pseudonymised information.
C. Risk assessment
Potential risks can include:
- identity theft;
- discrimination;
- unlawful surveillance;
- loss of confidentiality;
- financial harm;
- reputational harm;
- psychological harm;
- unauthorised disclosure; and
- excessive employee monitoring.
D. Safeguards
Possible safeguards include:
- encryption;
- access controls;
- pseudonymisation;
- data minimisation;
- restricted retention periods;
- audit logs;
- human review;
- transparency notices;
- employee consultation; and
- regular security testing.
E. Residual risk
After safeguards are implemented, the organisation should assess what risks remain.
Where high risks cannot be sufficiently mitigated, consultation with the relevant data-protection authority may be required under applicable law.
5. DPIAs and Employee Data
DPIAs are especially important in employment because employers often possess substantial amounts of personal information.
Examples include:
- attendance records;
- payroll information;
- performance evaluations;
- health-related information;
- disciplinary records;
- location data;
- CCTV footage;
- biometric information;
- email and internet-use records; and
- AI-generated employee profiles.
An employer should avoid assuming that its ownership of the employment relationship gives it unlimited authority to process employee information.
The necessity, proportionality and legitimate purpose of monitoring must still be considered.
6. DPIAs and Artificial Intelligence
AI systems can create particularly difficult privacy risks because they may:
- process enormous datasets;
- infer sensitive characteristics;
- create employee profiles;
- make automated recommendations;
- generate inaccurate information;
- reproduce discriminatory patterns; and
- make decisions that individuals cannot easily understand.
A DPIA can therefore examine whether an AI system should process particular categories of data at all.
It should also consider whether meaningful human oversight is necessary.
7. DPIAs and Data Minimisation
Data minimisation is closely connected with DPIAs.
An organisation should ask:
"Do we really need all of this information?"
For example, if an employer wants to monitor productivity, collecting employees' exact location every minute may be excessive if productivity can be assessed through less intrusive information.
A DPIA therefore provides a mechanism for challenging unnecessary data collection before the system is implemented.
8. DPIAs and Data Security
A DPIA should examine the consequences of security failures.
For example, where an HR database contains:
- employee addresses;
- bank information;
- identification information; and
- salary details,
the DPIA should consider the consequences of unauthorised access and establish appropriate security controls.
The assessment should not simply state that "security measures are in place." It should identify the particular risks and explain why the selected safeguards are appropriate.
9. DPIAs and Transparency
Individuals should generally be able to understand:
- what information is being collected;
- why it is being collected;
- how it will be used;
- who will receive it;
- how long it will be retained; and
- what rights they have.
Transparency becomes especially important where processing is complex, automated or involves AI.
10. DPIAs and Privacy by Design
DPIAs support the principle of privacy by design and by default.
Instead of creating a system first and attempting to correct privacy problems later, organisations should identify privacy risks during the planning stage.
For example, before launching a facial-recognition attendance system, an organisation could conduct a DPIA and determine whether:
- facial recognition is actually necessary;
- another attendance method would be less intrusive;
- biometric templates can be securely stored;
- employees have sufficient information;
- retention can be reduced; and
- alternative arrangements are required.
11. Important Case Laws
1. Digital Rights Ireland Ltd v Minister for Communications (Joined Cases C-293/12 and C-594/12)
The Court of Justice of the European Union examined large-scale retention of communications data. It emphasised that extensive interference with privacy and data-protection rights requires strong safeguards and must satisfy proportionality requirements.
Relevance to DPIAs:
A DPIA should identify whether the scale and nature of proposed data processing creates disproportionate interference with fundamental rights.
2. Schrems II (Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems) (Case C-311/18)
The CJEU examined international transfers of personal data and the protection available to individuals when data is transferred outside the EU.
The Court stressed the importance of ensuring essentially equivalent protection for personal data.
Relevance to DPIAs:
Where an organisation transfers employee or customer data internationally, the DPIA should examine the legal and practical risks associated with the destination country and available safeguards.
3. Google Spain SL v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González (Case C-131/12)
The CJEU considered the "right to be forgotten" and the responsibilities of search-engine operators concerning personal information.
Relevance to DPIAs:
The case illustrates the importance of considering individuals' rights when designing systems that process, publish or make personal information searchable.
4. Ryneš v Úřad pro ochranu osobních údajů (Case C-212/13)
The CJEU considered whether the use of a home surveillance camera fell within the household exemption.
The Court adopted a careful approach to determining whether surveillance constituted processing of personal data outside a purely private activity.
Relevance to DPIAs:
It demonstrates why organisations undertaking surveillance should carefully examine the scope and effects of monitoring activities.
5. TK v Asociaţia de Proprietari bloc M5A-ScaraA (Case C-708/18)
The CJEU considered video surveillance in a residential context and examined the requirements of lawful processing and legitimate interests.
Relevance to DPIAs:
Surveillance systems should be assessed in terms of necessity, proportionality, legitimate purpose and the rights of people being monitored.
6. La Quadrature du Net and Others v Premier ministre and Others (Joined Cases C-511/18, C-512/18 and C-520/18)
The CJEU considered extensive electronic communications surveillance and the relationship between national-security measures and EU data-protection principles.
The judgment highlighted the importance of safeguards surrounding large-scale interference with privacy.
Relevance to DPIAs:
A DPIA involving large-scale monitoring should consider the seriousness, scale and duration of the interference and whether adequate safeguards exist.
7. Puttaswamy v Union of India (Justice K.S. Puttaswamy (Retd.) v Union of India, 2017)
The Supreme Court of India recognised privacy as a fundamental right under Article 21 of the Constitution.
The judgment established that restrictions on privacy must satisfy constitutional requirements including legality, legitimate state purpose and proportionality.
Relevance to DPIAs:
Although India's data-protection framework differs from the GDPR, the constitutional principles of privacy, necessity and proportionality provide an important framework for assessing intrusive processing of personal information.
8. K.S. Puttaswamy (Retd.) v Union of India (Aadhaar case) (2018)
The Supreme Court examined extensive collection and use of identity information under the Aadhaar system and applied principles concerning necessity, proportionality and privacy.
Relevance to DPIAs:
Large-scale identity-data processing demonstrates why organisations should evaluate the purpose, amount of data collected, safeguards and potential impact on individuals before implementing a data-intensive system.
12. Importance of DPIAs for Employers
For employers, DPIAs can help prevent:
- unlawful employee surveillance;
- excessive collection of HR information;
- discriminatory AI decisions;
- biometric-data risks;
- unauthorised disclosure of employee information;
- excessive retention of personnel records; and
- unlawful international transfers.
They also provide evidence that the employer considered privacy risks before implementing a new HR technology.
13. Consequences of Failing to Conduct an Appropriate DPIA
Depending on the applicable legal framework, failure to conduct a required DPIA can result in:
- regulatory enforcement;
- administrative fines;
- orders to stop or modify processing;
- compensation claims;
- reputational damage;
- employee complaints;
- regulatory investigations; and
- inability to lawfully continue high-risk processing.
A DPIA should therefore be treated as an ongoing governance process rather than a one-time form.
Conclusion
A Data Protection Impact Assessment is an important tool for identifying and controlling privacy risks before high-risk processing begins. It requires an organisation to examine the purpose and necessity of processing, assess potential harm to individuals, introduce proportionate safeguards and evaluate residual risks.
In employment law, DPIAs are particularly valuable for employee monitoring, biometrics, AI-based HR systems, workplace surveillance, profiling, international data transfers and large-scale HR databases. The principles emerging from cases such as Digital Rights Ireland, Schrems II, Google Spain, La Quadrature du Net and Puttaswamy demonstrate the central importance of privacy, necessity, proportionality, transparency and safeguards when organisations process personal information.

comments