A Data Protection Impact Assessment (DPIA) is mandatory under article 35 of the GDPR when a processing operation is likely to result in a high risk to data subjects. ZETA guides the entire DPIA process: from inventory to final report.
Article 35 of the GDPR lists several situations in which a DPIA is mandatory
Do you use algorithms or AI to assess, score or select people? Then a DPIA is mandatory, for HR systems, credit assessments or marketing personalisation.
Health data, biometric data, criminal information or data of vulnerable groups (children) always require a DPIA before processing.
Camera surveillance, location tracking or monitoring of behaviour on a large scale, including in the workplace, falls under the DPIA obligation.
Are you implementing a new IT system that processes personal data or linking existing systems? Then a DPIA before go-live is often mandatory or strongly recommended.
Fully compliant with DPA guidelines and EDPB recommendations
We fully inventory the processing: which data, from whom, for what purpose, how long it is retained, who has access, which third parties are involved?
For each risk, the likelihood and impact are assessed: unauthorised access, data loss, discrimination, identity theft. Scored on the basis of GDPR criteria.
For each identified risk we formulate concrete measures: technical (encryption, pseudonymisation) and organisational (policy, training, contracts).
A full DPIA report in the DPA format. Where residual risks remain, we assess whether prior consultation of the DPA is necessary and guide you through this process.
Fill in the form for a no-obligation advisory consultation
Mon-Fri 9:00-17:30 | 088 804 0777