DPIA Self-Screening
Find out whether your processing activity is likely to require a Data Protection Impact Assessment (DPIA). Describe what you do and see your result.
This self-screening is based on Article 35(3) GDPR, the EDPB/WP29 guidelines (WP248 rev.01) and the published criteria of the national supervisory authorities. It is not legal advice: treat your result as a starting point and, in case of doubt, involve your data protection officer or an expert data protection advisor.
Privacy by design: your answers stay in your browser and are never transmitted or stored. We only count, anonymously, that a screening was completed.
Build profiles or score people (behaviour, performance, reliability, finances)e.g. work performance, fraud detection, economic situation, health, preferences, movements
Check creditworthiness or financial reliabilitye.g. scoring whether someone is likely to repay a loan
Decide who is refused a service, contract or benefit, or who cannot exercise a righte.g. an algorithm that bars someone from opening an account or receiving a service
Keep or share warning or blacklist-type records about peoplee.g. unpaid debts, problematic employees, nuisance behaviour of tenants in social housing
Make automated decisions, with little human involvement, that may have significant consequences for peoplee.g. an app that approves or rejects a loan, job application, or claim with no human review
Employees or workplace surveillancee.g. logging or recording keystrokes, screen time, calls, or staff whereabouts
Cameras, CCTV or drones filming public arease.g. a security camera filming an entrance or car park, a dashcam, or a drone over a public street
Large-scale secret investigation or observation of peoplee.g. an insurer quietly investigating lots of claimants for suspected fraud, or a company running covert background or online checks on many job applicants or customers
Systematic secret monitoring of someonee.g. a private detective hired to follow and gather information on an employee over several weeks, or ongoing covert tracking of one customer's online activity
Handle, for large numbers of people, information that someone is legally bound to keep confidential - through their profession, their official role, or a special duty of secrecye.g. running a private insolvency register that lists many people's debt histories, a large care institution holding residents' personal records, or a big law firm dealing mainly with family-law cases such as divorces and custody disputes
Data handled through a whistleblowing systeme.g. a report submitted to a company hotline naming a manager accused of fraud, including the identities of the whistleblower and the person reported
Buy personal data from other companiese.g. buying a marketing list, or topping up your records with data from a data broker or another company
Hold personal data about people who were never told you have ite.g. receiving customer data when you take over another business and never contacting those people
Share large amounts of personal data with other organisations for them to use for their own purposese.g. handing your customer list to a partner company to use as they wish - excluding routine IT or cloud providers (email, hosting) that only handle data on your instructions
Use the personal data you already hold for a new purpose, across many peoplee.g. taking customer details you collected to handle orders and now using them to build marketing or advertising tools
Racial or ethnic backgrounde.g. recording someone's ethnicity, nationality background, or skin colour
Religious or philosophical beliefse.g. someone's faith, church membership, or philosophical convictions
Political opinionse.g. party membership, who someone votes for, political activism
Trade-union membershipe.g. whether someone belongs to a trade union
Health information, including healthcare records or registriese.g. health status, test results, diagnoses, body measurements, hospital visits
Genetic datae.g. DNA or gene-test results
Biometric data used to identify someonee.g. a fingerprint door lock, a face-recognition login, or voice-ID for phone banking
Sex life or sexual orientatione.g. whether someone is gay, straight or bisexual, their relationship details, or their sex life
Criminal records or offencese.g. a past conviction, a pending prosecution, or an official record of an offence
Precise location or movement trackinge.g. GPS tracking, continuous or precise location history
Content of private messages or callse.g. the text of emails or messages
Data about vulnerable people (children, elderly, patients, etc.)e.g. children, elderly, patients, people with disabilities, asylum seekers, social-service users, abuse victims
Data about employeesincludes trainees, working students, and any employee-adjacent relationship
New or innovative technologye.g. AI or machine learning, facial recognition, wearables, connected devices, voice assistants
Large scale: many people, or a large amount of datae.g. thousands of customers, patients, employees or users; data gathered continuously or over a long period; or covering a wide area or many sites
Personal data is sent to, or accessible from, outside the EU/EEAe.g. a provider that stores or accesses the data from outside the EU/EEA (for example in the US or India)