Data protection impact assessment (DPIA)
A data protection impact assessment is a special instrument for describing, evaluating and mitigating risks to the rights and freedoms of natural persons in connection with the processing of personal data. It must be carried out if the form of processing, in particular when using new technologies, is likely to result in a high risk due to the nature, scope, circumstances and purposes of the processing. In particular, it deals with corrective measures to ensure the protection of personal data and to demonstrate compliance with the regulation.
verinice supports you in carrying out a data protection impact assessment.
Create new DPIA
In verinice, the data protection impact assessment is a subtype of the target object process and can be created with the Data protection impact assessment form using the two tried and tested methods - dashboard and/or main menu. In addition, there is the special feature that a DPIA can be created when the associated processing activity is recorded via the section Notifications > Create DPIA. However, this message only appears if the automated decision support comes to the conclusion that a DPIA is required but has not yet been carried out.

In this case, the new DPIA is automatically listed as part of the associated processing activity.

Form contents DSFA
With the Data Protection Impact Assessment form, you can document the formal requirements in a verifiable manner. In addition, an independent risk analysis and risk treatment can also be carried out for the DPIA. Details on this can be found in the chapter Risk analysis and risk treatment.