DPIA / AIPD: GDPR impact assessment
A data protection impact assessment (DPIA, or AIPD in French) is a requirement under the GDPR for processing likely to result in a high risk to individuals' rights and freedoms. Here's when and how to conduct one.
When is a DPIA mandatory?
A DPIA is required whenever processing is likely to result in a high risk to individuals. This applies to large-scale processing, systematic monitoring, sensitive data (biometric, health, genetic), fully automated decisions with legal effect, and new systems or major changes.
Far from being a mere formality, a DPIA is a management tool: it structures risk thinking and determines the legitimacy of processing. It naturally fits into an overall GDPR compliance.
The 5 steps of a DPIA
1. Describe the processing
Purposes, data processed, categories of recipients, retention period and existing security measures.
2. Necessity & proportionality
Justify the legal basis, verify proportionality against purposes and consider less intrusive alternatives.
3. Analyze risks
For each risk: probability × severity. Assess unauthorized access, data loss or alteration, and consequences for individuals.
4. Define controls
For each high risk: technical controls (encryption, strong authentication) and organizational measures.
5. Consult the CNIL
If a high risk remains despite controls, submit the DPIA to the CNIL and incorporate its recommendations.
Review regularly
A DPIA is not static: it updates with every significant change to the processing.
What to document
A DPIA must leave a written record: processing description, legal basis justification, risk matrix, mitigation measures, and methods for collecting consent, processor contracts and incident response plans. The CNIL provides free templates. This documentation is concrete proof of your accountability, and an asset in case of data breach.
Typical risks and controls
Common risks include: data loss or corruption, unauthorized access, processing without valid legal basis, confidentiality breach, or discriminatory data-driven decisions. Common controls are encryption, strong authentication, logging (audit trail), anonymization or pseudonymization, and staff training. The goal is to link each identified risk to an appropriate control.
Conducting a DPIA in practice
Engage the right stakeholders
Business, IT, legal and, where applicable, the DPO : a DPIA is a collective effort.
Assess methodically
Describe, justify, score each risk (probability × severity) without downplaying any.
Decide and document
Select controls, assign responsibilities and document everything.
Consult if needed
Contact the CNIL if high residual risk remains and incorporate its recommendations.
Maintain over time
Schedule periodic reviews and updates whenever processing significantly changes.
Why work with BCIT?
The 5 steps, with you
We guide you through each DPIA step with your business and IT teams, using CNIL templates, to reach defensible risk scoring during audits.
DPO support
Our outsourced DPO service manages or oversees your impact assessments.
Have processing to assess?
Let's take 15 minutes to identify your processing requiring a DPIA and frame the assessment approach.
DPIA / AIPD: GDPR impact assessment
A data protection impact assessment (DPIA, or AIPD in French) is a requirement under the GDPR for processing likely to result in a high risk to individuals' rights and freedoms. Here's when and how to conduct one.
When is a DPIA mandatory?
A DPIA is required whenever processing is likely to result in a high risk to individuals. This applies to large-scale processing, systematic monitoring, sensitive data (biometric, health, genetic), fully automated decisions with legal effect, and new systems or major changes.
Far from being a mere formality, a DPIA is a management tool: it structures risk thinking and determines the legitimacy of processing. It naturally fits into an overall GDPR compliance.
The 5 steps of a DPIA
1. Describe the processing
Purposes, data processed, categories of recipients, retention period and existing security measures.
2. Necessity & proportionality
Justify the legal basis, verify proportionality against purposes and consider less intrusive alternatives.
3. Analyze risks
For each risk: probability × severity. Assess unauthorized access, data loss or alteration, and consequences for individuals.
4. Define controls
For each high risk: technical controls (encryption, strong authentication) and organizational measures.
5. Consult the CNIL
If a high risk remains despite controls, submit the DPIA to the CNIL and incorporate its recommendations.
Review regularly
A DPIA is not static: it updates with every significant change to the processing.
What to document
A DPIA must leave a written record: processing description, legal basis justification, risk matrix, mitigation measures, and methods for collecting consent, processor contracts and incident response plans. The CNIL provides free templates. This documentation is concrete proof of your accountability, and an asset in case of data breach.
Typical risks and controls
Common risks include: data loss or corruption, unauthorized access, processing without valid legal basis, confidentiality breach, or discriminatory data-driven decisions. Common controls are encryption, strong authentication, logging (audit trail), anonymization or pseudonymization, and staff training. The goal is to link each identified risk to an appropriate control.
Conducting a DPIA in practice
Engage the right stakeholders
Business, IT, legal and, where applicable, the DPO : a DPIA is a collective effort.
Assess methodically
Describe, justify, score each risk (probability × severity) without downplaying any.
Decide and document
Select controls, assign responsibilities and document everything.
Consult if needed
Contact the CNIL if high residual risk remains and incorporate its recommendations.
Maintain over time
Schedule periodic reviews and updates whenever processing significantly changes.
Why work with BCIT?
The 5 steps, with you
We guide you through each DPIA step with your business and IT teams, using CNIL templates, to reach defensible risk scoring during audits.
DPO support
Our outsourced DPO service manages or oversees your impact assessments.
Have processing to assess?
Let's take 15 minutes to identify your processing requiring a DPIA and frame the assessment approach.