How to Create a Data Protection Impact Assessment (DPIA) in Accordance withCNIL (National Commission for Information Technology and Civil Liberties) Recommendations

AIPD: The Complete Guide to Conducting Your Impact Assessment in Accordance with the CNIL (National Commission for Information Technology and Civil Liberties)

Article Summary: The Data Protection Impact Assessment (DPIA ) is a requirement under Article 35 of GDPR. It is mandatory whenever processing is likely to result in a high risk to the rights and freedoms of data subjects. The CNIL (National Commission for Information Technology and Civil Liberties) established nine criteria: if your processing activity meets at least two of them, a DPIA is required. In the event of non-compliance, the fine can reach up to €10 million or 2% of global annual turnover. Dipeeo handles your DPIA through a outsourced DPO and an intuitive platform.

1. What is a PIPD? A clear definition and GDPR implications

AIPD stands for Data Protection Impact Assessment. It is an assessment conducted before initiating the processing of personal data to evaluate its impact on privacy. The CNIL (National Commission for Information Technology and Civil Liberties) defines CNIL (National Commission for Information Technology and Civil Liberties) as a tool that helps ensure data processing complies with GDPR respects the rights of data subjects. It is therefore a way to demonstrate that you have the risks under control.

2. Does this apply to your business? The CNIL (National Commission for Information Technology and Civil Liberties) criteria CNIL (National Commission for Information Technology and Civil Liberties) trigger a data breach notification

Not all companies are required to conduct a data protection impact assessment (DPIA). The requirement applies when the processing is likely to result in a high risk. The CNIL (National Commission for Information Technology and Civil Liberties) laid out the guidelines with an official list and a framework of nine criteria.

2.1 The “high-risk” criterion: what the CNIL (National Commission for Information Technology and Civil Liberties) really CNIL (National Commission for Information Technology and Civil Liberties) by this

“High risk” is determined by the nature and scope of the processing.Article 35 lists three cases in which the law presumes in advance that the risk is high:

  • The systematic assessment of personal factors
  • Systematic, large-scale surveillance of a public area
  • The large-scale processing of sensitive or criminal data.

This list is not exhaustive, which leaves room for some delicate interpretation.

2.2 Processing operations that automatically require an AIPD (official list from CNIL (National Commission for Information Technology and Civil Liberties))

The CNIL (National Commission for Information Technology and Civil Liberties) published a positive list of fourteen types of operations for which an analysis is required. For example.

  • Leak detection through analysis of outgoing emails
  • Video surveillance of employees handling cash
  • The processing of health data by a healthcare facility…

If your project is included on this list, the matter is closed. This list is the result of Resolution No. 2018-327 of October 11, 2018. Correspondingly, a negative list was adopted by Resolution No. 2019-118 of September 12, 2019, following consultation with the European Data Protection Board.

An AIPD is also not required when the processing is carried out to comply with a legal obligation that is already governed by a regulation that has been reviewed.

2.3 Borderline cases: when the CNIL (National Commission for Information Technology and Civil Liberties) without requiring compliance

There is a gray area between mandatory and optional processing. When the processing is not included on any list, the CNIL (National Commission for Information Technology and Civil Liberties) to the nine criteria set forth in the G29 guidelines, which have been adopted by the EDPB. As soon as at least two of these criteria are met, an analysis becomes mandatory. Here are the different situations:

  • assessment or scoring, including profiling;
  • automated decision-making with legal or similar effects;
  • systematic monitoring;
  • collection of sensitive or highly personal data;
  • large-scale data collection;
  • data matching;
  • vulnerable individuals (patients, children, the elderly);
  • innovative use or new technology;
  • forfeiture of a right or contract.

Even if only one criterion is met, the CNIL (National Commission for Information Technology and Civil Liberties) conducting a data protection impact assessment (DPIA) as a precaution. This process helps ensure your compliance, regardless of the actual risk. When in doubt, the assessment protects you.

GDPR EXTERNAL DPO

3. What must a compliant AIPD include? The 4 mandatory elements under the GDPR

Article 35(7) of GDPR the minimum requirements for a compliant data protection impact assessment (DPIA). It consists of four key elements. Failing to address these elements results in an assessment that cannot be relied upon during an audit.

Required fieldNatureKey question
Description of the treatmentTechnical and operationalWhat are you doing, with what data, and for what purpose?
Necessity and proportionalityLegalIs this treatment justified and appropriate?
Risk AnalysisTechnical (safety)What are the risks to people, and how serious are they?
Reduction measuresTechnical and organizationalHow can we reduce the risk to an acceptable level?

3.1 Detailed description of the processing and its purposes

This section should describe the data processing activities, the parties involved, data flows, data categories, recipients, Data retention periods Data retention any Data retention transfers. The more detailed the description, the more robust the analysis becomes.

3.2 Assessment of Necessity and Proportionality

Next comes a more legal assessment. Is the processing necessary for its Purpose Is the data collection proportionate? This section verifies the fundamental, non-negotiable principles: lawfulness, data minimization, limited retention period, information, and the rights of data subjects.

3.3 Risk analysis: severity and likelihood for those affected

The third section, which focuses on technical aspects, examines data security risks: confidentiality, integrity, and availability. For each potential incident, you identify the threats and then rate the risk based on its severity and likelihood.

3.4 Technical and organizational risk mitigation measures

Finally, the AIPD outlines the measures being considered: encryption, access controls, pseudonymization, awareness-raising, and oversight of processors. The goal is to reduce each risk to an acceptable level and to demonstrate this.

GDPR EXTERNAL DPO

4. How to Create an AIPD Step by Step: A Detailed Breakdown of the Steps

A rigorous analysis consists of five steps.

4.1. Step 1: Describe the treatment, its context, and the people involved

You define the scope of the processing: purposes, media, and data flows. You identify the parties involved, including data controllers, processors recipients. An unclear context can skew the entire analysis.

4.2. Step 2: Assess whether the processing is necessary and proportionate

You are evaluating the processing against the fundamental principles. Is the legal basis sound? Is the data limited to what is strictly necessary? Are the data subjects informed, and are their rights respected?

4.3. Step 3: Identify and assess risks to affected individuals

This is the technical core. You assess privacy risks related to data security and ensure they are properly addressed. Each risk is rated for severity and likelihood from the perspective of individuals. This rating helps you prioritize your actions.

4.4. Step 4: Identify measures to mitigate these risks

For each risk, you must identify the appropriate technical and organizational measures. If the residual risk remains high despite these measures, you must consult with the CNIL (National Commission for Information Technology and Civil Liberties) proceeding with any deployment.

4.5. Step 5: Document, validate, and schedule the review of the AIPD

Finally, you formalize the approval of the analysis. The AIPD is not set in stone: it is developed before the processing begins and is then regularly reviewed throughout its lifecycle. Any significant changes warrant an update.

Good to know: The AIPD must be conducted before data processing begins. If carried out after the incident, it no longer serves its preventive purpose and does not remedy the breach in the eyes of the CNIL (National Commission for Information Technology and Civil Liberties).

5. What the texts really say: interpretations by CNIL (National Commission for Information Technology and Civil Liberties) and the EDPS, and points to watch out for

Just reading the texts isn’t enough—you also have to make sense of them. Between the GDPR, the EDPB guidelines, and the CNIL (National Commission for Information Technology and Civil Liberties) lists, the sources are piling up. Here’s who says what and where the pitfalls lie.

5.1. Article 35 of GDPR the EDPB Guidelines: Key Takeaways

Article 35 of the General Data Protection Regulation is the founding text of the AIPD. It establishes the obligation, sets forth the minimum requirements, and provides for prior consultation with the authority in cases of high residual risk.

The EDPS guidelines, which were adopted from the G29, define the concept of high risk and set out the nine criteria.

5.2. How to interpret the list of high-risk processing operations published by the CNIL (National Commission for Information Technology and Civil Liberties)

CNIL (National Commission for Information Technology and Civil Liberties) positive list CNIL (National Commission for Information Technology and Civil Liberties) a presumption of high risk, but should be interpreted with caution. A processing operation not included on the list may still be subject to AIPD under the nine criteria. Conversely, inclusion on the negative list does not exempt an organization from complying with the other principles of GDPR. The list serves as a guide; it does not replace a case-by-case analysis.

5.3. The 3 Most Common Mistakes Made During an AIPD (and How to Avoid Them)

  • The first mistake is to artificially downplay the risk in order to avoid consulting the CNIL (National Commission for Information Technology and Civil Liberties) a transparent strategy that backfires on the company.
  • The second issue is that the AIPD is completed too late, when production has already begun.
  • The third is to produce a document that is merely for show, without any specifications or concrete measurements. During an inspection, the absence or inadequacy of an AIPD becomes an aggravating factor.

Dipeeo Tip: Don’t confuse the AIPD with other similar assessments. Under the AI Act, a high-risk AI system may require both an AIPD and a fundamental rights impact assessment.

6. What role does the DPO play in the preparation of the AIPD?

The data controller remains legally obligated to ensure the compliance of its processing activities, but it does not act alone. When a Data Protection Officer (DPO) is appointed, the General Data Protection Regulation ( GDPR ) requires the data controller to seek the DPO’s advice and entrust the DPO with verifying compliance with the Data Protection Impact Assessment (DPIA). The DPO serves as the methodological lead for the analysis, without assuming final Accountability for it.

GDPR EXTERNAL DPO

To remember

A DPIA is the data protection impact assessment required by Article 35 of GDPR. It becomes mandatory whenever processing is likely to result in a high risk:

  • Either because it appears on the official list of the CNIL (National Commission for Information Technology and Civil Liberties)
  • Either because it meets at least two of the nine criteria set by the EDPB.

A compliant analysis consists of four elements: a description of the processing, necessity and proportionality, a risk analysis, and mitigation measures. The CNIL (National Commission for Information Technology and Civil Liberties) method CNIL (National Commission for Information Technology and Civil Liberties) of five steps, which must be completed prior to deployment and reviewed on a regular basis.

Would you like to complete your AIPD with complete peace of mind? And ensure your compliance from start to finish?
Talk to an outsourced DPO expert outsourced by filling out the form on our website

Frequently Asked Questions

Is the AIPD mandatory for all companies?

No. It applies only to processing operations that are likely to pose a high risk to the rights and freedoms of data subjects. A processing operation is covered if it appears on the official list of the CNIL (National Commission for Information Technology and Civil Liberties) it meets at least two of the nine criteria set forth by the EDPB.

How long does it take to complete an AIPD correctly?

There is no legally prescribed timeframe. The duration depends on the complexity of the processing, the volume of data, and the availability of internal staff. A simple AIPD can be completed in a few days, while complex processing may take several weeks.

Is it necessary to submit your AIPD to the CNIL (National Commission for Information Technology and Civil Liberties)

Not necessarily. There is no general requirement to publish or disclose such information. However, you must consult the CNIL (National Commission for Information Technology and Civil Liberties) the residual risk remains high despite the measures taken.

Can you conduct a data protection impact assessment (DPIA) on your own without a DPO?

Legally speaking, yes: the data controller is free to choose their own method and may conduct the analysis in-house. In practice, however, this is a demanding task, and a poorly conducted data protection impact assessment (DPIA) can create a false sense of security and backfire on the company during an audit. It is therefore advisable to seek professional assistance.

What penalties could we face for failing to provide the required AIPD?

The violation falls under Article 83(4) of GDPR. The fine may amount to up to 10 million euros or 2% of the total worldwide annual turnover of the preceding fiscal year, whichever is higher. Beyond the amount of the fine, the absence of a DPA constitutes an aggravating circumstance that increases the penalty for other violations, as demonstrated by several recent decisions by the CNIL (National Commission for Information Technology and Civil Liberties).

Dipeeo
Dipeeo