Datenmaske
← Blog
DSGVO PRACTICE · Datenmaske Editorial Team

Data Protection Impact Assessment (DPIA) under Art. 35 DSGVO — a practical guide

The Data Protection Impact Assessment (DPIA) under Art. 35 DSGVO is the central instrument for identifying risks to data subjects at an early stage. Anyone who uses particularly risky procedures — such as large-scale profiling procedures, AI-supported analyses or the processing of sensitive data volumes — must systematically assess the risks and take measures. This guide explains when a DPIA is required, what it must contain and how the automatic redaction of documents effectively reduces the risk.

What is a Data Protection Impact Assessment?

The Data Protection Impact Assessment (DPIA) is a structured process under Art. 35 Abs. 1 DSGVO. It serves to systematically assess the impact of planned or existing processing operations on the rights and freedoms of natural persons and to define measures for risk mitigation at an early stage.

Unlike the record of processing activities (Art. 30 DSGVO), which merely documents what is processed, the DPIA specifically examines the risks of this processing: What threats exist? How likely are they? What damage can occur? And which technical and organisational measures mitigate the risks? The result is not an end in itself, but a decision template: Does the residual risk remain acceptable, or must the processing be adjusted — in case of doubt not carried out at all?

When is a DPIA required?

Art. 35 Abs. 1 DSGVO requires a DPIA whenever a form of processing is likely to result in a high risk to the rights and freedoms of natural persons. This is specified in Art. 35 Abs. 3 DSGVO by three statutory catalogues for which a DPIA is mandatory:

  • Systematic and extensive evaluation of personal aspects: When processing operations are based on automated processing — including profiling — and form the basis for decisions that produce legal effects on the data subject or similarly significantly affect them.
  • Large-scale processing of special categories of data: When data under Art. 9 Abs. 1 DSGVO is processed on a large scale — i.e. health data, biometric or genetic data, data concerning sex life or political opinions, trade union membership, ethnic origin or religious beliefs.
  • Large-scale systematic monitoring: When publicly accessible areas are monitored on a large scale and systematically — for example by video surveillance, sensors or automated licence plate recognition.

The European Data Protection Board (EDPB) has also defined in its DPIA guidelines (WP248 rev.01) a series of criteria that, individually or in combination, can establish a high risk: evaluation or prediction of behaviour, systematic monitoring, sensitive data or data of high intimacy, data about vulnerable persons (children, employees), large data volumes, combination or merging of data sets, innovative technologies (e.g. AI, biometrics), exclusion of the exercise of rights and many more. As soon as two of these criteria coincide, a DPIA is generally mandatory.

In Germany, § 35 BDSG supplements the requirements. For processing operations that do not require regular access to files or physical information and are not carried out wholly or partly by automated means on a large scale, a DPIA is only required if the processing is likely to result in a high risk to the rights and freedoms of data subjects. In practice, a rule of thumb is often cited according to which a risk indicator in the order of regularly at least 75 employees with automated processing can serve as a reference point for closer examination — however, this is not a rigid statutory threshold. The decision lies with the controller and, in case of doubt, must be justified to the supervisory authority.

What must a DPIA contain?

Under Art. 35 Abs. 7 DSGVO, every Data Protection Impact Assessment must comprise at least three elements:

1. Systematic description of the processing operations and purposes. What exactly is processed, where does the data come from, to whom is it shared, how long is it stored, what technology is used? This inventory alone forces controllers to be precise and often reveals processing components that had not previously been fully captured.

2. Assessment of necessity and proportionality. Are the processing operations really necessary for the purpose? Are there more privacy-friendly alternatives (data economy)? Is the processing appropriate in relation to the purpose? Here the principles from Art. 5 DSGVO apply — in particular data minimisation (Art. 5 Abs. 1 lit. c) and storage limitation.

3. Assessment of the risks to the rights and freedoms of data subjects. What threats are conceivable for data subjects — such as identity theft, discrimination, financial damage, reputational damage, loss of control over their own data? How likely is occurrence, and how severe would the damage be? This risk assessment is typically carried out in a matrix of probability of occurrence and severity.

In addition, Art. 35 Abs. 7 lit. d DSGVO requires the measures to address the risks — i.e. technical and organisational measures (TOMs), safeguards and procedures. This is exactly where automatic redaction comes in as an effective measure.

Redaction as a risk-minimising measure

When documents with personal data are processed as part of a high-risk procedure — for example in access requests (Art. 15 DSGVO), file inspection, IFG requests, the disclosure of reports or the release of personnel files — automatic redaction is one of the most effective measures for risk mitigation. It takes effect at several points:

Data minimisation under Art. 5 Abs. 1 lit. c DSGVO. Anyone who consistently redacts before sharing reduces the volume of disclosed personal data to what is absolutely necessary for the purpose. This drastically reduces the risk for data subjects — and at the same time the likelihood of a data protection breach by the controller.

Data protection by design (Art. 25 DSGVO). Privacy by design requires systems to be designed in such a way that only the necessary data is processed from the outset. Integrating automatic detection and redaction into the release workflow is a classic example of a built-in protective measure.

Effective measure under Art. 32 DSGVO. The DSGVO requires "appropriate" technical measures to ensure integrity and confidentiality. An irreversible redaction that physically removes text from the PDF — and does not just visually mask it — is such a measure. A mere black bar is not sufficient, because the underlying text remains in the PDF content stream and can be reconstructed with simple means.

Datenmaske supports controllers at exactly this point: the automatic detection of personal data (names, IBANs, email addresses, telephone numbers, addresses, social security numbers) combined with irreversible removal from the PDF verifiably reduces the risk of unauthorised sharing within the meaning of the DPIA. The cryptographically secured redaction log serves as evidence of the measures taken towards supervisory authorities. If necessary, the redaction can be entered directly into the risk analysis of the DPIA as a control measure.

Practical tip: Link the DPIA with a clear release process. Before documents go out, they are automatically checked for PII, the suggestions confirmed by a specialist, the redacted PDF exported and the process logged. This creates a traceable process that does justice to both the DSGVO requirements and the requirements of a DPIA. Try the Free-Check to experience automatic detection in a concrete document, and read the detailed DSGVO guide to redaction for embedding it in your compliance process.

Consultation of the supervisory authority under Art. 36 DSGVO

If a high residual risk remains after carrying out the DPIA that the controller cannot mitigate by its own measures, Art. 36 DSGVO requires consultation of the supervisory authority. This decides whether the processing is in conformity with the regulation and which conditions apply. In practice, this case is rare if risk mitigation is consistently implemented — for example through strong TOMs such as encryption, pseudonymisation and, indeed, redaction. The DPIA is therefore not only an obligation, but also protection: anyone who carries it out carefully and documents it has an important exculpatory document in the event of damage.

Conclusion

The Data Protection Impact Assessment is not a bureaucratic exercise, but a pragmatic tool for risk management. Anyone responsible for high-risk procedures benefits from clear documentation of the risks and the measures. The automatic redaction of documents plays a central role here: it minimises the data volume on sharing, fulfils Art. 5 Abs. 1 lit. c (data minimisation) and Art. 25 DSGVO (privacy by design) and is documentable as a technical measure under Art. 32 DSGVO. This turns the DPIA into a robust foundation of data protection compliance — and not a mere paper exercise.

FAQ

What is a Data Protection Impact Assessment (DPIA)?

The DPIA under Art. 35 DSGVO is a structured process for assessing the impact of processing operations on the rights and freedoms of natural persons. It is required when a processing is likely to result in a high risk — for example with profiling, large-scale processing of sensitive data or systematic monitoring.

When is a DPIA mandatory?

Art. 35 Abs. 3 DSGVO names three cases: systematic and extensive evaluation of personal aspects including profiling, large-scale processing of special data categories under Art. 9 DSGVO and large-scale systematic monitoring of publicly accessible areas. In addition, the EDPB criteria catalogues (WP248) apply.

What must a DPIA contain at minimum?

Under Art. 35 Abs. 7 DSGVO, the DPIA comprises a systematic description of the processing operations, an assessment of necessity and proportionality, an assessment of the risks for data subjects, as well as the measures to address the risks (technical and organisational measures, safeguards, procedures).

Does the 75-employee rule apply to the DPIA?

There is no rigid statutory threshold of 75 employees. § 35 BDSG supplements Art. 35 DSGVO for the German sphere; in practice a rule of thumb is often cited that closer examination is sensible if at least 75 persons regularly carry out automated processing. Ultimately, however, the decisive factor is the high risk for data subjects, not the pure number of employees.

How does redaction help with the DPIA?

The automatic redaction of personal data before sharing documents is a technical measure for risk mitigation within the meaning of Art. 32 DSGVO and supports data minimisation (Art. 5 Abs. 1 lit. c) as well as privacy by design (Art. 25). In the DPIA it can be documented as a control measure; the redaction log serves as evidence.

What happens if a high residual risk remains?

If the risk remains high despite measures, the controller must consult the supervisory authority under Art. 36 DSGVO before continuing with the processing. The authority decides on admissibility and can impose conditions. In practice, this can usually be avoided through strong TOMs — encryption, pseudonymisation, redaction.

Weiterlesen