DPIA: carrying out a data protection impact assessment

When a DPIA is mandatory, what it must contain and how to carry it out using the CNIL method, with a worked example.

· 11 min read
Illustration: a magnifying glass over a data grid with one orange cell

A DPIA (data protection impact assessment) is an assessment that the controller must carry out before launching personal data processing that is likely to result in a high risk to people's rights and freedoms. Required by Article 35 of the GDPR, it describes the processing, checks that it is necessary and proportionate, assesses its risks and sets out the measures to reduce them. It is mandatory as soon as the processing appears on the supervisory authority's list or meets at least two of the nine EDPB criteria.

01

What is a DPIA? Definition and Article 35 of the GDPR

Article 35 of the GDPR requires the controller, before processing begins, to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data where the processing is "likely to result in a high risk to the rights and freedoms of natural persons". It is one of the most concrete tools of the accountability principle: rather than registering its files with the authority as before 2018, the organisation demonstrates for itself that it has weighed the risks and made the right decisions.

The French authority, the CNIL, describes the DPIA as a tool for building processing that is compliant and respects privacy. Several names refer to the same exercise: DPIA in the GDPR, AIPD in French, and PIA (Privacy Impact Assessment), the older name the CNIL kept for its method and software.

A key point that is often misunderstood: the DPIA looks at risks to the people whose data is processed (employees, patients, customers, service users), not risks to the organisation. A health data leak is measured here by its consequences for patients (discrimination, reputational harm, distress), not by the cost of remediation. A single DPIA can cover a set of similar processing operations that present similar risks, so there is no need to start again for each site or subsidiary.

02

When is a DPIA mandatory?

The GDPR does not require a DPIA for every processing operation: most only need an entry in the record of processing activities. The obligation is triggered through four successive gateways.

The three cases listed in Article 35(3) GDPR

The text first expressly covers:

  • a systematic and extensive evaluation of personal aspects based on automated processing (including profiling), on which decisions producing legal effects are based;
  • large-scale processing of special categories of data (health, biometrics, opinions…) or of data relating to criminal convictions and offences;
  • systematic monitoring of a publicly accessible area on a large scale.

The 9 EDPB criteria and the two-criteria rule

To go beyond these three cases, the Article 29 Working Party, now the European Data Protection Board (EDPB), published guidelines (WP248) listing nine high-risk criteria. The CNIL draws a simple rule from them: processing that meets at least two criteria must undergo a DPIA. The nine criteria are evaluation or scoring, automated decisions with legal effect, systematic monitoring, sensitive or highly personal data, large scale, matching datasets, vulnerable data subjects, innovative use, and preventing people from exercising a right or using a contract. Test your processing below.

Checklist · The 9 EDPB criteria

Does my processing require a DPIA?

Tick the criteria that describe your processing. The verdict updates with each answer.

The CNIL lists
The 9 high-risk criteria
0/ 9 criteria ticked
DPIA not required a priori No criteria ticked. Keep the processing up to date in your record and review it if it changes.
Decision aid, not exhaustive. The criteria come from the Article 29 Working Party guidelines WP248, endorsed by the EDPB; the lists from CNIL decisions no. 2018-327 and no. 2019-118. The controller remains the judge, with the DPO's advice.

The CNIL list of processing requiring a DPIA

Each supervisory authority publishes its own list. The CNIL adopted a list of fourteen types of processing for which a DPIA is always required (decision no. 2018-327). It includes:

  • health data processing by healthcare or social-care institutions, and health data warehouses;
  • profiling of employees for HR purposes, such as algorithmic screening of applications, and constant monitoring of their activity;
  • whistleblowing schemes and social or health-related reporting systems;
  • profiling that may lead to exclusion from a contract (credit scoring) or that uses external data (data brokers);
  • biometrics applied to vulnerable people, and large-scale location data.

The list is not exhaustive: processing that is not on it may still require a DPIA if it meets two criteria.

When a DPIA is not required

Conversely, a second list of twelve types of processing (decision no. 2019-118) provides exemptions, such as HR management in an organisation with fewer than 250 staff and no profiling, supplier management, badge access control without biometrics, or patient management by a healthcare professional working alone. A DPIA is also unnecessary if the processing clearly presents no high risk, if it is very similar to processing that has already been assessed, or if it relies on a legal basis whose adoption already involved an impact assessment. In every case, document your reasoning: that is what an inspector will ask for.

03

What must a DPIA contain?

Article 35(7) of the GDPR sets a minimum content in four parts:

  • a systematic description of the envisaged processing operations and their purposes, including, where applicable, the legitimate interest pursued;
  • an assessment of the necessity and proportionality of the operations in relation to the purposes;
  • an assessment of the risks to the rights and freedoms of data subjects;
  • the measures envisaged to address those risks: safeguards, security measures and mechanisms to protect the data and demonstrate compliance.

In practice, a good DPIA report can be read by management in a few pages: a map of the processing, an analysis of the principles (legal basis, data minimisation, retention periods, information and rights of data subjects, oversight of processors and transfers), a risk assessment showing risk levels before and after measures, and the signed final decision.

04

How to carry out a DPIA: the CNIL's 4-step method

The GDPR does not impose a method. In France, the reference is the CNIL PIA method, published in three guides (the method, the templates, the knowledge bases) plus a case study. It has four steps, carried out iteratively.

CNIL PIA method · 4 steps
  1. Context Describe the processing: purposes, data, data subjects, recipients, retention periods, supporting assets.
  2. Fundamental principles Justify necessity and proportionality, and check the measures that protect people's rights.
  3. Risks For each feared event, estimate severity and likelihood, then choose the measures.
    • Illegitimate access
    • Unwanted modification
    • Disappearance
  4. Validation Action plan, opinions of the DPO and data subjects, decision by the controller.
Iterate until the risks are acceptable
Acceptable residual risks The processing goes live, then the DPIA is reviewed regularly.
High residual risk Prior consultation of the supervisory authority (Article 36) before going live.
The CNIL PIA method (2018 edition) in four steps. The three feared events map to the confidentiality, integrity and availability of the data.

Step 1: study the context

Describe the processing, its purposes, its stakes and its controller, then the data processed, its life cycle (collection, storage, use, deletion) and the assets that support it: applications, servers, service providers, paper. This description underpins everything else: a DPIA that skimps on it produces a risk analysis detached from reality.

Step 2: check the fundamental principles

First check that the processing is necessary and proportionate: a specified purpose, a legal basis, adequate and limited data, justified retention periods. Then review the measures that protect people's rights: information, consent where applicable, rights of access, rectification, erasure and objection, contracts with processors, transfers outside the EU.

Step 3: assess the risks to data security

The CNIL reasons in terms of three feared events: illegitimate access to data, unwanted modification and disappearance. They map to confidentiality, integrity and availability, the criteria found in the DICP classification. For each one, identify the impacts on people, the threats and their sources, then estimate severity and likelihood. Plotting these risks on a risk matrix helps decide where to focus effort.

Step 4: validate the DPIA

Build the action plan, obtain the DPO's opinion and, where possible, that of data subjects or their representatives, then the controller decides: DPIA validated, to be improved, or rejected. If risks remain too high, go back to the previous steps to strengthen the measures.

The tools: the CNIL PIA software and the European template

The CNIL distributes free, open-source PIA software for Windows, macOS and Linux, or for deployment on a server, which guides users step by step through its method and includes a legal and technical knowledge base. At European level, the EDPB adopted a harmonised DPIA template in April 2026, with an explanatory note, and put it out to public consultation until 9 June. The template mainly aims to make DPIAs comparable across countries; the EDPB states that it is not mandatory and that organisations remain free to choose their method. Whatever the format, running your DPIAs in GDPR compliance software linked to the record of processing avoids versions scattered across spreadsheets.

05

Who carries out the DPIA? The role of the DPO, the CISO and business teams

Responsibility for the DPIA lies with the controller, which in practice means the business unit that owns the project. It cannot be handed over entirely to the DPO, who should not be both judge and party.

  • The data protection officer (DPO) advises on how the DPIA is conducted and monitors its performance; their opinion is recorded in the file.
  • The CISO assesses existing or planned security measures and supports the risk assessment. On this role, read our article on the CISO.
  • Business and delivery teams describe the processing and implement the measures.
  • The processor (software vendor, hosting provider) provides the necessary information, as required by Article 28 of the GDPR. Assessing it is part of your third-party risk management.
  • Data subjects or their representatives are consulted where appropriate, for example staff representatives for an HR tool.

The right time to start the DPIA is the design phase, in line with data protection by design (Privacy by Design): it is much cheaper to drop an unnecessary data field on a mock-up than in software already in production. The DPIA is then reviewed whenever the processing changes: a new purpose, a new category of data, a new processor.

06

High residual risk: prior consultation of the supervisory authority

A DPIA is not normally sent to the authority: it is kept on file and produced in the event of an inspection. However, if it shows that the processing would result in a high residual risk despite the planned measures, Article 36 of the GDPR requires the controller to consult the supervisory authority before processing begins. In France, this is done through the CNIL's online service.

The authority then has eight weeks, which may be extended by six weeks depending on the complexity of the processing, to provide written advice. It may also use its corrective powers. Failing to carry out a mandatory DPIA, or failing to consult the authority when required, can lead to a fine of up to €10 million or 2% of total worldwide annual turnover (Article 83(4) GDPR).

07

DPIA vs cyber risk analysis: what is the difference?

Both approaches share a vocabulary (threats, severity, likelihood, measures) and feed into each other, but they do not answer the same question. A cyber risk analysis, carried out for example with EBIOS Risk Manager or following ISO 27005, protects the organisation's missions and assets.

DPIA and cyber risk analysis compared
DPIACyber risk analysis
What is protectedThe rights and freedoms of data subjectsThe organisation's missions, activities and assets
TriggerArticle 35 GDPR, high-risk processingISO 27001, NIS 2, DORA, security accreditation, security policy
ScopeOne personal data processing operationAn information system, a project, a service
Impacts assessedHarm to individualsBusiness, financial, legal and reputational impacts
Common methodsCNIL PIA method, EDPB templateEBIOS RM, ISO 27005
Possible outcomePrior consultation of the authorityRisk treatment plan, security accreditation

Security measures chosen in one often serve the other: encrypting a database protects both the patients and the hospital. Running both exercises in the same tool avoids describing the same assets and measures twice.

08

DPIA example: an application screening tool

Take a company with 1,200 employees that deploys online software to pre-screen job applications. The tool scores each CV and ranks the candidates; the vendor hosts the data. This simplified, fictitious example follows the four steps.

Is the DPIA mandatory?

Yes, on two counts. The processing is on the CNIL list (profiling for recruitment) and it meets several criteria: scoring candidates, innovative use (a selection algorithm), and the risk of excluding people from a contract, in this case employment.

Context and principles

The data processed covers identity, career history, skills and the score. Under data minimisation, the team removes the photo and date of birth from the form, as they serve no purpose for screening. Because Article 22 of the GDPR restricts fully automated decisions, every rejection is reviewed by a recruiter. Candidates are told an algorithm is used, and the contract with the vendor includes the Article 28 clauses.

Risks and measures

Simplified risk assessment example (CNIL scale: negligible, limited, significant, maximum)
Feared eventInitial severityMain measuresResidual risk
Illegitimate access to CVsSignificantEncryption, strong authentication, role-based access, assessment of the vendor's securityLimited
Unwanted modification (biased or wrong score)SignificantHuman review of rejections, regular bias testing, loggingLimited
Disappearance of applicationsLimitedBackups, acknowledgement of receipt to the candidateNegligible

After the measures, the residual risks are deemed acceptable: the DPO gives a favourable opinion, HR management validates the DPIA, and prior consultation of the authority is not needed. The DPIA will be reviewed if the vendor changes its scoring model.

09

Tooling your DPIAs with Phinasoft

The Phinasoft GDPR module helps you identify the scopes where a DPIA (PIA) is mandatory, carry out your PIAs and identify the main risks, track action plans and automatically generate the record of processing from your assessments. You can invite business teams to collaborate, guided step by step, import your DPIA history, start from a previous assessment rather than from scratch, and combine Privacy by Design with Security by Design. Healthcare organisations can also read our guide to HDS certification. To see a PIA carried out in the platform, request a demo.

Summary

01

A targeted obligation

A DPIA is only required for processing likely to result in a high risk: processing on the CNIL list and processing that meets at least two of the nine EDPB criteria.

02

A proven method

The CNIL PIA method has four steps: context, fundamental principles, risks, validation. The CNIL's free PIA software puts it into practice.

03

A living document

Carried out before the processing starts, the DPIA is reviewed whenever the processing changes. If the residual risk remains high, the authority must be consulted before going live.

Frequently asked questions

What is the difference between a DPIA and a PIA?

They are the same exercise. DPIA (Data Protection Impact Assessment) is the GDPR term. PIA (Privacy Impact Assessment) is the older name, which the French authority, the CNIL, kept for its method and its free software. In French, the GDPR term is AIPD.

Is a DPIA mandatory for every processing operation?

No. It is only required for processing likely to result in a high risk to people's rights and freedoms: processing on the supervisory authority's list (14 types in France) and processing that meets at least two of the nine EDPB criteria. Other processing is simply entered in the record of processing activities.

Who must carry out the DPIA?

The controller is responsible for it. It seeks the advice of the data protection officer (DPO) where one has been designated, involves business teams, IT and the CISO, and where appropriate seeks the views of data subjects. A processor must assist by providing the necessary information.

Do you have to send your DPIA to the supervisory authority?

Not as a rule. The DPIA is kept internally and produced in the event of an inspection. It is only submitted to the authority if the residual risk remains high despite the planned measures: this is the prior consultation under Article 36 of the GDPR.

How long does a DPIA take?

It depends on how complex the processing is and how mature the organisation is. A DPIA on a simple, well-documented processing operation can be done in a few workshops. Innovative, large-scale processing involving several processors takes more discussion. Starting from an existing DPIA on similar processing saves a lot of time.

What is the risk of not carrying out a DPIA?

Failing to carry out a mandatory DPIA breaches the controller's obligations. Article 83 of the GDPR provides for administrative fines of up to €10 million or 2% of total worldwide annual turnover for this type of breach, whichever is higher.

Is the EDPB DPIA template mandatory?

No. In April 2026 the EDPB adopted a harmonised DPIA template and put it out to public consultation. Using it is not mandatory: organisations remain free to choose their method, such as the CNIL's, as long as the DPIA meets the minimum content set by Article 35 of the GDPR.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.