Skip to Content

DPIA / AIPD: GDPR impact assessment

A data protection impact assessment (DPIA, or AIPD in French) is a requirement under the GDPR for processing likely to result in a high risk to individuals' rights and freedoms. Here's when and how to conduct one.

BCIT Formation logo
BCIT Formation is rated Excellent
4.7 · Trustpilot
🎓 +1000 learners trained

When is a DPIA mandatory?

A DPIA is required whenever processing is likely to result in a high risk to individuals. This applies to large-scale processing, systematic monitoring, sensitive data (biometric, health, genetic), fully automated decisions with legal effect, and new systems or major changes.

Far from being a mere formality, a DPIA is a management tool: it structures risk thinking and determines the legitimacy of processing. It naturally fits into an overall GDPR compliance.

The 5 steps of a DPIA

1. Describe the processing

Purposes, data processed, categories of recipients, retention period and existing security measures.

2. Necessity & proportionality

Justify the legal basis, verify proportionality against purposes and consider less intrusive alternatives.

3. Analyze risks

For each risk: probability × severity. Assess unauthorized access, data loss or alteration, and consequences for individuals.

4. Define controls

For each high risk: technical controls (encryption, strong authentication) and organizational measures.

5. Consult the CNIL

If a high risk remains despite controls, submit the DPIA to the CNIL and incorporate its recommendations.

Review regularly

A DPIA is not static: it updates with every significant change to the processing.

What to document

A DPIA must leave a written record: processing description, legal basis justification, risk matrix, mitigation measures, and methods for collecting consent, processor contracts and incident response plans. The CNIL provides free templates. This documentation is concrete proof of your accountability, and an asset in case of data breach.

Typical risks and controls

Common risks include: data loss or corruption, unauthorized access, processing without valid legal basis, confidentiality breach, or discriminatory data-driven decisions. Common controls are encryption, strong authentication, logging (audit trail), anonymization or pseudonymization, and staff training. The goal is to link each identified risk to an appropriate control.

Conducting a DPIA in practice

1

Identify at-risk processing

Rely on the processing register to identify those requiring a DPIA.

2

Engage the right stakeholders

Business, IT, legal and, where applicable, the DPO : a DPIA is a collective effort.

3

Assess methodically

Describe, justify, score each risk (probability × severity) without downplaying any.

4

Decide and document

Select controls, assign responsibilities and document everything.

5

Consult if needed

Contact the CNIL if high residual risk remains and incorporate its recommendations.

6

Maintain over time

Schedule periodic reviews and updates whenever processing significantly changes.

Why work with BCIT?

The 5 steps, with you

We guide you through each DPIA step with your business and IT teams, using CNIL templates, to reach defensible risk scoring during audits.

DPO support

Our outsourced DPO service manages or oversees your impact assessments.

Legal & technical risks

We link the assessment GDPR to concrete security controls through our audits.

Have processing to assess?

Let's take 15 minutes to identify your processing requiring a DPIA and frame the assessment approach.