Take-Aways (AI)
  • DPI­As are man­da­to­ry in some cases and ser­ve to assess data pro­tec­tion risks for data sub­jects and to pro­tect the company.
  • Legal requi­re­ments for imple­men­ta­ti­on are scar­ce; focus is on risk assess­ment, taking into account the risk miti­ga­ti­on mea­su­res taken.
  • Various tem­pla­tes (e.g. Wal­der Wyss Excel form, VUD tem­p­la­te with ChatGPT inter­face) are available in Ger­man and English.

Data pro­tec­tion impact assess­ments (DPI­As) are a some­ti­mes man­da­to­ry and usual­ly hel­pful tool for deal­ing with data pro­tec­tion risks for data sub­jects (and indi­rect­ly also for the com­pa­ny). The law pro­vi­des litt­le gui­dance on how the DSFA is to be con­duc­ted. Howe­ver, it is a mat­ter of Risk assess­ment for affec­ted per­sons under Con­side­ra­ti­on of the mea­su­restaken to redu­ce the risk.

You can repre­sent this in dif­fe­rent ways, and the­re are also various tem­pla­tes. We – Wal­der Wyss – For this pur­po­se, we often work with an Excel-based docu­ment, which we can down­load under Down­loads in an updated ver­si­on in Ger­man and Eng­lish for gene­ral use.

Direct links:

We are gra­teful for feed­back from the prac­ti­ce (or academy)!

Within the frame­work of the Asso­cia­ti­on enter­pri­se data pro­tec­tion (VUD), David Rosen­thal, after a test run within the VUD, has in turn pre­pared a tem­p­la­te for a DSFA that takes a slight­ly dif­fe­rent approach – more in pro­ce­du­re than in result – and which also has a ChatGPT inter­face has. It is available at www.vud.ch/dsfa and rosenthal.ch.