Governance & Operations
What is DPIA (Data Protection Impact Assessment)?
A DPIA (data protection impact assessment) is a structured analysis, required by GDPR Article 35 before high-risk processing begins, that documents a planned use of personal data, assesses its risks to individuals, and records the measures taken to mitigate them.
The DPIA is GDPR's mechanism for forcing risk analysis before the fact. It is mandatory where processing is 'likely to result in a high risk to the rights and freedoms of natural persons,' with three named triggers: systematic and extensive automated evaluation or profiling producing significant effects; large-scale processing of special-category or criminal data; and systematic large-scale monitoring of publicly accessible areas. Supervisory authorities publish supplementary lists — new technologies, data matching, tracking of vulnerable people, and combinations of risk factors commonly appear.
A compliant DPIA contains four elements: a systematic description of the processing and its purposes (including legitimate interests pursued), an assessment of necessity and proportionality, an assessment of the risks to data subjects, and the measures envisaged to address those risks and demonstrate compliance. Where a DPO is appointed, their advice must be sought; where residual risk remains high after mitigation, the controller must consult the supervisory authority before proceeding.
In practice, DPIAs work best as a screening-plus-deep-dive pipeline: a lightweight threshold assessment on every new project, tool, or campaign determines whether a full DPIA is needed, so the heavyweight process is spent only on genuinely risky processing. The DPIA is a living document — revisited when the processing changes — and a keystone of the accountability principle: it is the artifact you produce when a regulator asks 'show me you thought about this.'
US law is converging: Virginia, Colorado, Connecticut, and other state statutes require 'data protection assessments' for targeted advertising, sales of data, profiling, and sensitive-data processing — narrower documents than a GDPR DPIA, but the same discipline.
Why it matters for eCommerce
The DPIA triggers most relevant to eCommerce are profiling and targeted advertising at scale, loyalty programs joining purchase histories with behavioral data, and anything touching health-adjacent inferences. US state laws now independently require assessments for targeted advertising — meaning a store retargeting Virginians needs documented assessments even with zero EU exposure. A data map makes the 'describe the processing' step an export instead of an archaeology dig.
Frequently asked questions
- When is a DPIA legally required?
- Under GDPR, before processing likely to create high risk — notably systematic extensive profiling with significant effects, large-scale special-category processing, or large-scale systematic monitoring of public areas, plus items on your regulator's published list. US state laws separately require data protection assessments for targeted advertising, data sales, certain profiling, and sensitive data.
- What happens if a DPIA shows high residual risk?
- Under GDPR Article 36, the controller must consult the supervisory authority before starting the processing. The authority can advise, and ultimately restrict or ban the processing — which is why mitigation measures are designed into the plan during the DPIA rather than after.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
DPIA support in PieEye Data Mapping