Ir al contenido
Launch offerOnly until … — after that, prices go back to normal.See pricing

Data protection

Impact assessment (EIPD/AIPD): when you need one and how to tell

Author: Tranquilia by GRAC SA4 min read

General information about the law. It’s no substitute for a lawyer’s advice or a look at your specific case.

Direct answer: the data protection impact assessment (EIPD, also called AIPD or DPIA) is a prior analysis you have to carry out before starting a processing operation that may involve a high risk to people. It is required by article 35 of Reglamento (UE) 2016/679 (RGPD, the EU's general data protection regulation). It is not needed for everything: only for high-risk processing, such as the large-scale use of health data or large-scale video surveillance. Tranquilia detects in the questionnaire whether your case needs one and, if so, prepares it for you.

Contents

What is an impact assessment?

It is an analysis you carry out before setting a risky processing operation in motion, to see what can go wrong and how to avoid it. Think of it as the survey done before building work: you look at where the dangers are before you start, not after someone falls.

In RGPD terms, you describe the processing, you assess whether it is necessary and proportionate, you identify the risks to people and you decide which measures reduce them.

When is it obligatory?

Art. 35 RGPD requires it when a processing operation "is likely to result in a high risk" to people's rights. The article itself points to three clear cases:

  • Profiling or automated decisions that significantly affect someone.
  • Large-scale processing of special categories of data (health, ideology, biometrics).
  • Systematic monitoring of a public area on a large scale (for example, intensive video surveillance).

In addition, the AEPD publishes a list of types of processing that require an EIPD. If your case matches several risk criteria at once, it is an almost certain sign that you have to do one.

When is it NOT needed?

For most of an SME's ordinary processing (your customer list, payroll management, sending invoices), an EIPD is not needed. The AEPD also publishes a list of processing operations that do not require one. It is not about doing one for every single thing: it is about recognising the few high-risk cases and handling them with care.

What risk do you run if you skip it?

If you set a high-risk processing operation in motion without the EIPD, you are in breach of art. 35 RGPD. The AEPD (Agencia Española de Protección de Datos, Spain's data protection authority) can impose a penalty for it. The RGPD sets the maximums at two levels: up to 10 million euros or 2% of turnover, and up to 20 million or 4%, depending on the infringement (art. 83 RGPD); the higher figure applies.

In practice, for an SME the problem is not usually the maximum fine, but having set up — for example — a camera system or a biometric control system without having thought about the risks first, and having to dismantle or redo it when a complaint arrives.

How Tranquilia solves it

You do not have to guess whether your case needs an EIPD. The questionnaire includes the questions that trigger the risk criteria of art. 35, and if your processing meets them, it warns you and leaves the assessment ready for you to review. If it is not needed, it does not force you to do paperwork that does not apply to you.

Frequently asked questions

Does an ordinary shop need an impact assessment?

Almost never. Selling products and keeping a customer list is not high-risk processing. The EIPD is reserved for cases such as large-scale health data, intensive profiling or systematic surveillance.

Is the EIPD sent to the AEPD?

Only in one case: if after doing it there is still a high risk that you cannot reduce, you have to consult the AEPD before starting (art. 36 RGPD). In all other cases you keep it yourself as proof that you did it.

Who signs it?

It is signed by the controller (your company). If you have a data protection officer, they must take part and give their opinion, but the decision and the responsibility belong to the company.

Official sources


General information on legislation. It does not replace the advice of a lawyer or the analysis of your specific case. If you have any doubts, consult your gestoría or a legal professional.

Review: Translation of the Spanish original, which prevails in case of divergence.

Get your clients GDPR-compliant in 15 minutes.

Set up my free instance

No card, no sales calls. Two companies free, for as long as you like.

Blog