# Carrying Out a Data Protection Impact Assessment

The six steps of a DPIA under Article 35(7) GDPR: description, necessity and proportionality, identification and assessment of the risks using severity, likelihood and risk matrices, remedial measures, report, review and consultation under Article 36 GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.2-durchfuehrung
> Sprache: en



Once it has been established that a data protection impact assessment is required (see [Requirement](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.1-erforderlichkeit)), the assessment itself must be carried out. Article 35(7) GDPR sets out four mandatory substantive building blocks. These can be translated into a six-stage process that is workable in practice and concludes with a report.

<Callout type="info">
  **Key takeaways**

  * Minimum content under Article 35(7) GDPR: a description of the processing (point (a)), an assessment of necessity and proportionality (point (b)), an assessment of the risks (point (c)) and remedial measures (point (d)).
  * Risks are identified from the **perspective of the data subjects**, not from that of the company.
  * The level of a risk follows from the severity of the impact and the likelihood of its occurrence; a risk matrix brings the two together.
  * The process is iterative: once the remedial measures have been determined, the assessment steps are run through again, this time on the assumption that those measures have been implemented.
  * If a high residual risk remains, the supervisory authority must be consulted prior to the processing (Article 36 GDPR).
</Callout>

## 1. The four statutory building blocks [#1-the-four-statutory-building-blocks]

Article 35(7) GDPR requires at least:

* a systematic **description** of the envisaged processing operations and their purposes, including, where applicable, the legitimate interests pursued (point (a)),
* an **assessment of the necessity and proportionality** of the processing in relation to the purpose (point (b)),
* an **assessment of the risks** to the rights and freedoms of data subjects (point (c)),
* the **remedial measures** envisaged to address the risks, including safeguards, security measures and mechanisms by which the protection of the data is ensured and compliance with the Regulation is demonstrated (point (d)).

The GDPR does not prescribe any particular methodology. Methodological guidance is provided by the [Standard Data Protection Model of the German Data Protection Conference (DSK)](https://www.datenschutzkonferenz-online.de/media/ah/SDM-Methode-V31.pdf) and the [Bitkom guide on risk assessment](https://www.bitkom.org/Bitkom/Publikationen/Risk-Assessment-Datenschutz-Folgenabschaetzung.html). The following six steps give concrete shape to the four building blocks.

## 2. Step 1: description of the processing [#2-step-1-description-of-the-processing]

First, the controller describes the envisaged processing systematically, to the extent necessary for it to be understood. This includes:

* the nature, scope and circumstances of the processing as well as a functional description of what actually happens,
* the purposes of the processing, including, where applicable, the legitimate interests pursued,
* the data processed, the data flows and the recipients,
* the storage period,
* the underlying hardware, software and networks, including the system boundaries,
* the persons, bodies and external service providers involved as well as the underlying business processes.

The [records of processing activities](/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten) can be drawn on for this purpose. The description must be specific and at the same time concise enough to allow an outsider, such as a supervisory authority or an auditor, to form a picture of the risk-relevant aspects with reasonable effort. It constitutes the subject matter to be examined in the subsequent steps.

## 3. Step 2: necessity and proportionality [#3-step-2-necessity-and-proportionality]

In the second step, the controller examines whether the specific design of the processing is necessary and proportionate in view of the purposes. What is examined is whether there is an appropriate relationship between ends and means. Proportionality is lacking where less intrusive options exist by which the purpose can be achieved to the same extent. This step picks up the principle of [data minimization](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.5-datenminimierung) (Article 5(1)(c) GDPR).

The examination relates not only to the processing as a whole, but to the individual design aspects, in particular:

* the **storage period** (is earlier erasure of individual data categories possible?),
* the **volume of data** (is a reduction of the data fields or of the number of data subjects possible?),
* the **intensity of the processing** (is a lesser scope of analysis possible?).

Account must also be taken, and a description given, of the measures already implemented to comply with the GDPR, for example to uphold the data protection principles and the rights of data subjects, of the information provided, of agreements with processors and of measures relating to transfers to third countries.

## 4. Step 3: identification of the risks [#4-step-3-identification-of-the-risks]

Next, the risks to the rights and freedoms of data subjects associated with the processing are identified and described. What matters is the **perspective of the data subjects**, not that of the company; potential fines or reputational or business damage suffered by the controller are not relevant here. The risks may consist in physical, material or non-material damage, for example discrimination, identity theft, financial loss, loss of control over one's own data or unlawful profiling (Recital 75 GDPR).

When identifying the risks, the data protection objectives must be kept in view. **Integrity** and **confidentiality** follow directly from Article 5(1)(f) GDPR; the Standard Data Protection Model adds **availability, data minimization, unlinkability, transparency and intervenability**.

| Protection objective | Typical risk in the event of a breach                 |
| -------------------- | ----------------------------------------------------- |
| Confidentiality      | unauthorized access to data                           |
| Integrity            | unintended or unauthorized alteration                 |
| Availability         | unintended loss or erasure                            |
| Intervenability      | data subjects can no longer exercise their rights     |
| Unlinkability        | data are combined for incompatible purposes           |
| Transparency         | the processing is not comprehensible to data subjects |

For the subsequent assessment of likelihood, the various risk sources must be taken into account, that is, internal and external attackers as well as intent and negligence.

## 5. Step 4: assessment of the risks [#5-step-4-assessment-of-the-risks]

For each risk, two variables must be assessed: how severe the impact on the data subject would be if the harm materialized (severity of the impact) and how likely it is to occur (likelihood of occurrence). The following scales serve as guidance and are based on the methodological specifications of the [Bitkom guide](https://www.bitkom.org/Bitkom/Publikationen/Risk-Assessment-Datenschutz-Folgenabschaetzung.html) and of the Standard Data Protection Model.

### 5.1 Severity of the impact [#51-severity-of-the-impact]

| Level       | Meaning from the perspective of the data subjects                             |
| ----------- | ----------------------------------------------------------------------------- |
| Negligible  | any inconveniences can be overcome without difficulty                         |
| Limited     | noticeable inconveniences, which can be overcome with some difficulty         |
| Significant | considerable consequences, which can be overcome only with serious difficulty |
| Maximum     | considerable and possibly irreversible consequences, which cannot be overcome |

### 5.2 Likelihood of occurrence [#52-likelihood-of-occurrence]

| Level       | Feasibility of the threat                                |
| ----------- | -------------------------------------------------------- |
| Negligible  | seemingly impossible                                     |
| Limited     | difficult, feasible only with a certain amount of effort |
| Significant | possible, feasible even with little effort               |
| Maximum     | easy                                                     |

### 5.3 Risk matrix [#53-risk-matrix]

The risk band follows from severity and likelihood. The rows represent the severity of the impact, the columns the likelihood of occurrence.

| Impact \ Likelihood | Negligible | Limited | Significant | Maximum |
| ------------------- | :--------: | :-----: | :---------: | :-----: |
| **Maximum**         |   medium   |  medium |     high    |   high  |
| **Significant**     |   medium   |  medium |    medium   |   high  |
| **Limited**         |     low    |  medium |    medium   |  medium |
| **Negligible**      |     low    |   low   |    medium   |  medium |

The result is not the final verdict, but the basis for the risk treatment in the next step. Absolute security cannot be achieved in data and IT security; at the end there is always the assessment of a remaining residual risk.

## 6. Step 5: determining the remedial measures [#6-step-5-determining-the-remedial-measures]

For each assessed risk, the risk treatment must be determined. There are four options:

* **risk mitigation** through remedial measures,
* **risk acceptance** as a deliberate decision to accept the risk without further measures,
* **risk avoidance** by refraining from the risk-bearing activity,
* **risk transfer** by shifting the consequences of the risk to third parties, for example an insurer.

Where the measures already envisaged are not sufficient to reduce the risk to an acceptable residual risk, additional remedial measures must be determined. This is called for in particular where a high risk or numerous medium risks remain. Remedial measures may be technical, organizational or legal in nature.

<Callout type="warn">
  Remedial measures must not remain abstract. Each measure must be assigned to a specific risk and protection objective and described as precisely as possible. The statement "use of encryption" is not sufficient; what has to be specified is the object of the encryption, the method and the key length. A mere list of all security measures without reference to the respective risk is not enough.
</Callout>

Once the remedial measures have been determined, steps 2 to 5 must be run through again, this time on the assumption that the measures are implemented. This shows whether the residual risk becomes acceptable.

## 7. Step 6: overall assessment and report [#7-step-6-overall-assessment-and-report]

Finally, it is determined whether the risks have been sufficiently reduced by the remedial measures. The content and results of all steps are brought together and documented in a report. This report is evidence that the obligation under Article 35 GDPR has been fulfilled and forms part of [accountability](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.9-rechenschaftspflicht) (Article 5(2) GDPR). It is advisable to maintain the report continuously across all steps rather than to draw it up only at the end.

If the overall assessment is positive, the processing may take place as soon as the remedial measures determined have been implemented. If it is negative, that is, if a high risk remains despite the measures, the processing may not be commenced before the supervisory authority has been consulted (see 9.).

<Callout type="info">
  **Use templates.** You do not have to develop your own structure for the report. The European Data Protection Board has presented a uniform template that the authorities intend to adopt in future or to use as the basis for national templates ([EDPB DPIA Template](https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2026/edpb-dpia-template_en)). In addition, the [Standard Data Protection Model](https://www.datenschutzkonferenz-online.de/media/ah/SDM-Methode-V31.pdf) and the [Bitkom guide](https://www.bitkom.org/Bitkom/Publikationen/Risk-Assessment-Datenschutz-Folgenabschaetzung.html) offer fully worked-out methodologies and model tables.
</Callout>

## 8. Review and updating (paragraph 11) [#8-review-and-updating-paragraph-11]

A data protection impact assessment is not a one-off act. Where necessary, the controller carries out a review to assess whether the processing continues to be performed in accordance with the impact assessment; this applies at least where there is a change of the risk represented by the processing (Article 35(11) GDPR). Such changes may arise, for example, from new interfaces, new technology, new security risks or an altered legal situation. There is no grandfathering for processing operations that were already running before the GDPR became applicable.

<Callout type="info">
  **Practical recommendation on review intervals.** Beyond event-driven review, a regular review at fixed intervals, for example every twelve months, is advisable. In a first step, a summary check is made as to whether a reassessment of the risks is necessary; if it is, the process is run through again accordingly. The review must be documented.
</Callout>

## 9. Consultation of the supervisory authority (Article 36 GDPR) [#9-consultation-of-the-supervisory-authority-article-36-gdpr]

Where the data protection impact assessment indicates that the processing would result in a high risk despite the remedial measures envisaged, the controller consults the supervisory authority prior to the processing ([Article 36(1) GDPR](https://dsgvo-gesetz.de/art-36-dsgvo/)). Consultation is therefore the consequence of a remaining high residual risk.

When consulting, the controller provides the supervisory authority in particular with (Article 36(3) GDPR):

* the respective responsibilities in the case of joint controllership,
* the purposes and means of the intended processing,
* the measures and safeguards provided to protect the data subjects,
* where applicable, the contact details of the data protection officer,
* the data protection impact assessment itself, and
* any other information requested.

The supervisory authority provides written advice within eight weeks of receipt of the request. In the case of complex processing, it may extend that period by six weeks. Where it considers that the intended processing would not comply with the Regulation, it may exercise its powers under Article 58 GDPR, up to and including a ban on the processing (Article 36(2) GDPR).

<Cards>
  <Card title="Article 35 GDPR" href="https://dsgvo-gesetz.de/art-35-dsgvo/" description="Data protection impact assessment." />

  <Card title="Article 36 GDPR" href="https://dsgvo-gesetz.de/art-36-dsgvo/" description="Prior consultation of the supervisory authority." />

  <Card title="Standard Data Protection Model" href="https://www.datenschutzkonferenz-online.de/media/ah/SDM-Methode-V31.pdf" description="Method for selecting and assessing technical and organizational measures." />

  <Card title="Bitkom guide on risk assessment" href="https://www.bitkom.org/Bitkom/Publikationen/Risk-Assessment-Datenschutz-Folgenabschaetzung.html" description="Methodology for risk assessment and data protection impact assessments." />

  <Card title="EDPB DPIA Template" href="https://www.edpb.europa.eu/our-work-tools/documents/public-consultations/2026/edpb-dpia-template_en" description="Uniform template of the European Data Protection Board for the DPIA report." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.