Back to blogCompliance

How to conduct a Data Protection Impact Assessment (DPIA)?

NRNicolas Renard·September 9, 2025· 10 min read

A Data Protection Impact Assessment, or DPIA, is a mandatory study for any personal data processing likely to result in a high risk to the rights and freedoms of data subjects: large scale profiling, video surveillance, health data processing, among others. The CNIL provides a free tool, PIA, along with a detailed methodology to structure this assessment, which weakens the excuse of lacking the tools to carry one out.

When is a DPIA mandatory?

Whiteboard covered with sticky notes and a detailed timeline, illustrating the structuring of a data protection impact assessment

A DPIA is required whenever a processing activity meets at least two of the following criteria: evaluation or scoring of individuals, automated decision making with legal effect, systematic monitoring, large scale processing of sensitive data, data matching, or processing concerning vulnerable individuals.

The steps of a DPIA

  1. Describe the intended processing: purposes, data collected, recipients, retention period.
  2. Assess the necessity and proportionality of the processing in relation to its purpose.
  3. Identify the risks to data subjects: illegitimate access, unwanted alteration, loss of data.
  4. Assess the severity and likelihood of each identified risk.
  5. Define measures to reduce these risks to an acceptable level.
  6. Document the entire process, so it can be presented to the data protection authority in the event of an inspection.

Typical structure of a DPIA

SectionContent
ContextDescription of the processing, purposes, data controller
PrinciplesNecessity, proportionality, measures ensuring data subject rights
RisksSources of risk, potential impacts, existing measures
Action planAdditional measures to implement and their owners

Worked example: warehouse video surveillance

A company installing video surveillance cameras in its warehouses, with facial recognition to control access, is a good illustration of the process. Out of the CNIL's six criteria, this processing meets at least three: systematic monitoring of employees, use of biometric (therefore sensitive) data, and often data matching with an existing badge system. The DPIA must therefore demonstrate that the purpose (securing access to sensitive areas) cannot be achieved through a less intrusive means, such as a simple badge without biometrics, before documenting risk-reduction measures: limited retention of footage, restricted access to recordings, clear information given to employees. This is precisely the kind of processing — disproportionate video surveillance combined with inadequate information to data subjects — for which the CNIL fined Amazon.fr €35 million in January 2024, alongside a finding on advertising cookies.

GDPR Diagnostic·See a diagnostic preview

Using the CNIL's PIA tool

The PIA software, free and downloadable from the CNIL's website, structures the process into modules that map exactly onto the four expected parts of a DPIA: context, measures, risks, validation. It includes a built-in knowledge base of common threats and measures, avoiding a blank-page start, and generates an exportable report that can be presented directly during an inspection. Its main value for an SME without in-house legal expertise is that it forces a quantified assessment of the severity and likelihood of each risk, rather than a vague qualitative call like 'low risk.'

Best practices for a useful DPIA

  • Involve the business team behind the project from the start, not just the DPO or legal team, to keep the assessment grounded in operational reality.
  • Document the less intrusive alternatives considered and ruled out, not just the option chosen.
  • Have the data controller explicitly sign off on the DPIA before the project launches, with a written record of that approval.
  • Review the DPIA whenever the processing changes significantly, not just on a fixed schedule.

Common mistakes

  • Conducting the DPIA after the processing has gone live, when it should precede its implementation.
  • Limiting it to a list of technical security measures, without actually assessing the risks to individuals.
  • Never updating the DPIA as the processing evolves.

A well conducted DPIA is not just a template to fill in: its value depends entirely on how seriously the risk assessment inside it is done, not on its formal compliance with the expected outline. A DPIA produced for form's sake, without genuinely questioning the processing, protects data subjects no better and offers no real safeguard in the event of an inspection. Building on a map of processing activities and risks already identified during a GDPR diagnostic, however, considerably speeds up its completion.

Ready to assess your organization?

Try for free