data protection impact assessment
noun · Datenschutz-Folgenabschätzung
The data protection impact assessment is the Datenschutz-Folgenabschätzung of Art. 35 DSGVO, DSFA for the English DPIA: the prior assessment owed where processing is likely to result in a high risk for rights and freedoms. Word-for-word inventions like Datenschutz-Auswirkungsbeurteilung miss the fixed term and detach the text from the threshold, the blacklists and the prior-consultation mechanics.
Which translation, when
Why
The data protection impact assessment translates as Datenschutz-Folgenabschätzung, and the term is fixed: German practice writes DSFA where English writes DPIA, and the pair is worth keeping because the German word carries the mechanics of Art. 35 DSGVO with it. The duty is triggered by a threshold, not a list of technologies: wherever a form of processing, especially with new technologies, is likely by its nature, scope, context and purposes to result in a high risk for the rights and freedoms of natural persons, the controller must assess the consequences in advance, one assessment sufficing for several similar operations, the advice of the data protection officer to be sought where one exists. Abs. 3 turns the threshold into standard cases, systematic and extensive evaluation of personal aspects including profiling as a decision basis, large-scale processing of Art.-9 or Art.-10 data, systematic large-scale monitoring of public areas, and Abs. 4 obliges the supervisory authority to adopt and publish a mandatory list, so whether a project needs a DSFA is answered by threshold, catalogue and blacklist together. The output is regulated too: Abs. 7 fixes the minimum content, description, necessity and proportionality, risk assessment, remedies. And the assessment has a sequel: where high risk remains despite the planned measures, Art. 36 DSGVO demands prior consultation of the Aufsichtsbehörde before the processing starts. Translation mistakes cluster at the term itself, machine variants like Datenschutz-Auswirkungsbeurteilung or Folgenabschätzung zum Datenschutz look plausible and belong to no statute, and at the stages, collapsing assessment and consultation into one event. So the safe rendering is Datenschutz-Folgenabschätzung, threshold and catalogue kept distinct, and the Art.-36 valve mentioned where the source escalates.
Typical mistakes
- Datenschutz-Auswirkungsbeurteilung and similar word-for-word variants belong to no statute, the fixed term is Datenschutz-Folgenabschätzung.
- The duty hangs on the likely-high-risk threshold together with the Abs.-3 catalogue and the published mandatory lists, so reading it as a duty for all processing overstates Art. 35 DSGVO.
- Assessment and prior consultation are two stages, so a text that sends every DSFA to the Aufsichtsbehörde confuses the filter with the Art.-36 valve for remaining high risk.
What matters
A compliance memo on a new analytics or monitoring project: the translation should say Datenschutz-Folgenabschätzung, test the likely-high-risk threshold against the Abs.-3 cases and the published lists, and reserve the walk to the Aufsichtsbehörde for the remaining-risk case of Art. 36 DSGVO.
What the machine misses
The machine turns data protection impact assessment into word-for-word variants, Datenschutz-Auswirkungsbeurteilung or Folgenabschätzung zum Datenschutz, that belong to no statute; the fixed term is Datenschutz-Folgenabschätzung, Art. 35 DSGVO, and a text that misses it detaches the document from the high-risk threshold, the published mandatory lists and the prior-consultation valve of Art. 36 that the term carries.
Examples
| to carry out a data protection impact assessment | eine Datenschutz-Folgenabschätzung durchführen |
| likely to result in a high risk | voraussichtlich ein hohes Risiko zur Folge |
| prior consultation of the supervisory authority | vorherige Konsultation der Aufsichtsbehörde |
| measures envisaged to address the risks | zur Bewältigung der Risiken geplante Maßnahmen |