Skip to content
+370 5 212 1506 info@dat.lt

Data protection impact assessment: what it consists of, how long it takes and how much work it needs from you

23 September 2026 · Good to know

A data protection impact assessment, or DPIA for short, usually takes up to three weeks. Most of the work is not done by you: you receive a questionnaire that one or several employees can fill in, so the process does not require heavy involvement from management. The result is a document that states whether the planned operation poses a high risk to people’s rights and freedoms, and what needs to be done so that it does not.

This page does not answer the question of when an assessment is mandatory. That is a separate topic. It answers what the assessment consists of, how long it takes and what it will require of your organisation.

What a DPIA consists of

Our working definition is this: a DPIA is a process that identifies and assesses whether a data processing operation is carried out lawfully and does not pose a high risk to the rights and freedoms of natural persons.

The assessment must contain:

  • a description of the processing operation;
  • the purposes of the processing;
  • where legitimate interest is relied on (Article 6(1)(f) GDPR), a description of the legitimate interest;
  • an assessment of necessity and proportionality;
  • an assessment of the risks to the rights and freedoms of data subjects;
  • the security measures and procedures envisaged to address the risks;
  • a conclusion on whether the Regulation is complied with.

The minimum content is set by Article 35(7) GDPR. In practice, the weakest part is almost always necessity and proportionality. Describing what you will do is easy. Showing that the same purpose cannot be achieved in a less intrusive way is harder, and that is exactly what is asked.

If the organisation has appointed a data protection officer (DPO), Article 35(2) GDPR requires it to consult them. This is not a formality: the absence of the DPO’s opinion can later halt the whole process.

How much work it will require of you

This question is asked first, and it is usually the one people worry about most.

From a real answer we prepared for one institution: during the assessment you receive a questionnaire that one or several employees can fill in, so the process does not require heavy involvement from management. The assessment takes up to three weeks.

In practice it looks like this. The questionnaire is filled in by the people who actually use the system or buy it, often an IT or facilities employee and one manager. Clarifications then follow in writing. Management needs less time for this than people expect: at most, one conversation and one signature.

The law does not set this three-week period. It is a figure from practice, and it depends on how quickly the completed questionnaire comes back.

One case we can talk about

An institution was planning video surveillance with audio recording in the head’s office. The question it asked was simple: is this allowed at all?

The assessment was carried out precisely so that this could be answered: whether such an operation poses a high risk. If the conclusion was that it does not, the operation could go ahead. This is the real function of a DPIA: it is not an obstacle to overcome, but a way to get a reasoned “yes” or a reasoned “no” before the equipment is bought.

In Lithuania, audio recording is one of the situations in which an assessment is mandatory. This is worth knowing when buying a system: many devices record audio by default, and switching it off removes one of the reasons for the assessment obligation straight away.

What happens if the conclusion is negative

This part is often seen as a threat. It is not one.

If it is found that the planned operation would pose a high risk and the risk cannot be reduced by measures, you must consult the supervisory authority before starting to process the data (Article 36 GDPR). This is not a penalty. It is a route provided for in the Regulation.

One thing matters when planning: this consultation takes weeks, and during that time the data may not yet be processed. That is why the assessment is most useful when the decision has not yet been made: while choosing the system, not after installing it. Then the assessment often changes one or two decisions, and that is the end of it.

Children’s data

There are a few cases here that catch organisations by surprise. An assessment is mandatory when children’s data are processed:

  • for direct marketing purposes;
  • where personal aspects of children are evaluated by automated means, including profiling;
  • where information society services are offered directly to children.

This is set out in point 9 of the list approved by Order No 1T-35 (1.12.E) of the Director of the State Data Protection Inspectorate (VDAI) of 14 March 2019. The list was drawn up under Article 35(4) GDPR, which requires the supervisory authority to publish such a list.

One thing about this list is often overlooked: it is not exhaustive. The fact that a particular situation is not on it does not mean an assessment is not needed. The general rule in Article 35 GDPR always applies where processing may pose a high risk to people’s rights and freedoms.

And when you want to use children’s photos in advertising

This is no longer a question of assessment but of legal basis, and it is worth keeping the two clearly apart.

Using a child’s image in advertising requires consent. For use of the image, it is required by Article 2.22(1) of the Civil Code of the Republic of Lithuania (CK), and the legal basis for the data processing is Article 6(1)(a) GDPR. For a child who cannot yet consent themselves, consent is given on their behalf by the parents as their legal representatives (Article 3.157(1) CK); guardians act as representatives once they have provided a document confirming this (Article 3.157(2) CK). An assessment does not replace this consent and cannot stand in for it. If there is no consent, no assessment conclusion will allow the photo to be used.

The reverse is also true: having consent does not exempt you from an assessment if the processing falls within the list of operations for which one is mandatory.

How to start

The most useful way to start is a two-sentence description: what you plan to process, what technology you will use and when you want to launch. That is enough for us to tell you whether an assessment is mandatory in your case and whether we see a risk that you will need to consult the supervisory authority.

Write that description to us. We will tell you whether an assessment is needed, and only then propose a price and a timeline. The first answer is free of charge. Email: info@linden.lt.

A practical step-by-step guide is on Privacio, a site built by Linden: Kada reikia poveikio duomenų apsaugai vertinimo (DPIA)? (in Lithuanian). You can also check whether your organisation needs a record of processing activities with the Privacio tool (in Lithuanian).

More about this service: data protection impact assessment.

Get a free assessment

Related articles