Direct answer · GDPR
When a DPIA is required
A DPIA is required where processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1)). That is in any case so for (Article 35(3)): (a) a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significant effects; (b) processing on a large scale of special categories of data or of data relating to criminal convictions and offences; (c) systematic monitoring of a publicly accessible area on a large scale. In addition, the list of the Dutch Data Protection Authority (Staatscourant 2019, 64418) includes, among others: employee monitoring, fraud prevention, profiling, credit scoring, camera surveillance, location data and biometric data. According to the EDPB guidelines, a DPIA is as a rule required where two or more of the nine criteria are met (such as evaluation or scoring, systematic monitoring, vulnerable data subjects such as employees, and innovative technology).
For you to establish
- Is the processing large-scale or systematic (the Dutch list sets its own condition per category)?
- Are decisions about people based on it?
Articles
- Art. 35(1) GDPR Main rule: likely high risk.
- Art. 35(3)(a) to (c) GDPR Three cases in which a DPIA is required in any event, including profiling with decisions.
- Art. 35(4) GDPR The supervisory authority establishes a list of processing operations that require a DPIA.
Guidelines and decisions
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679 (Article 29 Working Party, WP248 rev.01, 2017-10-04)Nine criteria; where two or more are met, a DPIA is as a rule required. Employees count as vulnerable data subjects.
- Opinion 2/2017 on data processing at work (Article 29 Working Party, WP249 (Opinion 2/2017), 2017-06-08)Data processing at work: monitoring of employees.
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA) (Autoriteit Persoonsgegevens (AP), Staatscourant 2019, nr. 64418, 2019-11-27)Dutch list of 17 types of processing, including employee monitoring, fraud prevention and profiling.
