Guides and playbooks/Privacy
PRIVACYGDPRISO/IEC 27701

Six records that make a DPIA defensible

9 August 2026 · 5 min read
TL;DRFive things to take away
  • 01A DPIA is not judged on whether the document exists. It is judged on whether the reasoning behind it can still be produced, months later, for the processing as it runs today.
  • 02Six records carry that reasoning: the screening decision, the processing description, the necessity and proportionality assessment, the risk assessment, the measures with their owners, and the consultation and approval.
  • 03The screening decision matters even when the answer is no. An unrecorded decision not to run a DPIA is indistinguishable from never having considered it.
  • 04The most common failure is drift. The processing changes, the DPIA does not, and the document now describes a system that is no longer running.
  • 05Held as controlled records with owners and review triggers, these six answer an inspection directly. Held as one document in a folder, they answer it only if someone rewrites them first.

Article 35 of the GDPR requires a data protection impact assessment where processing is likely to result in a high risk to the rights and freedoms of natural persons. Most organisations know this and have documents to show for it. Fewer can produce, on request, the reasoning that led to the measures they chose, for the processing as it operates now rather than as it was designed.

That gap is what an inspection finds. The assessment was genuine at the time and the document is real, but the facts moved: a new sub-processor, a new data source, a widened purpose, a retention change, a country added. The DPIA still describes the earlier system.

Accountability is not the possession of privacy documents. It is the ability to demonstrate, at any point, what was decided, on what basis, by whom, and what has changed since.

The six records

RecordWhat it has to answer
1. Screening decisionWhy this processing does or does not require a DPIA, against Article 35(3) and the supervisory authority's list. Record it either way, with the date and the person deciding. An unrecorded decision not to assess is indistinguishable from never having considered it.
2. Processing descriptionPurposes, categories of data and data subjects, recipients, sub-processors, transfers and their safeguards, retention, and the systems involved. This is the record that goes stale first, and everything downstream depends on it being current.
3. Necessity and proportionalityThe lawful basis, why the data are necessary for the stated purpose, what less intrusive alternative was considered and rejected, and how data minimisation, accuracy, and storage limitation are satisfied in practice.
4. Risk assessmentRisks to the rights and freedoms of the data subjects, not risks to the organisation. Likelihood and severity of each, assessed from the individual's perspective, including illegitimate access, unwanted modification, and disappearance of data.
5. Measures and ownersEach measure addressing a specific identified risk, with a named owner, an implementation state, and the evidence that it works. A measure with no owner is an intention.
6. Consultation and approvalThe DPO's advice and, where sought, the views of data subjects or their representatives. The residual risk accepted, who accepted it, and whether prior consultation with the supervisory authority was required under Article 36.

Why a document alone does not carry them

Each of the six has a different lifetime. The screening decision is settled once unless the processing changes character. The processing description changes whenever a system, supplier, or purpose changes. Measures have owners who leave. Residual-risk acceptance has a person's name attached to a specific moment.

Bound into one document, they share a single version and a single review date, so the document is either rewritten wholesale or left to drift. Held as separate records with their own owners and review triggers, a change to one shows which of the others it reopens. That is the difference between a DPIA you can defend and a DPIA you have to reconstruct.

ISO/IEC 27701:2025 expresses the same idea as a privacy information management system: context, leadership, planning, support, operation, performance evaluation, and improvement working as a coherent system rather than as a shelf of deliverables.

Four questions about one DPIA you hold today

CurrencyDoes the processing description match the systems, sub-processors, and transfers in use this month?
OwnershipDoes every measure have a named owner who still works here, and evidence that it operates?
PerspectiveAre the risks stated as risks to the data subjects, rather than as risks to the organisation?
TriggersIs it defined what change reopens this assessment, and who is told when that change happens?

Summary and interpretation only, not legal advice. Sources: Regulation (EU) 2016/679 Articles 35 and 36, ISO/IEC 27701:2025.

COMMON QUESTIONS

Is a DPIA required for every processing activity

No. Article 35 requires one where processing is likely to result in a high risk to the rights and freedoms of natural persons, and specifically for systematic and extensive automated evaluation, large-scale special category data, or large-scale systematic monitoring of a publicly accessible area. The screening decision itself should be recorded, including when the answer is no.

Can a DPIA be completed after processing starts

It should be carried out prior to the processing. A DPIA produced after launch is evidence of a gap rather than evidence of compliance, and it cannot demonstrate that the measures chosen were informed by the assessment.

Does a DPIA have to be published

No. It has to be available to the supervisory authority on request and kept current as the processing changes.

THE FULL ARGUMENT

A systematic approach for the protection of personal data and privacy

Miguel Azevedo, Qity, 2026 · 21 pages, open access

Read the paper

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA