Skip to main content

The Art of CTO PIA/DPIA Generator produces Privacy Impact Assessments and Data Protection Impact Assessments that satisfy GDPR Article 35, documenting processing purpose, necessity, risks to data subjects, and mitigating controls.

Frequently Asked Questions

When is a DPIA legally required?

Under GDPR Article 35 a DPIA is mandatory when processing is likely to result in high risk to individuals. This includes systematic and extensive automated decision-making with legal effects, large-scale processing of special category data such as health or biometric data, and large-scale systematic monitoring of publicly accessible areas. Many supervisory authorities publish their own additional lists of operations that always require one.

What is the difference between a PIA and a DPIA?

A DPIA is the specific assessment mandated by GDPR Article 35 and has prescribed content: a description of processing, an assessment of necessity and proportionality, an assessment of risks to data subjects, and the measures addressing those risks. A PIA is the broader, older discipline used in other jurisdictions and internal governance. In practice a DPIA is a PIA that meets GDPR's specific requirements.

Who needs to sign off on a DPIA?

The data controller owns the DPIA, and your Data Protection Officer must be consulted and their advice recorded. If the assessment shows high residual risk that you cannot mitigate, you must consult your supervisory authority before starting the processing. Engineering leaders typically supply the technical detail while the DPO or legal owns the final determination.