Data protection impact assessment (DPIA)
In EU data protection, a data protection impact assessment (DPIA) is the analysis the GDPR requires before processing that is likely to result in a high risk to people’s rights. It is the deliverable a supervisory authority expects, and the place where a technical firm contributes the real risk picture. In Spain it is known as an EIPD.
How it works
A DPIA is a structured assessment carried out before a processing activity begins, when that activity is likely to pose a high risk to individuals: large-scale processing of sensitive data, systematic monitoring, new technologies, and similar triggers. It describes the processing and its purpose, assesses whether it is necessary and proportionate, identifies the risks to the people whose personal data is involved, and sets out the measures that reduce those risks. The AEPD publishes guidance on when one is required and how to conduct it, and the organisation’s data protection officer typically owns the process. Where the residual risk stays high after mitigation, the authority may need to be consulted before the processing starts.
What goes wrong
DPIAs are often written as paperwork that describes the processing without genuinely assessing the technical risk, which is the part a legal or governance team is not equipped to judge. The document lists safeguards (“data is encrypted”, “access is controlled”) without testing whether those safeguards actually hold, so the risk analysis rests on assumptions. From a security standpoint, that is the gap: the DPIA claims a control mitigates a risk, and nobody verified it. A processing activity assessed on paper can carry a real, unassessed exposure, and the assessment that was meant to protect individuals instead documents a false level of assurance.
Where this shows up in an audit
Where a DPIA is needed, a technical firm supplies the part the legal analysis cannot: an evidenced view of whether the stated safeguards resist attack, and what the realistic impact on individuals would be if they did not. We test the controls the DPIA relies on and feed the results into the risk assessment, so the document reflects measured risk rather than assumed safety. For high-risk AI processing this overlaps with the obligations under the EU AI Act. This is part of how we supply the technical risk for a DPIA.