Skip to main content

Finepost · Notes · Law

data protection impact assessment

noun · Datenschutz-Folgenabschätzung

The data protection impact assessment is the Datenschutz-Folgenabschätzung of Art. 35 DSGVO, DSFA for the English DPIA: the prior assessment owed where processing is likely to result in a high risk for rights and freedoms. Word-for-word inventions like Datenschutz-Auswirkungsbeurteilung miss the fixed term and detach the text from the threshold, the blacklists and the prior-consultation mechanics.

Which translation, when

Begriff und Schwellethe trigger: Art. 35 Abs. 1 DSGVO requires the assessment vorab wherever a form of processing, in particular using new technologies, is likely by its nature, scope, context and purposes to result in a high risk for the rights and freedoms of natural persons; one assessment may cover several similar operations with similarly high risks, and the advice of the Datenschutzbeauftragte is to be sought where one is appointed, Abs. 2; the German term is fixed, DSFA answers the English DPIA.
Pflichtfälle und Listenthe catalogue: Abs. 3 names the standard cases, systematic and extensive evaluation of personal aspects based on automated processing including profiling as a basis for decisions with legal or similarly significant effect, large-scale processing of special categories under Art. 9 or of criminal-conviction data under Art. 10, and systematic large-scale monitoring of publicly accessible areas; the supervisory authority must adopt and publish a list of operations for which the assessment is mandatory, Abs. 4, and Abs. 7 fixes the minimum content, from the systematic description to the remedies planned.
vorherige Konsultationthe escalation: where the assessment shows that the processing would still leave a high risk despite the mitigating measures, the controller must consult the Aufsichtsbehörde before processing, Art. 36 DSGVO; the assessment is the filter, the consultation the valve, and a translation collapsing the two stages blurs a sequence the regulation keeps apart.

Why

The data protection impact assessment translates as Datenschutz-Folgenabschätzung, and the term is fixed: German practice writes DSFA where English writes DPIA, and the pair is worth keeping because the German word carries the mechanics of Art. 35 DSGVO with it. The duty is triggered by a threshold, not a list of technologies: wherever a form of processing, especially with new technologies, is likely by its nature, scope, context and purposes to result in a high risk for the rights and freedoms of natural persons, the controller must assess the consequences in advance, one assessment sufficing for several similar operations, the advice of the data protection officer to be sought where one exists. Abs. 3 turns the threshold into standard cases, systematic and extensive evaluation of personal aspects including profiling as a decision basis, large-scale processing of Art.-9 or Art.-10 data, systematic large-scale monitoring of public areas, and Abs. 4 obliges the supervisory authority to adopt and publish a mandatory list, so whether a project needs a DSFA is answered by threshold, catalogue and blacklist together. The output is regulated too: Abs. 7 fixes the minimum content, description, necessity and proportionality, risk assessment, remedies. And the assessment has a sequel: where high risk remains despite the planned measures, Art. 36 DSGVO demands prior consultation of the Aufsichtsbehörde before the processing starts. Translation mistakes cluster at the term itself, machine variants like Datenschutz-Auswirkungsbeurteilung or Folgenabschätzung zum Datenschutz look plausible and belong to no statute, and at the stages, collapsing assessment and consultation into one event. So the safe rendering is Datenschutz-Folgenabschätzung, threshold and catalogue kept distinct, and the Art.-36 valve mentioned where the source escalates.

Typical mistakes

  • Datenschutz-Auswirkungsbeurteilung and similar word-for-word variants belong to no statute, the fixed term is Datenschutz-Folgenabschätzung.
  • The duty hangs on the likely-high-risk threshold together with the Abs.-3 catalogue and the published mandatory lists, so reading it as a duty for all processing overstates Art. 35 DSGVO.
  • Assessment and prior consultation are two stages, so a text that sends every DSFA to the Aufsichtsbehörde confuses the filter with the Art.-36 valve for remaining high risk.

What matters

A compliance memo on a new analytics or monitoring project: the translation should say Datenschutz-Folgenabschätzung, test the likely-high-risk threshold against the Abs.-3 cases and the published lists, and reserve the walk to the Aufsichtsbehörde for the remaining-risk case of Art. 36 DSGVO.

Authority

  1. Art. 35 DSGVO
  2. Art. 36 DSGVO

What the machine misses

The machine turns data protection impact assessment into word-for-word variants, Datenschutz-Auswirkungsbeurteilung or Folgenabschätzung zum Datenschutz, that belong to no statute; the fixed term is Datenschutz-Folgenabschätzung, Art. 35 DSGVO, and a text that misses it detaches the document from the high-risk threshold, the published mandatory lists and the prior-consultation valve of Art. 36 that the term carries.

See what the machine does with this clause →

Examples

to carry out a data protection impact assessmenteine Datenschutz-Folgenabschätzung durchführen
likely to result in a high riskvoraussichtlich ein hohes Risiko zur Folge
prior consultation of the supervisory authorityvorherige Konsultation der Aufsichtsbehörde
measures envisaged to address the riskszur Bewältigung der Risiken geplante Maßnahmen
Checked 30 Jul 2026 finepost.co.uk/notes/data-protection-impact-assessment