DPIA screening
Assessing whether a DPIA is mandatory against the GDPR criteria and the list published by the Dutch Data Protection Authority. A documented decision, even where no DPIA turns out to be needed.
Embed AI · Zahed Ashkara
A DPIA (data protection impact assessment) is mandatory when processing is likely to result in a high risk to the people concerned (Article 35 GDPR). I carry out the DPIA with your team or review a DPIA that has already been drafted: from screening and description of the processing to risk analysis, measures and a decision that management can stand behind. For AI applications I connect the DPIA with the AI governance questions.
Assessing whether a DPIA is mandatory against the GDPR criteria and the list published by the Dutch Data Protection Authority. A documented decision, even where no DPIA turns out to be needed.
Description of the processing, necessity and proportionality, risks to data subjects and measures. In working sessions with the process owner, IT and security.
Second opinion on an existing DPIA: completeness, substantiation of risks, workability of measures and the DPO’s advice.
Management decision, residual risks, action owners and the moment for reassessment. Where needed, preparation of a prior consultation with the supervisory authority.
Zahed Ashkara is a legal counsel and freelance AI and privacy consultant, with assignments at Rabobank, Sanoma, drinking water utility PWN, central government and municipalities. Certified AI Compliance Officer and member of the NEN AI & Big Data standards committee.
View my experienceDownload profile (PDF)Practical privacy and GDPR knowledge hub
For processing likely to result in a high risk to people’s rights and freedoms, such as large-scale processing of special categories of data, systematic monitoring or profiling with legal effects. The Dutch Data Protection Authority publishes a list of processing operations for which a DPIA is always required.
That depends on the scale of the processing and the availability of information and people. A screening takes little time; a full DPIA with working sessions needs several weeks of lead time.
Yes. For AI applications I assess the AI governance questions alongside the privacy risks, such as human oversight and the supplier’s role. Where a fundamental rights impact assessment (FRIA) also applies to the AI system, I combine the two.
Then prior consultation with the Dutch Data Protection Authority is mandatory before processing starts (Article 36 GDPR). I prepare that consultation and advise on alternatives.
The effort depends on the processing and the information available. We discuss the approach and the rate upfront.
Legal source: AVG / GDPR, including Articles 5, 6, 28 and 35.
Include the desired start date, weekly hours and duration if known.