Privacy risk assessment

Data Protection Impact
Assessment Procedure.

Pintop uses Data Protection Impact Assessments to identify, understand and reduce privacy risks connected to products, technologies, integrations and processing activities that may have a significant effect on individuals.

Lower risk
Medium risk
High risk
Identify
Assess
Mitigate

Assess privacy risk before it becomes part of the system.

A DPIA is a structured assessment used to understand how a proposed or changing processing activity may affect individuals.

It examines the purpose and necessity of the activity, the personal data involved, how information moves through the system, the risks created and the controls available to reduce those risks.

DPIA screening should take place early enough for the findings to influence product design, architecture, contractual arrangements, integrations and operational processes.

Activities that may require
closer assessment.

A DPIA may be appropriate where the scale, sensitivity, technology, monitoring or context of processing creates an elevated risk to affected individuals.

Large-scale processing

Processing involving a substantial quantity of personal data, a large population or extensive geographic coverage.

Profiling and automated decisions

Systematic evaluation, profiling or automated decision-making that may significantly affect an individual.

Sensitive personal data

Processing involving biometric, health, identity, financial or other information requiring heightened protection.

New or unfamiliar technology

Artificial intelligence, facial recognition, novel tracking or other technologies whose privacy effects are not yet well understood.

Vulnerable individuals

Processing involving children, employees or individuals whose relationship may limit their ability to exercise a free choice.

Systematic monitoring

Continuous or structured observation of behaviour, locations, devices or publicly accessible areas.

Dataset matching

Combining information from separate sources in a way that may create new insights, profiles or unexpected uses.

Other elevated risks

A DPIA may also be required where the context, novelty or potential effect of an activity creates a material privacy concern.

Initial screening

Every relevant project begins with the right questions.

Screening helps determine whether a full assessment is needed and identifies the information required to begin the review.

Purpose
What outcome is the project or processing activity intended to achieve?
People affected
Which individuals are involved and could any of them be particularly vulnerable?
Personal data
Which categories of information are collected, created, inferred, shared or retained?
Data flow
Where does information come from, where does it go and which systems or providers are involved?
Potential impact
What could happen to an individual if the processing is inaccurate, misused, disclosed or unavailable?

The assessment from
screening to outcome.

A DPIA follows a structured pathway so that decisions, risks, mitigations and responsibilities remain traceable.

01

Screen the activity

Review the proposed processing, relevant risk indicators and whether a full assessment is required.

02

Describe the processing

Document the purpose, scope, context, data categories, affected individuals, systems, recipients, providers, retention and lawful basis.

03

Assess necessity and proportionality

Consider whether the activity is necessary, whether a less intrusive approach exists and whether the data, access and retention are appropriately limited.

04

Identify risks

Examine risks to confidentiality, integrity, availability, autonomy, fairness, reputation, financial wellbeing and other interests of affected individuals.

05

Define mitigations

Identify technical, organisational and procedural measures capable of reducing each risk and reassess the residual risk after those measures.

06

Review and approve

Relevant product, engineering, business and data-protection stakeholders review the findings and confirm the actions required before processing begins.

07

Record and monitor

Record the outcome, assigned actions, residual risk and review conditions so the assessment can be revisited when the processing changes.

Risk assessment

Risk reflects both likelihood and impact.

Each identified risk is evaluated by considering how likely the event is and the seriousness of the possible effect on an individual.

Factor one
Likelihood
×
Factor two
Impact
=
Assessment
Risk level
Lower risk

Manage through standard controls

Existing safeguards may be sufficient, subject to confirming implementation and ownership.

Medium risk

Additional controls required

Specific actions should be implemented and tracked before or during deployment.

High risk

Escalation and further review

Processing should not proceed without appropriate escalation, documented decision and any further action required for the residual risk.

Risk reduction requires more than
one type of control.

Mitigations may combine technical safeguards, operational responsibilities and documented procedures.

Technical controls

Encryption, access controls, environment separation, pseudonymisation, logging, monitoring, secure deletion and other safeguards implemented through technology.

Organisational controls

Defined ownership, confidentiality commitments, training, supplier governance, access approval and management oversight.

Procedural controls

Review points, approval steps, audit trails, incident routes, retention schedules, testing and recurring reassessment.

The assessment is a
shared responsibility.

The quality of a DPIA depends on contributions from the people who understand the business purpose, architecture, implementation and privacy risk.

Project or product owner

Explains the business objective, provides project information, identifies stakeholders and coordinates implementation of agreed actions.

Data Protection Officer

Reviews screening, advises on the assessment, supports risk evaluation and confirms the privacy issues that require resolution or escalation.

Engineering and technical teams

Explain architecture and data flows, assess technical feasibility and implement relevant security and privacy controls.

Business and operational teams

Provide process context, contractual information, service-provider details and operational safeguards relevant to the activity.

Appropriate approvers

Review the residual risk, confirm ownership of required actions and decide whether the activity may proceed.

Assessment record

The outcome should remain understandable after the project launches.

The completed assessment should preserve the context, decisions, controls, responsibilities and review conditions connected to the processing activity.

Processing and project description
Data-flow and system information
Necessity and proportionality analysis
Identified risks and ratings
Mitigation measures and residual risk
Decisions, action owners and review conditions
Review and consultation

An assessment is revisited when the processing changes.

A DPIA should remain connected to the actual processing activity. Material changes, incidents or new information may require the assessment to be reviewed.

Material processing change
Reassess where purpose, scale, data, technology, integrations, hosting or recipients change significantly.
Related incident or control failure
Review the assessment where an incident reveals a risk or control weakness not previously understood.
Legal or regulatory change
Update the assessment where applicable requirements or authoritative guidance changes.
Unresolved high residual risk
Where significant residual risk cannot be reduced appropriately, further consultation and escalation may be required before processing begins.
Privacy assessment enquiries

Need information about Pintop’s DPIA approach?

Share the relevant product, implementation, integration or processing activity so the enquiry can be directed to the appropriate privacy or technical team.