Data Protection Impact
Assessment Procedure.
Pintop uses Data Protection Impact Assessments to identify, understand and reduce privacy risks connected to products, technologies, integrations and processing activities that may have a significant effect on individuals.
Assess privacy risk before it becomes part of the system.
A DPIA is a structured assessment used to understand how a proposed or changing processing activity may affect individuals.
It examines the purpose and necessity of the activity, the personal data involved, how information moves through the system, the risks created and the controls available to reduce those risks.
DPIA screening should take place early enough for the findings to influence product design, architecture, contractual arrangements, integrations and operational processes.
Activities that may require
closer assessment.
A DPIA may be appropriate where the scale, sensitivity, technology, monitoring or context of processing creates an elevated risk to affected individuals.
Large-scale processing
Processing involving a substantial quantity of personal data, a large population or extensive geographic coverage.
Profiling and automated decisions
Systematic evaluation, profiling or automated decision-making that may significantly affect an individual.
Sensitive personal data
Processing involving biometric, health, identity, financial or other information requiring heightened protection.
New or unfamiliar technology
Artificial intelligence, facial recognition, novel tracking or other technologies whose privacy effects are not yet well understood.
Vulnerable individuals
Processing involving children, employees or individuals whose relationship may limit their ability to exercise a free choice.
Systematic monitoring
Continuous or structured observation of behaviour, locations, devices or publicly accessible areas.
Dataset matching
Combining information from separate sources in a way that may create new insights, profiles or unexpected uses.
Other elevated risks
A DPIA may also be required where the context, novelty or potential effect of an activity creates a material privacy concern.
Every relevant project begins with the right questions.
Screening helps determine whether a full assessment is needed and identifies the information required to begin the review.
The assessment from
screening to outcome.
A DPIA follows a structured pathway so that decisions, risks, mitigations and responsibilities remain traceable.
Screen the activity
Review the proposed processing, relevant risk indicators and whether a full assessment is required.
Describe the processing
Document the purpose, scope, context, data categories, affected individuals, systems, recipients, providers, retention and lawful basis.
Assess necessity and proportionality
Consider whether the activity is necessary, whether a less intrusive approach exists and whether the data, access and retention are appropriately limited.
Identify risks
Examine risks to confidentiality, integrity, availability, autonomy, fairness, reputation, financial wellbeing and other interests of affected individuals.
Define mitigations
Identify technical, organisational and procedural measures capable of reducing each risk and reassess the residual risk after those measures.
Review and approve
Relevant product, engineering, business and data-protection stakeholders review the findings and confirm the actions required before processing begins.
Record and monitor
Record the outcome, assigned actions, residual risk and review conditions so the assessment can be revisited when the processing changes.
Risk reflects both likelihood and impact.
Each identified risk is evaluated by considering how likely the event is and the seriousness of the possible effect on an individual.
Manage through standard controls
Existing safeguards may be sufficient, subject to confirming implementation and ownership.
Additional controls required
Specific actions should be implemented and tracked before or during deployment.
Escalation and further review
Processing should not proceed without appropriate escalation, documented decision and any further action required for the residual risk.
Risk reduction requires more than
one type of control.
Mitigations may combine technical safeguards, operational responsibilities and documented procedures.
Technical controls
Encryption, access controls, environment separation, pseudonymisation, logging, monitoring, secure deletion and other safeguards implemented through technology.
Organisational controls
Defined ownership, confidentiality commitments, training, supplier governance, access approval and management oversight.
Procedural controls
Review points, approval steps, audit trails, incident routes, retention schedules, testing and recurring reassessment.
The assessment is a
shared responsibility.
The quality of a DPIA depends on contributions from the people who understand the business purpose, architecture, implementation and privacy risk.
Project or product owner
Explains the business objective, provides project information, identifies stakeholders and coordinates implementation of agreed actions.
Data Protection Officer
Reviews screening, advises on the assessment, supports risk evaluation and confirms the privacy issues that require resolution or escalation.
Engineering and technical teams
Explain architecture and data flows, assess technical feasibility and implement relevant security and privacy controls.
Business and operational teams
Provide process context, contractual information, service-provider details and operational safeguards relevant to the activity.
Appropriate approvers
Review the residual risk, confirm ownership of required actions and decide whether the activity may proceed.
The outcome should remain understandable after the project launches.
The completed assessment should preserve the context, decisions, controls, responsibilities and review conditions connected to the processing activity.
An assessment is revisited when the processing changes.
A DPIA should remain connected to the actual processing activity. Material changes, incidents or new information may require the assessment to be reviewed.
Related privacy and
governance documents.
These documents provide further context about Pintop’s privacy, security, retention and incident-management framework.
Need information about Pintop’s DPIA approach?
Share the relevant product, implementation, integration or processing activity so the enquiry can be directed to the appropriate privacy or technical team.
