When should an DPIA be done?
The controller must perform the DPIA when processing is likely to pose a high risk to the rights and freedoms of individuals.
This is particularly the case when new technologies are used and/or when the processing is particularly extensive.
When deciding whether to carry out an DPIA, consideration should also be given to the nature, scope, context and purpose of the processing.
The Data Protection Authority has issued a list of types of processing where the DPIA is mandatory before the processing begins. It is available here.
When processing is not included in the registry, it is the responsibility of the controller to assess in each case whether the processing requires an DPIA.