A new tool, a new process or a supplier that will process personal data: the first privacy question is almost always the same. Does this need a DPIA? The honest answer is often "it depends", and that is exactly why the screening matters. A DPIA screening is a short, documented assessment that determines whether a full data protection impact assessment is required. Done well, it prevents two expensive mistakes: skipping a DPIA where one was mandatory, or spending months on a DPIA nobody asked for.
Below are the five questions I use in practice, with the legal basis. This is my working method as a privacy lawyer, not an official checklist from a supervisory authority.
When is a DPIA mandatory?
The basic rule is in Article 35(1) GDPR: a DPIA is required where processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. Article 35(3) names three situations where this is the case in any event: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, with legal or similarly significant effects; large-scale processing of special categories of data or of criminal data; and systematic monitoring of publicly accessible areas on a large scale.
The European supervisory authorities have developed this into nine criteria, such as evaluation or scoring, automated decision-making with legal effect, systematic monitoring, sensitive data, large scale, matching or combining datasets, vulnerable data subjects, innovative use of technology and processing that may prevent people from exercising a right or using a service. Rule of thumb from those guidelines: where processing meets two or more criteria, a DPIA is usually required.
In addition, the Dutch Data Protection Authority has published a list of processing operations for which a DPIA is always mandatory in the Netherlands. It includes covert investigation, blacklists, fraud prevention, credit scoring, large-scale processing of health and genetic data, camera surveillance, employee monitoring, location data, communication data, profiling, behavioural influencing and biometric identification. If your processing is on that list, the screening is done: a DPIA is mandatory.
The five screening questions
1. Which personal data, about whom, and for what purpose? Describe the processing in plain language: which data, about which people, for what purpose, and who has access. Without this description, every risk estimate is a guess. Include suppliers and sub-processors; the data flow does not stop at your own systems.
2. Does it involve sensitive data or vulnerable people? Health, criminal history, financial situation, biometrics, data about children, employees or clients in the social domain. Each of these categories weighs heavily. Employees count as vulnerable because of their dependent position, even where monitoring looks harmless.
3. How large and how systematic is the processing? The number of data subjects, the volume of data, the duration and the geographical reach together determine the scale. A one-off analysis is different from continuous monitoring. Systematic observation or scoring of behaviour is a strong signal for a DPIA.
4. Are decisions taken about people, is there profiling, or is new technology involved? Automated decision-making, profiling, scoring, combining datasets from different sources, AI applications and new sensor technology belong here. For AI applications I assess, alongside the privacy risks, who takes the decision, how human oversight is organised and what the supplier's role is.
5. What has changed since the previous assessment? A DPIA is not a one-off exercise. Article 35(11) GDPR requires a review when the risk changes: a new purpose, a new supplier, a larger audience, a link to another system. An existing processing operation can become subject to a DPIA through a change.
The answer is no: what do you record?
A negative screening result also deserves a documented decision. Record who carried out the screening, on what date, with what information, which criteria were assessed and why a DPIA is not required. Ask the data protection officer for advice if your organisation has one; Article 35(2) GDPR requires that for a DPIA, and it is sensible for a screening. Agree a moment to revisit the screening. That way you can later show a supervisory authority, an auditor or a customer that the question was answered seriously.
The answer is yes: what does the DPIA look like?
A DPIA describes the processing and its purposes, assesses necessity and proportionality, maps the risks to data subjects and sets out the measures that reduce those risks. The result is a management decision with residual risks, action owners and a date for reassessment. Where the residual risk remains high, the organisation must consult the Dutch Data Protection Authority before processing starts (Article 36 GDPR).
In practice, a DPIA works best in working sessions with the process owner, IT and security, with a lawyer asking the questions and recording the outcomes. Would you like the screening or the full DPIA carried out, or an existing DPIA reviewed? See DPIA support: carry out or review your DPIA or use the privacy and AI scan to see where your organisation stands.
Frequently asked questions
Is a DPIA mandatory for every AI application? No. An AI application without personal data falls outside the GDPR. Where the application does process personal data, innovative technology, profiling and automated decision-making weigh heavily, and a DPIA is often needed. For high-risk AI systems under the EU AI Act, a fundamental rights impact assessment may apply as well.
Can we adopt the supplier's DPIA? A supplier can provide a generic DPIA or a detailed description, and that is useful input. Responsibility for assessing your own processing remains with your organisation as controller.
How long does a DPIA screening take? With a good description of the processing, a screening is completed in a single working session. The full DPIA takes several weeks of lead time, mainly because information has to be collected from different departments.

