Skip to content
+370 5 212 1506 info@dat.lt

Data protection impact assessment (DPIA)

A data protection impact assessment (DPIA) is a new procedure introduced by the General Data Protection Regulation (GDPR). Its purpose is to ensure compliance with the accountability principle and with the other requirements of the GDPR. You can find more information about the DPIA, and about the cases in which it is mandatory, by following this link (in Lithuanian). A DPIA examines a specific processing operation: it establishes whether that operation poses a high risk to the rights and freedoms of natural persons and sets out recommendations for reducing the risks identified. Where no measures are available to reduce the risk, prior consultation with the State Data Protection Inspectorate (VDAI) is recommended. Our support with a DPIA covers:

  • an initial consultation, free of charge, on whether you need to carry out a DPIA;
  • if an assessment is needed, we send you a proposal that you can discuss with our team;
  • we prepare a dedicated questionnaire for the assessment;
  • where possible, we see the processing operation under assessment in person;
  • we carry out the DPIA on the basis of the information collected;
  • the outcome of the DPIA is a DPIA report with recommendations either for reducing the risks or for prior consultation with the State Data Protection Inspectorate;

Contact us for a free consultation by filling in the form on the right-hand side of this page.

Contact us

    Check it yourself

    A practical step-by-step guide is on Privacio, a site built by Linden: Kada reikia poveikio duomenų apsaugai vertinimo (DPIA)? (in Lithuanian). You can also check whether your organisation needs a record of processing activities with the Privacio tool (in Lithuanian).

    Frequently asked questions

    When is a data protection impact assessment mandatory?

    When a type of processing, in particular one using new technologies, is likely to result in a high risk to people’s rights. The assessment is carried out before the processing begins. The Regulation names three cases directly: a systematic and extensive evaluation of personal aspects based on automated processing, processing of special categories of data on a large scale, and systematic monitoring of a publicly accessible area on a large scale. In addition, the supervisory authority draws up its own list of cases in which an assessment is mandatory.

    Which processing operations always require a DPIA in Lithuania?

    The VDAI has approved a ten-item list. It includes processing of biometric data for monitoring or control purposes, processing of genetic data to evaluate a person’s characteristics, certain cases of video surveillance, recording of telephone calls, processing of children’s data for direct marketing, and employee monitoring. Importantly, the order itself states that the list is not exhaustive: an operation that is not on it may still require an assessment under the general criterion in Article 35 of the GDPR.

    Does video surveillance require a DPIA?

    Not always, but very often. The VDAI list names video surveillance in three cases: where the premises or areas monitored are not controlled by the controller; where monitoring takes place in healthcare, social care, custodial or other institutions providing services to vulnerable persons; and where images are recorded together with sound. Employee monitoring is listed separately.

    Does employee monitoring require a DPIA?

    Yes. It is a separate item on the VDAI list, and a broad one: it covers processing of video and audio data at the workplace and in premises or areas where employees work, as well as processing of data relating to the monitoring of employees’ communications, behaviour, location or movement. This includes GPS tracking, access control with facial recognition, breathalysers that capture images, and tools for monitoring work computers.

    Who must carry out the DPIA: the controller or the processor?

    The obligation lies with the controller. The processor can, and often must, contribute by providing a description of the system, its security measures and a list of its sub-processors, but the obligation to carry out the assessment remains with the controller. An assessment already carried out by a supplier does not replace your obligation, because the supplier assessed its own processing context, not yours; it can be used as input material.

    Must the data protection officer be involved in the DPIA?

    Yes, if a DPO has been designated. The Regulation requires the controller to seek the DPO’s advice. The DPO’s task is to provide advice on the assessment where requested and to monitor its performance. If there is no DPO and one is not required, the assessment can be carried out without one, but it is worth recording in the DPIA report itself whether a consultation took place or not.

    What if a high risk remains after the DPIA?

    In that case, the supervisory authority must be consulted in advance (prior consultation) before the processing begins. If the authority considers that the intended processing would infringe the Regulation, it provides written advice within eight weeks of receiving the request at the latest; this period may be extended by a further six weeks, taking into account the complexity of the processing. A residual high risk is therefore a question of timing as well as a legal one.

    How does a DPIA work, and what must the organisation provide?

    First, a free consultation on whether an assessment is needed at all. Then a dedicated questionnaire is prepared, which the organisation completes, and any missing information is clarified orally. The information collected is assessed in the data protection context and a DPIA report is prepared. From the organisation we need a description of its activities and an explanation of its systems and data flows; for video surveillance, camera layout plans, fields of view and descriptions of the areas monitored.

    Do the assessors need to visit our premises?

    Usually not. The plans and descriptions you provide are enough: camera layout, fields of view, areas monitored, systems and data flows. If the site is unusual or too many questions remain open, a site visit can help, but it is not a precondition of the assessment.

    What is the outcome of a DPIA?

    The outcome is a DPIA report. It describes the envisaged processing operations and their purposes, assesses their necessity and proportionality, assesses the risks to people’s rights and sets out the measures to address those risks. If the risk cannot be reduced, the report recommends prior consultation with the supervisory authority.

    Can one DPIA cover several similar processing operations?

    Yes. The Regulation allows this expressly: a single assessment may address a set of similar processing operations that present similar high risks. In practice, operations are grouped by risk level. For example, several cameras of the same type in one area are assessed together, while a biometric system is assessed separately, because the nature of its risk is different.

    Must the DPIA be repeated when a system or process changes?

    The Regulation requires a review, where necessary, of whether the processing is carried out in accordance with the assessment, at least when there is a change in the risk posed by the processing operations. Practical signals: a new feature, new cameras, a new supplier, a different volume of data or a different group of data subjects. If the risk has not changed, there is no need to repeat the whole assessment; it is enough to record the review.

    Must the DPIA be submitted to the supervisory authority?

    Not as a matter of course. The assessment is an internal document and evidence of accountability. It is submitted to the authority in two cases: when prior consultation is sought because a high risk remains, and when the authority requests it during an inspection. The assessment must therefore be kept available and up to date, not simply carried out once.

    We record telephone calls. Do we need an assessment?

    Recording telephone calls is a separate item on the list of processing operations that require an assessment, so almost always yes.

    We are already processing the data without an assessment. What should we do?

    Carry it out now. The findings of the assessment may require you to change something that is already running, so putting it off raises the cost rather than lowering it.

    Can we carry out the assessment ourselves?

    Yes. It is the controller’s obligation, not something only a lawyer may do. In practice the difference usually shows in the proportionality assessment and in the decision on whether you need to consult the Inspectorate.