A data protection impact assessment (DPIA) is a written analysis carried out before a new processing of personal data begins. Its purpose is to identify the risks to the people whose data is processed and to put measures in place to reduce them.
When a DPIA is required
Under the GDPR, with which Albanian Law 124/2024 is aligned, a DPIA is required when processing is likely to result in a high risk to the rights and freedoms of individuals. Typical examples are:
- Systematic evaluation of people by automated means, including profiling, when decisions with significant effects are based on it.
- Large-scale processing of sensitive data, such as health data.
- Systematic monitoring of public areas on a large scale, for example with cameras.
If you are unsure, it is better to do the assessment than to skip it. Even a short DPIA that concludes the risk is low is evidence of your care.
What it contains
- A description of the processing: what data, about whom, for what purpose and with which systems.
- An assessment of whether the processing is necessary and proportionate to the purpose.
- The risks to individuals and how severe and likely they are.
- The measures that will be taken to reduce the risks.
Common mistakes
- It is done after the system has been bought or built, when changes are expensive.
- It is written once and not updated when the processing changes.
- It describes the risks to the company and not to the people whose data is processed.
A DPIA is not a form to fill in. It is a way to make better decisions before you invest in a system.
