# Internal Organization of a Data Protection Impact Assessment

Who does what within an organization during a DPIA? Roles and responsibilities of the business unit, the data protection officer, contributing units, data subjects and processors, with a proposed internal procedure under Article 35 GDPR.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.3-unternehmensinterne-organisation
> Sprache: en



The GDPR assigns the data protection impact assessment to the controller but says nothing about how an organization is to distribute the task internally. A clear allocation of roles is nevertheless decisive, because a data protection impact assessment typically requires several units to contribute. This page describes a proven model of roles and a proposed internal procedure. The statutory reference points are named in the text; the organizational arrangement is a recommendation, not a statutory requirement.

<Callout type="info">
  **Key takeaways**

  * Responsibility remains with the controller; internally, the lead lies with the **unit with subject-matter responsibility** that plans the processing.
  * The **data protection officer advises** and accompanies the process but bears no responsibility for its content and outcome (Article 35(2) GDPR).
  * **Contributing units** such as IT security, IT operations and the business units concerned must supply their expertise.
  * The views of the **data subjects** must be sought where appropriate (Article 35(9) GDPR), in the case of employees typically through the employee representative body.
  * **Processors** must be involved where necessary; they are contractually bound to assist with the impact assessment (Article 28(3)(f) GDPR).
</Callout>

## 1. Basic allocation of responsibility [#1-basic-allocation-of-responsibility]

### 1.1 The controller bears the obligation [#11-the-controller-bears-the-obligation]

Externally, the addressee of the obligation is the [controller](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.7-verantwortlicher) (Article 35(1) GDPR). The controller may organize the performance of the task internally but cannot divest itself of responsibility for it. In particular, the data protection impact assessment cannot be delegated to the data protection officer: the officer must be involved but does not carry out the assessment personally (Article 35(2) GDPR).

### 1.2 The unit with subject-matter responsibility takes the lead [#12-the-unit-with-subject-matter-responsibility-takes-the-lead]

In practice, the lead lies with the organizational unit that has subject-matter responsibility for the processing, that is, the business unit or process owner planning the project. This unit has the best knowledge of the purpose, the data flows and the technical arrangement, and is therefore the right place for the systematic description and for the assessment of necessity and proportionality. It makes sense for its management to entrust a specific individual with carrying out the assessment. Where several units are responsible, the unit to which they are jointly subordinate takes the lead; where no such unit can be clearly identified, the units involved should agree on a lead unit at an early stage.

## 2. The participants and their roles [#2-the-participants-and-their-roles]

<Mermaid
  chart="flowchart TD
  V[Controller] --> F[Unit with subject-matter responsibility<br/>lead]
  F -->|advises, no transfer of responsibility| D[Data protection officer]
  F -->|supply expertise to| M[Contributing units:<br/>IT security, IT operations, business units]
  F -->|seeks the views of| B[Data subjects / employee representatives]
  F -->|involves where necessary| A[Processor]
  F -->|may call in| E[External experts]"
/>

### 2.1 Data protection officer: advisory, without decision-making power [#21-data-protection-officer-advisory-without-decision-making-power]

Where a [data protection officer](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.3-aufgaben) has been designated, the controller seeks and takes into account that officer's advice (Article 35(2) GDPR). Advising on the data protection impact assessment is one of the officer's statutory tasks (Article 39(1)(c) GDPR). The role is a supporting one: the officer bears no responsibility for the content and the documentation and has no decision-making power of their own over the impact assessment. The advice is not binding; however, if the controller departs from advice that is substantively correct, this may be held against the controller in an inspection by the supervisory authority.

<Callout type="warn">
  **Maintain the separation of roles.** If the data protection officer in fact carries out the impact assessment personally, this conflicts with the task of monitoring compliance with the Regulation (Article 39(1)(b) GDPR): the officer would then be monitoring their own work. Responsibility for the substance should therefore rest with the business unit, and the advisory support with the data protection officer.
</Callout>

### 2.2 Contributing units [#22-contributing-units]

The lead unit calls in further units that can supply factual information or expertise, in particular information security, IT operations and the areas dealing with the processing in substantive terms. They contribute above all to identifying and assessing the risks, determining the remedial measures and reaching the overall assessment. It makes sense for each contributing unit to nominate a contact person who is technically competent and empowered to make decisions.

### 2.3 Optional committee for coordination [#23-optional-committee-for-coordination]

For complex projects with many participants, a dedicated coordination committee can bring the process together. Such a committee typically consists of the management of the lead unit and one representative from each contributing unit. Depending on the occasion, the exchange may take place by written circulation, by telephone or in meetings; written minutes are recommended for meetings. Such a committee is not mandatory; for smaller projects, direct coordination between the business unit and the data protection officer is sufficient.

### 2.4 Data subjects and employee representatives [#24-data-subjects-and-employee-representatives]

Where appropriate and possible, the controller seeks the views of the data subjects or their representatives on the intended processing and engages with those views (Article 35(9) GDPR). Where employees are primarily affected, this will regularly be the staff council or the works council. Seeking those views is not mandatory in every case; it comes into consideration above all where the group of data subjects can be specifically identified. If the views are not sought, for instance because of conflicting confidentiality interests or because the group of data subjects cannot be delimited, the reasons must be documented. The same applies where the controller decides against the views obtained.

### 2.5 Processors and external experts [#25-processors-and-external-experts]

Where the processing is also carried out by a [processor](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.8-auftragsverarbeiter), the lead unit involves that processor where necessary, for example in order to clarify risks and protective measures on the processor's side. The processor is contractually obliged to assist the controller with the data protection impact assessment (Article 28(3)(f) GDPR). Beyond this, the controller may call in external experts at its own expense, for example on questions of IT security.

## 3. Proposal for an internal procedure [#3-proposal-for-an-internal-procedure]

An orderly internal procedure ensures that the data protection impact assessment begins in good time and that all participants are involved.

<Steps>
  <Step>
    **Threshold analysis at the planning stage.**

     The unit with subject-matter responsibility examines at an early stage whether a high risk exists and documents the result (see 

    [Requirement](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.1-erforderlichkeit)

    ). In case of doubt, it calls in the data protection officer.
  </Step>

  <Step>
    **Inform the data protection officer and determine the participants.**

     If a data protection impact assessment is required, the data protection officer is informed without undue delay; the contributing units and, where applicable, a coordination committee are determined.
  </Step>

  <Step>
    **Carry out the impact assessment.**

     The lead unit works through the six steps (see 

    [Carrying out the assessment](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.2-durchfuehrung)

    ) and drafts the report as it goes.
  </Step>

  <Step>
    **Overall assessment and decision.**

     The result is established and documented. Where a high risk remains, the supervisory authority must be consulted prior to the processing (Article 36 GDPR).
  </Step>

  <Step>
    **Implementation and monitoring.**

     The lead unit ensures that the remedial measures determined are actually implemented and verifies this where necessary. Implementation and verification are documented.
  </Step>
</Steps>

<Callout type="info">
  **Practical tip on the separation of tasks.** Record in writing who is responsible for content and completeness (the business unit) and who advises and checks for plausibility (the data protection officer). This separation prevents the conflict of roles and makes the responsibilities demonstrable in the event of a dispute.
</Callout>

## 4. Retention and connection to the documentation [#4-retention-and-connection-to-the-documentation]

The completed report is assigned to the internal documentation and linked to the [records of processing activities](/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten). In this way, the data protection impact assessment can be located at any time and, together with the documented threshold analysis, evidences compliance with the [accountability](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.9-rechenschaftspflicht) obligation (Article 5(2) GDPR).


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.