Key takeaway
A DPIA decision concerns the proposed processing and its effects on people. Small samples, encryption and an internal readiness score do not settle it.
Screen the operation before granting access
A sponsor can know the archive's fields and still misunderstand the operation a recipient intends to perform. Reading maintenance notes to improve a generic fault taxonomy differs from combining those notes with worker profiles to score individual performance. For a privacy assessment, describe the purpose, affected people, joins, outputs and decisions that could follow.
The final WP248 rev.01 guidance treats a DPIA as a pre-processing assessment where likely high risk to people is involved. Its screening criteria include evaluation, monitoring, matching and vulnerable people. Two criteria often indicate a need, but this is not a rule that one criterion is safe. CNIL's current explanation likewise links the obligation to likely high-risk processing.
Screening is not the DPIA itself. Its useful result is a reasoned decision to assess, a documented reason for another conclusion, or a hold because the facts are incomplete. Check relevant national authority requirements and current legal advice rather than treating a generic matrix as a complete legal test.
Worked example: a technician-scoring proposal
In this hypothetical EU project, a recipient proposes joining service narratives with workforce profiles to rank technicians for scheduling priority. The original archive supports service administration. The new evaluation would generate person-level rankings, including records where the outcome and responsible technician are disputed. The sponsor completes the following screening before releasing real records.
The sample contains only a limited period, but the proposed operation includes a new link to workforce profiles and a consequential use of its output. Reducing the number of rows does not answer the problem of someone receiving a low score from ambiguous evidence. The completed decision is to undertake a DPIA and keep real access on hold while the design is examined.
| Screening question | Hypothetical fact recorded | Decision consequence |
|---|---|---|
| Evaluation or scoring? | Person-level technician ranking influences scheduling priority | Material risk-to-people concern |
| Matching different sources? | Service archive joined with workforce profiles | Assess the new linkage and purpose |
| Vulnerable people or power imbalance? | Workers cannot freely control the employer's scheduling decision | Assess employment context and consequences |
| Necessity of identifiable rows? | Generic fault taxonomy can be tested without worker identity | Prepare a narrower alternative |
| Current evidence complete? | Disputed technician attribution and unresolved appeal path | Hold real-data access; investigate before assessment conclusion |
Describe harm in terms a decision maker can act on
The hypothetical sponsor's first risk entry says data breach. The review expands it into distinct scenarios. A misattributed job lowers the wrong person's ranking. A record about leave or health is inferred from free text. A supervisor treats an experimental score as an established performance measure. The affected person cannot see or contest the source record.
Each scenario names the pathway to harm. For misattribution, the pathway includes the join key, ambiguous shared jobs, scoring transformation and scheduling interface. For inappropriate inference, it includes free-text ingestion and output categories. This prevents the team from treating access control as the only relevant safeguard.
Work through necessity before discussing a sophisticated mitigation. The sponsor records that the generic taxonomy question needs event sequences and fault descriptions, while individual ranking adds a separate purpose. Removing worker identifiers does not establish anonymity if the recipient can relink jobs through other records. The alternative must be assessed on its actual design.
Complete the residual-risk action record
In the hypothetical action record, the product owner removes scheduling integration from the proposed taxonomy test. The data lead excludes workforce-profile joins and marks shared-job attribution as unresolved. The privacy lead asks whether the remaining narratives still permit person-level inference. The sponsor assigns a release decision only after the redesigned processing and residual risks have been assessed.
The final guidance describes necessity/proportionality, risks and envisaged measures as assessment components. It also identifies prior consultation where remaining high risk cannot be adequately reduced. A sponsor's commercial enthusiasm cannot replace that process.
The completed record below tracks what would change the decision. Due dates are project choices rather than statutory deadlines. Evidence means an inspected design or result, not a checkbox stating that the person has been informed.
| Risk and action | Owner and evidence needed | Current hypothetical position |
|---|---|---|
| Scores affect scheduling | Product owner: inspect removed integration and output routes | Original scoring evaluation held |
| Incorrect worker attribution | Data lead: review shared-job linkage and disputed examples | Individual-score use excluded from redesign |
| Free text supports sensitive inference | Privacy lead: inspect selected text and plausible recipient linkage | Unresolved; no release authorization |
| Residual risk remains high | Controller sponsor with privacy advice: complete risk assessment and any required consultation | No access until the relevant process is resolved |
Keep the assessment attached to the design
The hypothetical result is a hold on the ranking proposal and a redesigned taxonomy proposal for further assessment. It is not a certification that the narrower package is lawful or anonymous. A new recipient, new join or revived scheduling output would reopen the relevant decision. Record those change triggers beside the assessment so delivery staff can recognize them.
Use readiness to find missing preparation facts and due diligence to ask about the recipient's actual operation. Neither tool returns a legal DPIA verdict. The review record should contain the processing description, alternatives considered, people affected, advice received and the sponsor's reasoned next action.
VOID can coordinate a permitted metadata introduction while these questions are being worked through. A named recipient's interest supplies no authority to process real records. The business decision at this stage is whether to fund and complete the assessment, narrow the purpose, or stop a proposal whose risks cannot be justified.
Use this review agenda with your legal and privacy advisers. Requirements depend on the records, jurisdictions and intended use.