Skip to main content
Praxikon

Direct answer · GDPR

Is a DPIA required?

Short answer

A DPIA is required where processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1)). That is in any case so for profiling on which decisions are based, large-scale processing of special categories or criminal data, and systematic large-scale monitoring of public areas (Article 35(3)). The Dutch Data Protection Authority list adds, among others, employee monitoring and camera surveillance.

Direct answer · GDPR

When a DPIA is required

A DPIA is required where processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1)). That is in any case so for (Article 35(3)): (a) a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significant effects; (b) processing on a large scale of special categories of data or of data relating to criminal convictions and offences; (c) systematic monitoring of a publicly accessible area on a large scale. In addition, the list of the Dutch Data Protection Authority (Staatscourant 2019, 64418) includes, among others: employee monitoring, fraud prevention, profiling, credit scoring, camera surveillance, location data and biometric data. According to the EDPB guidelines, a DPIA is as a rule required where two or more of the nine criteria are met (such as evaluation or scoring, systematic monitoring, vulnerable data subjects such as employees, and innovative technology).

For you to establish

  • Is the processing large-scale or systematic (the Dutch list sets its own condition per category)?
  • Are decisions about people based on it?

Articles

Guidelines and decisions

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist