DPIA
Data Protection Impact Assessment.
Data Protection Impact Assessment for new projects, AI systems, sensitive data processing, third-party data sharing and systematic monitoring. Methodology per Amendment 13, Israeli Privacy Authority opinions, and GDPR Article 35. Deliverable: a written DPIA report, risk matrix, prioritized mitigations, and a decision on Authority consultation. See our in-depth DPIA guide for the underlying methodology.
Six situations that call for a DPIA
AI for automated decisions
A system that makes decisions about people: candidate screening, credit approval, risk scoring, profiling. The PPA explicitly recommends a DPIA here; under GDPR it is mandatory.
Sensitive data at scale
Medical data, data on minors, intimate surveys, location data, sexuality, religion. Exactly the cases where the PPA recommends a DPIA as a risk-management tool.
Systematic monitoring of public space
City CCTV, sensors, customer behavior analysis, employee monitoring. Touches Privacy by Design principles.
Data sharing with third party
Database transfer to a new vendor, integration with external system, sharing customer records with a business partner, cross-border transfer.
New employee-facing system
Productivity monitoring, employee health system, new payroll system, biometric security system.
M&A and exit
When data transfers between entities — DPIA finds privacy risks not considered in the deal.
Six steps from kick-off to report
Scope definition
A 90-minute kick-off with project lead, IT, legal. What is the system? What is the data flow? Who are the users? What is the business risk?
Data and processing map
What data is collected? Why? From where? To where? Legal basis? Retention? Data subjects? Third parties?
Risk matrix
For each data flow — what can go wrong? At what probability and severity? Result: a visual matrix.
Mitigations
For each risk — controls that reduce it? Privacy by Design (Pseudonymization, Minimization, local storage, role-based access).
Authority consultation
If residual risk is still high — consulting the Israeli Privacy Authority before processing begins is the recommended practice (and a GDPR Article 36 duty where GDPR applies). We manage the process.
Final DPIA report
Written document (20-40 pages), matrices, decisions, mitigation plan, update date. Signed by the database owner and DPO.
DPIA for AI — what's different
Sector-specific DPIA delivery: DPO for healthcare (clinics, labs, medical SaaS) and DPO for SaaS (AI features, US/EU customers).
Explainability
How does the system make decisions? Can a data subject request an explanation? Is there a right of appeal?
Bias
Is the model trained on representative data? Unfair results for specific groups? How is it measured?
Minimization in models
Is all input data necessary? Can synthetic or pseudonymized data be used?
Data transfer to foundation models
OpenAI, Claude, Gemini, others — where is data processed? Is there a Data Processing Addendum? Is the data used for training?
Human in the loop
Does every automated decision pass human review? If not — a special legal basis is required under Amendment 13.
Prompt and log retention
Prompts contain personal data — how are they stored? For how long? Who has access?
Frequent questions about DPIA
When do you need a DPIA?
How long does a DPIA take?
What is the difference between DPIA and PIA?
Do you have a template?
What if Authority consultation is required?
How much does it cost?
Got a project that needs DPIA?
30-minute call, quote within 48 hours, kick-off within two weeks.
Discuss a project