All services

Embed AI · Zahed Ashkara

DPIA support: carry out or review your DPIA

A DPIA (data protection impact assessment) is mandatory when processing is likely to result in a high risk to the people concerned (Article 35 GDPR). I carry out the DPIA with your team or review a DPIA that has already been drafted: from screening and description of the processing to risk analysis, measures and a decision that management can stand behind. For AI applications I connect the DPIA with the AI governance questions.

How I support your team

DPIA screening

Assessing whether a DPIA is mandatory against the GDPR criteria and the list published by the Dutch Data Protection Authority. A documented decision, even where no DPIA turns out to be needed.

Carrying out the DPIA

Description of the processing, necessity and proportionality, risks to data subjects and measures. In working sessions with the process owner, IT and security.

Reviewing a DPIA

Second opinion on an existing DPIA: completeness, substantiation of risks, workability of measures and the DPO’s advice.

Decision and follow-up

Management decision, residual risks, action owners and the moment for reassessment. Where needed, preparation of a prior consultation with the supervisory authority.

How do we start?

  1. 01Discuss the processing, the departments involved and the available documents.
  2. 02Agree the approach, working sessions, planning and rate.
  3. 03Carry out or review, discuss findings and record the decision.

Who you engage

Zahed Ashkara is a legal counsel and freelance AI and privacy consultant, with assignments at Rabobank, Sanoma, drinking water utility PWN, central government and municipalities. Certified AI Compliance Officer and member of the NEN AI & Big Data standards committee.

View my experienceDownload profile (PDF)

Practical privacy and GDPR knowledge hub

Frequently asked questions

When is a DPIA mandatory?

For processing likely to result in a high risk to people’s rights and freedoms, such as large-scale processing of special categories of data, systematic monitoring or profiling with legal effects. The Dutch Data Protection Authority publishes a list of processing operations for which a DPIA is always required.

How long does a DPIA take?

That depends on the scale of the processing and the availability of information and people. A screening takes little time; a full DPIA with working sessions needs several weeks of lead time.

Do you also do DPIAs for AI applications such as Microsoft 365 Copilot?

Yes. For AI applications I assess the AI governance questions alongside the privacy risks, such as human oversight and the supplier’s role. Where a fundamental rights impact assessment (FRIA) also applies to the AI system, I combine the two.

What if the residual risk remains high?

Then prior consultation with the Dutch Data Protection Authority is mandatory before processing starts (Article 36 GDPR). I prepare that consultation and advise on alternatives.

What does a DPIA cost?

The effort depends on the processing and the information available. We discuss the approach and the rate upfront.

Legal source: AVG / GDPR, including Articles 5, 6, 28 and 35.

Discuss your assignment

Include the desired start date, weekly hours and duration if known.