Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework
Abstract
1. Introduction
2. Research Methods
3. Results
3.1. Overview of Previous DPIA Studies
3.2. RQ1. What Challenges Were Encountered in Implementing the DPIA, Particularly in the Area of Technology-Based Data Processing?
3.2.1. Legal and Regulatory Challenges
3.2.2. Risk Assessment Challenges
3.2.3. Complexity of DPIA Implementation Challenges
3.2.4. Enhancing DPIA Scope Challenges
3.3. RQ2. Can a Framework Be Developed to Address the DPIA Implementation Challenges for Digital Technologies?
4. Discussion
5. Conclusions
Author Contributions
Funding
Data Availability Statement
Acknowledgments
Conflicts of Interest
Appendix A. Definitions and Summary of Included Studies
| Data Protection Authority/Organisation | Definition | Reference |
|---|---|---|
| DPIA | ||
| Irish Data Protection Commission | “DPIA describes a process designed to identify risks arising out of the processing of personal data and to minimise these risks as far and as early as possible. DPIAs are important tools for negating risk, and for demonstrating compliance with the GDPR.” | Irish Data Protection Commission [59] |
| Information Commissioner’s Office | “A DPIA is a process designed to help you systematically analyse, identify and minimise the data protection risks of a project or plan. It is a key part of your accountability obligations under the UK GDPR, and when done properly helps you assess and demonstrate how you comply with all of your data protection obligations.” | Information Commissioner’s Office [60] |
| Article 29 Data Protection Working Party | “A DPIA is a process designed to describe the processing, assess its necessity and proportionality and help manage the risks to the rights and freedoms of natural persons resulting from the processing of personal data by assessing them and determining the measures to address them.” | Article 29 Data Protection Working Party [12] |
| National Commission on Informatics and Liberty (CNIL) | “The Data Protection Impact Assessment (DPIA) is an approach that allows to map and assess the risks of a personal data processing and to establish an action plan to reduce them to an acceptable level.” | National Commission on Informatics and Liberty [61] |
| Personal Data Protection Commission Singapore | “A DPIA involves identifying, assessing and addressing personal data protection risks based on the organisation’s functions, needs and processes.” | Personal Data Protection Commission Singapore [62] |
| PIA | ||
| Office of the Privacy Commissioner of Canada | “A PIA is a risk management process that helps institutions ensure they meet legislative requirements and identify the impacts their programs and activities will have on individuals’ privacy.” | Office of the Privacy Commissioner of Canada [63] |
| International Organization for Standardization | “PIA is an instrument for:
| ISO/IEC 29134 [23] |
| Title | Author(s)/Year | Objective | Country/Region | Sector Context | Technology Focus | Methodology |
|---|---|---|---|---|---|---|
| 1. DPIAs’ Role in Fundamental Rights Governance | Moniz [37] | The study examines how DPIAs under the GDPR function as both accountability tools and decentralised governance frameworks, positioning data controllers as quasi-judicial actors who adjudicate conflicts between fundamental rights. This article aims to explain the balancing and proportionality assessments embedded in DPIAs, identify structural challenges such as subjectivity, legitimacy and inconsistency, and propose reforms to strengthen the role of DPIAs in protecting fundamental rights in the digital age. | EU | Regulatory Compliance | AI | Conceptual |
| 2. Establishing a comprehensive data protection impact assessment methodology for big data analytics in compliance with the GDPR | Georgiadis and Poels [40] | The study aims to enhance DPIA practices for big data analytics by validating nine Privacy Touch Points (PTPs) that are specific to risks arising from big data analytics processes. It also seeks to identify gaps in existing GDPR-aligned DPIA frameworks and propose methodological improvements. The study further aims to operationalize these PTPs, validated through Delphi rounds and expert interviews, into a refined DPIA framework tailored to environments where big data analytics is used. This improved framework is intended to address issues such as unclear controllership, re-identification risks, concerns of discrimination, transparency gaps and challenges related to stakeholder involvement. | EU | IT and Regulatory Compliance | Big Data Analytics | Mixed Method |
| 3. Navigating data governance risks: Facial recognition in law enforcement under EU legislation | Gültekin-Várkonyi [43] | The study examines how the use of facial recognition technologies by law enforcement agencies creates four major data governance risks under the GDPR and the AI Act: data minimization, purpose limitation, data/system accuracy, and administrative challenges. The article aims to analyse these risks from legal, technical and practical angles, and proposes expanding the DPIA process and integrating it with the risk-management requirements of the AI Act to ensure that the deployment of facial recognition technologies for public security is more legitimate and respects privacy. | EU | Regulatory Compliance | Facial Recognition Technologies | Qualitative |
| 4. Enhancing AI fairness through impact assessment in the European Union: a legal and computer science perspective | Calvi and Kotzinos [32] | To explore the potential of algorithmic impact assessments (AIA), including DPIA, to protect individuals from algorithmic harms. It examines the societal impact of AI systems and explores how AIA processes can integrate legal, social and computer science perspectives to enhance accountability, promote fairness and contribute to the development of fairer AI solutions within existing and future regulatory frameworks. | EU | IT | AI | Mixed Method |
| 5. TRUSTEE’s Framework for DPIAs: Safeguarding personal information in the Digital Era | Grammatopoulos at al. [30] | The research article aims to introduce and explore the TRUSTEE framework’s holistic approach to GDPR-compliant DPIAs, emphasising the comprehensive assessment of data processing activities and the integration of technical, user-centric, ethical, social and legal perspectives. It also outlines the implementation process within the TRUSTEE framework, emphasising its commitment to improving data protection and providing stakeholders with a robust tool for protecting personal data in the digital age. | EU | Regulatory Compliance | Self-sovereign identity, Homomorphic encryption, Blockchain technology | Qualitative |
| 6. Position Paper: The role of law in achieving privacy and security measures in smart buildings from the GDPR context | Leesakul and Morisset [34] | The symposium paper aims to explore the challenges of applying the GDPR in the context of smart buildings, focusing on the ambiguities surrounding personal data processing and data privacy management for building controllers. By identifying the key requirements for data controllers in managing data privacy in smart buildings, particularly through the conduct of DPIAs, the study seeks to address compliance issues and strike a balance between privacy protection and the benefits of smart building technologies. The article emphasises the need for empirical and interdisciplinary research to effectively address the compliance challenges posed by smart environments. | EU | Industrial Sector | Smart building technologies (sensors, IoT, pervasive computing) | Conceptual |
| 7. The Processing goes far beyond “the app”—Privacy issues of decentralised Digital Contact Tracing using the example of the German Corona-Warn-App | Rehak and Kuhne [33] | The research article aims to assess the data protection implications of contact tracing apps in response to the COVID-19 pandemic in Europe, focusing on the requirements of the GDPR and the necessity of conducting DPIAs. By utilising the Standard Data Protection Model, the study identifies weaknesses and risks in current implementations, highlighting the need for enhanced data subject rights protection and proposing solutions to address these shortcomings. | Germany | IT and Healthcare | Contact tracing | Conceptual |
| 8. Gender, data protection and the smart city: Exploring the role of DPIA in achieving equality goals | Calvi [53] | The research article aims to explore the impact of data protection law, in particular the DPIA, on the development of smart cities in the European Union, focusing on its potential to address fundamental rights challenges and empower women from diverse backgrounds. By exploring how data protection measures can mitigate the dynamics of oppression of women in smart cities, the study aims to initiate a discussion on how to enhance inclusivity and address challenges in urban environments shaped by data processing. | EU | Regulatory compliance | Digital infrastructure, sensors, IoT devices, big data analytics, and cloud computing | Conceptual |
| 9. Approaching the Data Protection Impact Assessment as a legal methodology to evaluate the degree of privacy by design achieved in technological proposals. A special reference to Identity Management systems | López et al. [39] | The research aims to propose the adaptation of the DPIA as a legal requirement to assess technology proposals, focusing on privacy by design principles, with a particular emphasis on identity management technologies. By addressing the challenges of digital identity management and emphasising the importance of considering both architectural and user aspects in technology development. | EU | IT | Digital Identity Management systems | Conceptual |
| 10. Fairness and Data Protection Impact Assessments | Kasirzadeh and Clifford [52] | The research purpose of this article is to critically evaluate the effectiveness of conducting a DPIA through the lens of fairness metrics, highlighting the theoretical importance of fairness considerations in the DPIA process and examining their practical implementation based on guidance from data protection authorities. The paper aims to assess the operationalization of fairness metrics within DPIAs, considering technical challenges, the contextual nature of fairness, and the pivotal role of data controllers in determining fairness. | EU | IT and Regulatory Compliance | Machine Learning Systems | Conceptual |
| 11. Designing a GDPR compliant blockchain-based IoV distributed information tracking system | Campanile et al. [38] | The research objective of this article is to propose a reference model for a system that uses blockchain technology to create trustworthy data logging systems for the Internet of Vehicles, addressing privacy concerns and ensuring GDPR compliance in the European Union. The study aims to demonstrate how blockchain can support GDPR-compliant solutions for tracking the chain of responsibility in the event of accidents or damage related to vehicle maintenance, ultimately improving road safety and legal accountability. In addition, the article explores the role of DPIAs in ensuring that the implementation of blockchain technology in the Internet of Vehicles domain is in line with GDPR requirements and safeguards the privacy rights of individuals. | Italy | IT | Blockchain and the Internet of Vehicles (IoV) | Mixed Method |
| 12. A Perfect Match: Converging and Automating Privacy and Security Impact Assessment On-the-Fly | Papamartzivanos et al. [35] | The research purpose of this article is to introduce the APSIA (“Automated Privacy and Security Impact Assessment”) methodology, utilising interdependency graph models and data processing flows to assess privacy risks in Information and Communication Technology infrastructures. Through a case study in the assistive healthcare domain, the study demonstrates the efficacy of APSIA in quantifying privacy impacts and enhancing security and privacy assessments in heavily regulated sectors. | Greece and Denmark | IT and Healthcare | Information and Communication Technology infrastructure | Mixed Method |
| 13. Evaluating privacy impact assessment methods: guidelines and best practice | Vemou and Karyda [47] | The research purpose of this article is to provide practical guidance for implementing PIA by proposing a PIA process that incorporates best practices from existing guidelines and privacy research. The paper critically reviews and assesses various PIA methods to identify best practices and support PIA practitioners, ultimately proposing a comprehensive PIA process and evaluation framework to enhance the support for PIA projects. This research aims to extend existing PIA guidelines by offering practical and comprehensive guidance to PIA practitioners, addressing gaps and providing practical support for organising and implementing PIA projects. | EU | IT | Information and Communication Technology systems | Qualitative |
| 14. Data Protection Impact Assessment in Identity Control Management with a Focus on Biometrics | Bisztray et al. [42] | The research purpose of this conference paper is to evaluate the efficacy of two distinct privacy impact assessment frameworks within the realm of biometric data protection, specifically in the domain of identity and access control management (IAM). By leveraging insights from the SWAN project, which employs four biometric characteristics for authentication, the study aims to assess the capability of these frameworks in pinpointing sector-specific privacy risks associated with IAM and biometric identification. The comparative analysis conducted in this research seeks to provide insights into the practical utility of these frameworks in addressing privacy concerns related to the processing of biometric data in alignment with GDPR regulations. | EU | IT | Biometric Authentication and Identity Management Systems (IDMs) | Case Study |
| 15. Privacy Regulations Challenges on Data-centric and IoT Systems: A Case Study for Smart Vehicles | Campanile et al. [50] | The research purpose of this conference paper is to address the security challenges faced by IoT systems, particularly focusing on privacy preservation in the context of sensitive user data and compliance with the GDPR. The study aims to investigate the potential of blockchain technology in enhancing the privacy and compliance of IoT systems with data protection regulations, as evidenced through a pilot study and DPIA focusing on the Internet of Vehicles (IoVs) case study. | EU | IT | IoT, Internet of Vehicles (IoV), and Blockchain Technology | Case Study |
| 16. Ethical Considerations for Movement Mapping to Identify Disease Transmission Hotspots | Jong et al. [54] | The purpose of this paper is to explore the ethical considerations surrounding the use of mobility data, specifically mobile phone call detail records (CDRs), for mapping infectious disease transmission hotspots. The study aims to address the risks and benefits of using ICT data to track the movements of infected individuals and identify potential transmission hotspots, while also developing a model DPIA template for conducting similar assessments in the future. | EU | IT and Healthcare | Information and Communication Technology (ICT) | Qualitative |
| 17. AI and Big Data: A blueprint for a human rights, social and ethical impact assessment | Mantelero [41] | The research purpose of this article is to propose a new assessment model, the Human Rights, Ethical, and Social Impact Assessment (HRESIA), that integrates human rights, ethical considerations, and societal impacts into a comprehensive evaluation framework for data-intensive technologies, including DPIA. The aim is to address the limitations of existing assessment models and provide a broader perspective on the impact of data processing on fundamental rights and collective social and ethical values. | EU | IT | AI and Big Data | Conceptual |
| 18. An Open-Source Software Tool to Facilitate Data Protection Impact Assessments | Riemann et al. [44] | The research purpose of this article is to introduce and evaluate the efficacy of the “DPIA click&go” tool, designed to simplify and streamline the DPIA process in medical research settings. The study aims to validate the tool’s performance through a real-world project, comparing its capabilities with manually created DPIAs in terms of risk coverage and mitigation strategies, highlighting its potential to harmonise data protection practices at a larger, potentially European or global scale. | Germany | IT and Healthcare | IT infrastructure, Open-Source Software | Mixed Method |
| 19. Practical fundamental rights impact assessments | Janssen et al. [36] | The research purpose of this article is to introduce a practical four-phased framework to assist organisations in performing DPIAs and fundamental rights impact assessments for their AI systems. This framework addresses the challenges of assessing risks related to fundamental rights and data protection, ensuring compliance with the GDPR, and mitigating potential infringements on fundamental rights in AI systems to maintain public trust and address societal consequences. | EU | IT and Regulatory Compliance | AI systems | Qualitative |
| 20. Towards a privacy impact assessment methodology to support the requirements of the general data protection regulation in a big data analytics context: A systematic literature review | Georgiadis and Poels [3] | The research purpose of this article is to conduct a systematic literature review to identify privacy, and data protection risks specific to the Big Data Analytics context, aiming to develop a comprehensive DPIA methodology. Through thematic analysis, the study defines nine Privacy Touch Points summarising identified risks, with the goal of assisting data processors and controllers in identifying, analysing, and mitigating privacy and data protection risks in the context of Big Data Analytics. | EU | IT | Big Data Analytics | Systematic Literature Review |
| 21. A Semantic Specification for Data Protection Impact Assessments (DPIA) | Pandit [31] | The research purpose of this article is to address the challenges faced by stakeholders in conducting DPIAs under the GDPR by utilising linked-data to represent DPIA-related information in a consistent and reusable manner. The article introduces an extension to the Data Privacy Vocabulary (DPV) for documenting DPIAs and an ontology for risk management based on ISO 31000 standards, aiming to improve the management and sharing of DPIA information and pave the way for shared impact assessments in the context of emerging technologies like AI and Cybersecurity. | EU | IT | Semantic Web Technologies, AI | Conceptual |
| 22. DPIA in Context: Applying DPIA to Assess Privacy Risks of Cyber Physical Systems | Henriksen-Bulmer et al., [29] | The research purpose of this article is to introduce the DPIA Data Wheel, a holistic privacy risk assessment framework based on Contextual Integrity, to assist practitioners in evaluating privacy risks associated with Cyber Physical Systems. The framework aims to enable comprehensive contextual inquiry into privacy risks, identify mitigation strategies, and facilitate GDPR compliance by assessing privacy concerns from both organisational and individual perspectives through empirical evaluation in real-world settings. | UK | IT | Cyber Physical Systems (CPS) | Mixed method |
| 23. Impact assessment requirements in the GDPR vs. the AI Act: Overlaps, divergence, and implications | Rintamäki et al. [9] | The study examines the overlaps, divergences and practical implications between DPIA obligations under the GDPR and Fundamental Rights Impact Assessment (FRIA) obligations under the AI Act. The article aims to identify when high-risk AI systems involving personal data trigger overlapping assessment requirements across the GDPR and the AI Act, analyse the variance in DPIA requirements across EU and EEA jurisdictions, and propose a more harmonised and interoperable impact assessment approach to support information sharing and compliance throughout the AI value chain. | EU/EEA | Regulatory Compliance | AI systems and high-risk AI systems | Mixed Method |
| 24. Illuminating the DPIA Blackbox—A Survey of Data Protection Impact Assessment Practices in Organisations | Hansen et al. [13] | The study investigates how DPIAs are implemented in organisational practice and examines the practical challenges, operational processes, and methodological approaches used by organisations when conducting DPIAs. The article aims to illuminate the “DPIA blackbox” by analysing how organisations operationalise DPIA activities, structure assessment practices, and address implementation-related decision-making in practice. | EU | Regulatory Compliance | N/A (process-oriented DPIA study) | Exploratory Qualitative Study |
| 25. Regulating AI-Driven Triage: Fundamental Rights and Compliance Challenges in the European Union | Lazcoz et al. [51] | The study examines the legal and regulatory challenges associated with the use of AI-driven triage systems in emergency healthcare within the European Union. The article analyses the applicability of the AI Act, GDPR, and MDR to AI-supported emergency triage, focusing particularly on automated decision-making, human oversight, profiling, DPIAs, FRIAs, and patient rights in AI-assisted clinical decision-making. | EU | Healthcare/Regulatory Compliance | AI-driven triage systems, generative AI, large language models (LLMs), automated decision-making systems | Legal and Regulatory Analysis |
Appendix B. Derivation and Validation of the Proposed Framework
| Lifecycle Phase | Risk Management Domain | Control Objective | Operational Activity Details | Sources |
|---|---|---|---|---|
| PLAN Pre-Assessment Phase | Define Scope | Articulation of the data processing activities to be assessed | It is essential first to identify the need for a DPIA by considering whether the data processing activity is likely to result in a high risk to the rights and freedoms of individuals. This includes specifying the types of data processed, the purposes of the processing, the systems involved, and the geographical scope. In the context of big data analytics, for example, it is essential to understand how data from different sources is integrated and processed in order to effectively identify potential privacy risks. Detail the specific data types (e.g., personal identification information, behavioural data, transactional data), the objectives of processing (e.g., personalised marketing, service improvement, fraud detection), the technological systems used (e.g., databases, analytics platforms, cloud services), and the geographical regions where data processing occurs (e.g., EU, non-EU regions) | Information Commissioner’s Office [64] Georgiadis and Poels [3] Wright and Hert [45] |
| Consideration of the specific technological context | Addressing the specific technological environment will help understand the unique challenges and risks associated with these technologies at a more pre-assessment stage, as it highlights the need to tailor the scope of the DPIA to the specific technological environment to ensure a comprehensive risk assessment at a later stage. For instance, AI systems may involve automated decision-making processes that need scrutiny for fairness and transparency. IoT devices may introduce additional risks related to data transmission and device security. Blockchain technologies, particularly in IoT systems, can present challenges related to data immutability and transparency. While blockchain can enhance compliance with privacy regulations by providing secure and tamper-resistant data management, it also raises issues such as the difficulty of modifying or deleting data to comply with GDPR’s right to be forgotten. | Riemann et al. [44] Georgiadis and Poels [3] Mantelero [41] Bieker et al. [49] Campanile et al. [38,50] | ||
| Define Objectives | Aligning Data Processing with Business Goals | Ensure that the data processing activity supports the company’s overarching goal of enhancing customer experience through personalised services. This involves integrating data protection principles into the organizational culture to ensure that privacy considerations are part of the decision-making process at all levels | Calvi and Kotzinos [32] | |
| Addressing Business Needs | Identify and document the specific business needs that the data processing activity is intended to meet, such as improving customer satisfaction, increasing sales through targeted marketing and optimising product recommendations. This ensures that data processing activities are fit for purpose and aligned with business objectives. | Grammatopoulos et al. [30] | ||
| Ensuring Data Minimization | Ensuring data minimization involves limiting the amount of personal data processed to what is strictly necessary for the purposes identified. This reduces the risk of unnecessary data exposure and enhances compliance with the principle of data minimization. In the context of Big Data Analytics, it is crucial to adopt data minimization strategies to mitigate the inherent privacy risks associated with processing large volumes of data from various sources. For instance, the importance of embedding data protection throughout the life cycle of data processing, particularly in environments with extensive data analytics operations, to prevent over-collection and misuse of personal data. In addition, the need to align data processing practices with data minimization principles to ensure that only the essential data required for specific purposes is processed, thereby reducing the likelihood of privacy breaches. Conducting data minimization during the Pre-Assessment Phase is essential because it allows organisations to identify and limit the scope of data collection from the outset, thereby setting a foundation for compliant data processing activities. This proactive approach ensures that data protection measures are integrated early in the data lifecycle, minimising risks and enhancing overall data governance. | Wright and Hert [45] Georgiadis and Poels [3] | ||
| Assessing Data Quality and Sources | Evaluate the quality and accessibility of the data to be used in the processing activity. Ensure that the data is accurate, complete, and reliable, and that it is sourced in a manner that complies with legal and ethical standards. | Papamartzivanos et al. [35] | ||
| Data Flow Mapping | Mapping the flow of data to understand how data is being collected, processed and shared | Implementing a detailed data flow mapping is crucial for identifying privacy and security risks effectively. This involves charting how data moves through different stages of collection, processing, storage, and sharing within the organisation. This process helps in pinpointing potential vulnerabilities and ensures comprehensive privacy risk assessments. The APSIA methodology (Papamartzivanos et al. [35]) emphasises the importance of detailed data flow mapping to identify privacy and security risks in ICT infrastructures. It incorporates the use of interdependency graphs to visualise visualize the relationships between data assets, processing activities, and associated vulnerabilities. This graphical representation supports the identification of risky data processing activities by highlighting the interconnections and dependencies between different assets, thus enabling a dynamic and thorough privacy risk assessment. In this regard, best practices for conducting privacy impact assessments include comprehensive data flow analysis to understand the data lifecycle and potential risk points. This involves creating detailed diagrams that map out every stage of data processing, from collection to deletion, and identifying the entities involved at each stage. Such thorough mapping helps organisations ensure compliance with GDPR and other regulatory requirements by providing a clear overview of data processing activities and their associated risks. | Papamartzivanos et al. [35] Vemou and Karyda [47] | |
| Stakeholder Engagement | Involving all relevant stakeholders, including legal, technical and ethical experts, as well as representatives of affected communities | This is critical to ensure that all perspectives are considered and that the DPIA addresses the full privacy and data protection needs of the organisation. Accordingly, evolving DPIA frameworks should adapt to the dynamic nature of technology and the increasing volume of data being processed. This approach ensures that the DPIA remains relevant and effective in mitigating the risks associated with new and emerging technologies. Stakeholder engagement should also involve people from different parts of the organisation to ensure strong buy-in and diverse expertise. In this regard, heterogeneous organisational practices and insufficiently assessed multi-stakeholder processes may further complicate the practical implementation of DPIAs. The literature review revealed that the importance of ongoing stakeholder engagement throughout the DPIA process and continuous interaction with relevant stakeholders ensures that data protection measures are in line with actual data processing activities and dynamic changes in the technological environment. This ongoing engagement is crucial to effectively identify and mitigate data protection risks, especially in complex environments such as smart cities and IoT systems. In addition, the involvement of stakeholders such as legal advisors, technical experts and community representatives helps to address different concerns and ensures that the DPIA is comprehensive. The inclusiveness of the DPIA process ensures that the expertise of different stakeholders is utilised to identify potential risks and develop effective mitigation strategies. This is particularly important in scenarios involving advanced technologies such as AI and IoT, where the expertise of technical stakeholders is essential for understanding and addressing specific risks. Lastly, involving stakeholders from different backgrounds ensures that the DPIA can address not only technical and legal aspects, but also social and ethical implications. In this regard, by engaging a wide range of stakeholders, organisations can ensure that the DPIA process is robust, inclusive and able to address the complex and evolving landscape of data protection. | Hansen et al. [13] Wright and Hert [45] Grammatopoulos et al. [30] Mantelero [41] Calvi [53] | |
| PLAN Risk Identification and Impact Evaluation | Risk Policy | Developing a risk policy based on ISO 31000 risk management standard to systematically identify risks, mitigations, consequences, and impacts | ISO 31000 risk management standard provides principles and guidelines for risk management, emphasising the importance of establishing a structured framework to address risks in a consistent and effective manner. According to ISO 31000, risk management should be integrated, structured, comprehensive and appropriate to the context of the organisation. In this context, the literature review proposed an extension of the Data Privacy Vocabulary (“DPV”) (Pandit [31]) to document DPIA-related information using an ontology based on ISO 31000 standards to improve consistency and reusability. This approach enables better management and interoperability by representing DPIA-related information as linked data and facilitates the sharing and reuse of risk-related information. In addition, overlaps and divergences between GDPR DPIA requirements and AI Act FRIA obligations further demonstrate the need for more harmonised and interoperable risk assessment structures capable of supporting consistent information sharing across the AI value chain (Rintamäki et al. [9]). The DPV includes comprehensive taxonomies for describing personal data processing activities, risks and DPIA concepts, making it a versatile tool for different risk management applications. In this regard, Georgiadis and Poels [40] emphasise that incorporating Privacy Touch Points, a structured set of recurring privacy challenges identified through expert consensus, including lack of transparency, purpose expansion, inference-related risks and procedural ambiguity, into DPIA structures can strengthen methodological clarity and improve the consistency of risk-related decision-making in complex, technology-intensive environments. On the other hand, the review highlighted the need for structured risk assessments in AI systems in order to effectively manage risks to individual rights and freedoms. The need for a well-defined risk ontology that integrates legal, social and technical perspectives, provides a holistic understanding of the impact of AI, and promotes fairness and accountability was advocated. By combining these methodologies and adhering to the principles of ISO 31000, organisations can develop a robust risk ontology that supports comprehensive risk identification and management, improves the effectiveness of DPIAs and ensures compliance with data protection regulations. | Rintamäki et al. [9] ISO 31000 [28] Pandit [31] Calvi and Kotzinos [32] Georgiadis and Poels [40] |
| Risk Analysis | Conducting a comprehensive contextual analysis to identify potential privacy and security risks associated with data processing technologies, ensuring data protection through proactive assessment and mitigation strategies | A comprehensive identification of potential privacy risks, covering both physical and technological processes, is essential to ensure data protection. The literature has highlighted the complexity of risk assessment, emphasised the need for a comprehensive analysis of both physical and technological risks due to the integration of multiple sensors and systems, creating a socio-technical environment where privacy concerns must be carefully managed to prevent unauthorised access and data breaches, and advocated a DPIA that includes comprehensive assessments of data flow, storage and processing activities to address potential risks such as identity theft and unauthorized data access, underlining the importance of detailed risk identification and mitigation strategies. Accordingly, it is recognised that conducting a comprehensive contextual analysis is critical to understanding the specific technological environment and identifying potential privacy and security risks associated with data processing activities, including AI, big data, IoT and blockchain. The literature review discussed the CLIFOD framework (Henriksen-Bulmer et al. [29]), which integrates physical, human, and technological components to provide a comprehensive privacy risk assessment using Nissenbaum’s Contextual Integrity (Nissenbaum [65]) which defines privacy as appropriate information flows within specific social contexts, based on key aspects including the context itself, the actors involved, the types of information being shared, and the transmission principles governing how information is exchanged. The stages of the framework, namely disclosure, risk assessment and decision making, enable organisations to systematically identify and mitigate privacy risks in cyber-physical systems. In addition, conducting a contextual risk analysis prior to commencing data processing activities is critical to identifying vulnerabilities specific to the technologies used. In AI-supported decision-making environments, this analysis should also consider automation bias, meaningful human oversight and workflow-integrated safeguards in order to effectively mitigate risks associated with high-risk AI systems (Lazcoz et al. [51]). This proactive approach ensures that potential privacy and security risks are fully understood and mitigated. By assessing the weaknesses and vulnerabilities of AI, big data, IoT and blockchain technologies in advance, organisations can implement appropriate protection and compliance measures, thereby improving overall data security and regulatory compliance. In this context, the review highlighted the importance of understanding the technological context of GDPR-compliant blockchain systems in the IoT to effectively address privacy risks. As highlighted in the UK government’s research on cybersecurity risks to AI, which highlights the need for comprehensive assessments to mitigate potential risks, it is crucial to identify specific vulnerabilities of technologies prior to implementation. | Lazcoz et al. [51] UK-Government [66] Henriksen-Bulmer et al. [29] Campanile et al. [38] Nissenbaum [65] Leesakul and Morisset [34] Bisztray et al. [42] | |
| Fairness Assessment | Implementing fairness metrics to ensure that data processing activities are fair and equitable, integrating comprehensive frameworks and intersectional considerations to mitigate bias | The application of fairness metrics is crucial for assessing the impact of data processing activities on individuals’ rights and freedoms, and for ensuring that these activities are carried out in a fair and equitable manner. The systematic literature review presented a framework for integrating fairness metrics into DPIAs, highlighting their importance for operationalizing the fairness principle in the GDPR and for systematically assessing and mitigating bias in data processing, particularly in AI systems. The framework includes a detailed review of the fairness principle in Article 5(1)(a) of the GDPR and its application to DPIAs, highlighting the need for concrete, quantified fairness metrics to bridge the gap between regulatory frameworks and AI systems. Specifically, the review discusses the role of fairness in data protection in smart cities, highlighting the need to assess the impact on different populations and consider cross-cutting aspects such as gender, race and socio-economic status to avoid disproportionate impacts on vulnerable groups. In this context, companies should apply fairness metrics as part of their DPIAs to ensure that data processing activities are fair and equitable. This includes integrating comprehensive frameworks and cross-cutting considerations to effectively mitigate bias. Furthermore, Moniz [37] highlights that fairness assessments within DPIAs inherently rely on discretionary balancing and proportionality judgments by data controllers, which introduces risks of subjectivity and inconsistency when determining whether processing is fair. This way, organisations can align their data processing practices with legal requirements and promote social justice by ensuring that their technology serves all populations in a fair and responsible manner. | Calvi [53] Kasirzadeh and Clifford [52] Moniz [37] | |
| Ethical Analysis | Conducting an ethical impact assessment to address socio-ethical implications and promote fairness | The literature review highlighted the importance of assessing the ethical implications of data protection, with a particular focus on inclusiveness and the needs of diverse populations and argued that it should consider how data processing affects different demographic groups and ensure that activities promote fairness and equality. It stressed the importance of integrating ethical considerations into the DPIA process, particularly in the context of AI and big data, and of addressing wider societal impacts and ensuring that data processing activities do not disproportionately affect vulnerable groups. Gültekin-Várkonyi [43] emphasises that technologies such as facial recognition and AI-driven surveillance create significant socio-ethical concerns, including mass surveillance risks, erosion of individual autonomy, unequal impacts arising from accuracy disparities and the normalisation of intrusive monitoring practices, and therefore argues that DPIAs should adopt a human-rights-oriented ethical analysis that explicitly evaluates these broader societal harms and fundamental-rights implications when assessing emerging data-intensive systems. Ethical Impact Assessments are necessary to maintain public trust and ensure that data processing activities are in line with societal values; therefore, companies should assess the potential socio-ethical impacts of data processing activities and integrate these ethical considerations into their DPIA processes in order to promote fairness, build public trust and align their practices with societal values. In order to conduct an effective Ethical Impact Assessment, companies should engage with diverse stakeholders, including representatives from different demographic groups and communities, to gather different perspectives on the potential impacts of data processing activities. They should systematically identify and assess potential harms and benefits, ensuring that vulnerable populations are considered. Ensuring transparency and accountability, by making the decision-making process transparent and holding those responsible accountable for their decisions, fosters trust and upholds ethical standards. In addition, companies should document and monitor their ethical considerations and assessments and continually monitor impacts to adapt and improve practices over time. By following these steps, companies can ensure that their data processing activities are fair, ethical and in line with societal values. | Calvi [53] Mantelero [41] Gültekin-Várkonyi [43] | |
| User Rights Impact Analysis | Assessing how data processing activities impact the rights of data subjects, including the right to access, rectify, erase, and restrict processing of their data | Assessing how data processing activities affect the rights of data subjects, including their rights to access, rectification, erasure and restriction of the processing of their data, ensures compliance with GDPR requirements and promotes the protection of individual rights. The literature review advocated the importance of assessing privacy by design in identity management systems, emphasising both architectural and user aspects to address digital identity management challenges and adapt DPIA as a legal methodology. The need for comprehensive DPIA frameworks to effectively protect the rights of data subjects and the importance of fairness criteria in the DPIA process to ensure that data processing activities respect the rights and freedoms of individuals was emphasized, highlighting in particular the complexities of big data analytics. Regular review and updating of these procedures are crucial to address emerging challenges and maintain compliance. By implementing transparent procedures for data subjects to exercise their rights, providing regular GDPR training to employees, regularly reviewing and, where necessary, updating data protection policies, and using fairness criteria to ensure non-discriminatory data practices, organisations will not only comply with the GDPR and other relevant regulations, but will also improve the protection of data subjects’ rights, build trust with their customers, and demonstrate their commitment to privacy, thereby increasing customer satisfaction and loyalty. | López et al. [39] Kasirzadeh and Clifford [52] Georgiadis and Poels [3] | |
| Technical Feasibility | Ensuring that proposed privacy measures are practical and can be effectively implemented | Discussing technical feasibility with subject matter experts is critical to assessing the feasibility of proposed safeguards. The literature review highlighted the importance of assessing the technical feasibility of identity management systems to ensure the practical implementation of privacy measures. This includes assessing the technical capabilities of the systems to support privacy-enhancing technologies such as encryption, anonymization, and secure access controls. It is also important to assess the ability of the system to integrate these technologies without compromising performance or user experience. It also highlights the need to assess the technical feasibility of blockchain-based IoT systems, focusing on the scalability, reliability and security of blockchain solutions in managing IoT data. This includes ensuring that blockchain technologies can maintain data integrity and confidentiality when processing the large volumes of data generated by IoT devices. Companies should conduct thorough technical assessments, including stress testing and performance evaluations, to identify potential technical limitations and opportunities for optimisation. Working with experts in relevant fields can help companies implement robust and effective privacy protections by providing valuable insight into the latest technological developments and best practices. By thoroughly assessing technical feasibility, organisations can ensure that privacy measures are not only theoretically sound, but also practically feasible, resulting in enhanced privacy and legal compliance. This proactive approach to assessing technical feasibility will help to create flexible data protection frameworks that can adapt to technological developments and changing threats. | López et al. [39] Campanile et al. [50] | |
| DO Mitigation Strategies | Technical and Organizational Measures (TOMs) | Ensuring comprehensive protection of personal data through effective technical and organisational measures | Implementing TOMs such as encryption, access controls and data minimisation and taking a holistic approach to TOMs and integrating them into the overall risk management framework to ensure robust data protection across the organisation is critical to protecting personal data and ensuring compliance with data protection regulations. The PACTS methodology of the TRUSTEE framework (Grammatopoulos et al. [30]) from the literature review emphasises a structured approach to risk management and outlines effective strategies for the development and implementation of risk mitigation measures. The Preparation component of the PACTS methodology involves identifying potential risks and preparing a comprehensive plan to address those risks; Assessment involves evaluating the identified risks and their potential impact on data protection; Control involves implementing measures to control and mitigate the identified risks and data protection; Monitoring involves tracking the effectiveness of implemented measures and monitoring changes in risk levels; and Sharing involves sharing information about risks and mitigation strategies with relevant stakeholders to ensure transparency and collaborative risk management. Companies should be encouraged to adopt this methodology to ensure a comprehensive and systematic approach to risk mitigation, technical guidelines, recognise the importance of integrating cybersecurity measures into privacy frameworks to enhance data protection, and conduct continuous monitoring and periodic reviews to maintain the effectiveness of implemented strategies. The need to ensure the precise definition and implementation of technical and organisational measures tailored to specific data protection needs was also highlighted in the studies. | Grammatopoulos et al. [30] Pandit [31] European Union Agency for Network and Information Security [67] |
| Cybersecurity Integration | Enhancing data protection by integrating cybersecurity measures with privacy frameworks | The literature review highlighted the APSIA methodology (Papamartzivanos et al. [35]), which integrates privacy and security assessments to provide a comprehensive approach to risk management. In particular, it highlighted the need to integrate cybersecurity into DPIAs in the context of big data analytics to address the unique security challenges posed by large-scale data processing. Accordingly, it highlights the importance of companies incorporating cybersecurity measures into their privacy frameworks to enhance data protection. By ensuring that cybersecurity practices are integrated into privacy frameworks to effectively address both security and privacy risks, organisations can enhance their overall risk management strategy, improve data protection compliance, and build customer trust by demonstrating a strong commitment to data security and privacy. This integration aligns the privacy framework with the Information Security Management System baseline specified in ISO/IEC 27001:2022, whose Annex A controls (organised under organisational, people, physical and technological themes) are explicitly referenced by ISO/IEC 27701:2025’s Annex A.3 as the security controls underpinning a PIMS. | Papamartzivanos et al. [35] Georgiadis and Poels [3] ISO/IEC27701:2025 [14] | |
| DO Documentation and Reporting | Comprehensive Documentation | Documenting all phases of the DPIA process, including identified risks, mitigation strategies, and stakeholder consultations | Documenting all stages of the DPIA process, including the pre-assessment phase, will ensure that every aspect of the DPIA is meticulously recorded and will provide a comprehensive and reusable reference. The literature review highlighted the importance of using an expanded data privacy vocabulary, which is an extended vocabulary designed to provide a structured and comprehensive framework for documenting data privacy activities, ensures that all aspects of data privacy are clearly defined and consistently documented, facilitating better communication, understanding, and management of privacy risks and compliance measures within an organisation, for detailed documentation and that all data privacy activities should be clearly defined and consistently documented. It also highlighted the need to document fairness criteria and impact assessments that provide a transparent record of how decisions were made and their potential impact on data subjects. This level of detail is critical to maintaining corporate accountability and due diligence in data protection practices. | Pandit [31] Kasirzadeh and Clifford [52] |
| Transparent Reporting | Ensuring transparent reporting to stakeholders and regulatory authorities, clearly communicating how privacy risks are managed and mitigated | Transparent reporting includes regularly updating stakeholders on the results of the DPIA, including steps taken to address identified risks. In particular, the importance of conducting privacy impact assessments and transparently communicating the results to all relevant parties should be recognised. This should include detailed reports explaining the reasoning behind decisions and the effectiveness of the measures taken. The literature review recommends transparent reporting in big data DPIAs, emphasizing that findings should be communicated in a clear and comprehensive manner to maintain stakeholder trust and compliance. Companies should ensure that all DPIA activities are clearly and effectively communicated to stakeholders by establishing regular reporting protocols. This practice not only increases accountability but also builds trust and demonstrates a commitment to privacy. By implementing robust documentation and transparent reporting practices, organisations can ensure ongoing regulatory compliance and create a culture of data privacy transparency and accountability. | Georgiadis and Poels [3] Information Commissioner’s Office [11] | |
| CHECK Continuous Monitoring | Monitoring and Review | Maintaining the effectiveness and relevance of data protection measures through continuous monitoring and regular updates | Mechanisms for continuous monitoring and periodic review of privacy measures should be put in place to ensure continuous adaptation and adjustment to new risks. The literature review supports continuous monitoring as part of the CLIFOD framework (Henriksen-Bulmer et al. [29]) and highlights the importance of continuous assessment and adaptation of data protection measures. It also highlighted the need for regular updates and improvements to address emerging threats and evolving legal requirements. In this context, organisations should implement automated monitoring systems to monitor data processing activities in real time, enabling rapid detection and response to potential security incidents. Regular audits and assessments should be conducted to evaluate the effectiveness of existing data protection measures and identify areas for improvement. By establishing a feedback loop, organisations can ensure that their privacy policies evolve in line with technological developments and regulatory changes. It is also recommended that a dedicated team be established to oversee the ongoing monitoring and review process, ensuring accountability and a continued focus on privacy. Working with external auditors and industry experts can provide additional insight and verify the robustness of the measures in place. This proactive approach helps organisations take a strong data protection stance, ensure compliance and build trust with stakeholders. | Henriksen-Bulmer et al. [29] Vemou and Karyda [47] |
| CHECK Compliance Verification | Legal Compliance Check | Ensure compliance with GDPR and other relevant privacy legislation | The Article 29 Data Protection Working Party Guidelines (Article 29 Data Protection Working Party [12]) outline the requirements for assessing processing activities to ensure compliance with the principles of the GDPR. These and similar guidelines provide a structured approach to ensuring that data processing activities comply with legal standards, thereby protecting the privacy of individuals and supporting data protection legislation. Additionally, it is critical for organisations to comply with local data protection regulations, which may have specific requirements that go beyond the GDPR. In the literature review, the TRUSTEE framework (Grammatopoulos et al. [30]) highlights the importance of complying with local data protection laws to ensure comprehensive compliance. In addition, the Data Act provides a framework for managing data access and sharing in accordance with the law. Richter [68] argues that the Data Act aims to facilitate data sharing across sectors while providing robust data protection measures, and that compliance with the Data Act is crucial for organisations to balance innovation with the protection of fundamental rights and freedoms. Therefore, organisations should familiarise themselves with the provisions of the Data Act to understand the regulatory landscape for data access and sharing. This includes understanding the legal obligations for data protection and the measures required to comply with the Data Act and should ensure that they understand and implement the requirements of the Data Act to maintain legal compliance. Moreover, Moniz [37] argues that legal compliance checks within the DPIA should also evaluate the legitimacy of the underlying balancing and proportionality assessments, noting that mere adherence to regulatory provisions may be insufficient where fundamental rights are affected. By following these guidelines and ensuring comprehensive legal compliance by adhering to both the GDPR and local data protection regulations, organisations can not only avoid legal penalties but also enhance the organisation’s reputation for data protection and build trust with stakeholders. Finally, seeking advice from privacy law experts can help navigate the complex regulatory landscape and ensure that all compliance measures are implemented effectively. | Grammatopoulos et al. [30] Article 29 Data Protection Working Party [12] Richter [68] Moniz [37] |
| Fairness Validation | Verifying the fairness of data processing activities through the application of appropriate fairness metrics and transparency safeguards. | The validation of fairness requires assessing whether the data processing activity results in discriminatory effects, unequal outcomes, or systemic disadvantages for particular groups of data subjects, moving beyond formal compliance and examining the socio-technical implications of automated decision-making. In the context of emerging technologies such as AI and big data analytics, the DPIA should integrate concrete fairness metrics to systematically evaluate potential bias, ensuring that fairness is operationalised in line with the GDPR’s fairness principle. Recent literature highlights that fairness within DPIAs must be based on measurable criteria rather than abstract normative interpretations and should be embedded in the risk assessment process by linking fairness metrics to mitigation strategies in AI-driven environments (Kasirzadeh & Clifford [52]), while acknowledging that fairness determinations ultimately depend on discretionary balancing and proportionality assessments that reflect the DPIA’s nature as a fundamental rights governance instrument rather than a purely technical evaluation (Moniz [37]). The AI Act further reinforces this governance logic by embedding fairness evaluations into a continuous risk-based compliance framework for high-risk AI systems through mandatory data governance duties, bias mitigation obligations and post-market monitoring requirements. Accordingly, fairness validation requires identifying and justifying the fairness metrics applied, assessing their contextual adequacy, evaluating procedural safeguards such as transparency and documentation, and establishing mechanisms for continuous monitoring to address potential fairness-related harms over time. In this regard, fairness validation complements the overall compliance verification by ensuring that the processing activity not only satisfies legal requirements but also promotes equitable outcomes and accountability throughout the lifecycle of advanced data processing systems. | Kasirzadeh and Clifford [52] Calvi and Kotzinos [32] Georgiadis and Poels [40] Moniz [37] | |
| ACT Review and Adaptation | Periodic Reviews | Regularly reviewing the DPIA framework to incorporate new insights and regulatory updates | Periodic reviews ensure that the DPIA framework remains up-to-date and effective. The literature review highlighted the importance of regularly updating DPIA methodologies to keep pace with technological developments and emerging risks, as well as the importance of periodic reviews to ensure that DPIAs continue to address current and evolving privacy concerns. In this regard, companies should establish regular review programmes and engage with regulatory updates to incorporate the latest changes and best practices into their DPIA processes. | Mantelero [41] Janssen et al. [36] |
| Emerging Technologies | Continuously adapting the DPIA framework to address new challenges and risks posed by emerging technologies | Adapting the DPIA framework to emerging technologies is critical for effective privacy risk management. The literature review recommended modifying DPIA methodologies for big data analytics to address the unique challenges posed by large-scale data processing and argued for the need to adapt DPIA approaches for blockchain and IoT systems, highlighting the need to ensure that the framework remains effective in managing privacy risks in evolving technological contexts. In this context, companies need to keep abreast of technological developments and work with experts to continuously update DPIA methodologies to ensure robust and up-to-date privacy measures. | Georgiadis and Poels [3] Campanile et al. [50] |
| Lifecycle Phase (PDCA) | Risk Management Domain | Control Objective | Operational Activity (Figure 4) and Addressed Challenges | ISO 31000:2018 Alignment (Process Backbone) | ISO/IEC 27701:2025 Mapping | ISO/IEC 29134:2023 Mapping |
|---|---|---|---|---|---|---|
| PLAN—Pre-Assessment Phase (aligns with ISO 31000 §6.3 Scope, Context and Criteria) | ||||||
| Plan | Pre-Assessment Phase | Define Scope—articulation of the data processing activities to be assessed | Identifies the need for a DPIA, specifying data types, processing purposes, systems and geographical scope. Addresses L1, L2 | §6.3.2 Defining the scope (subject of the risk management activity) | §4.3 Determining the scope of the PIMS; §6.1.1 Actions to address risks; A.1.2.6 PIA mandatory trigger | §6.2 Threshold analysis; §6.3.3 Describe what is being assessed; §7.3.1 Process under evaluation |
| Plan | Pre-Assessment Phase | Define Scope—consideration of the specific technological context | Tailors DPIA scope to AI, IoT, blockchain, or big data environments. Addresses L3, L2 | §6.3.3 External and internal context (technological environment) | §4.1 Understanding the organisation and its context | §6.3.3 System design information; §7.3.1.3 System design |
| Plan | Pre-Assessment Phase | Define Objectives—aligning data processing with business goals | Integrates data protection principles into organisational decision-making | §6.3.3 Internal context (objectives, strategies) | §4.1 Context; §4.2 Needs and expectations of interested parties | §6.3.1 Risk criteria reflect organisation’s values, objectives, resources |
| Plan | Pre-Assessment Phase | Define Objectives—addressing business needs | Documents specific business needs for fitness for purpose | §6.3.4 Defining risk criteria (linked to objectives) | §4.4 PIMS scope; §5.1 Leadership and commitment | §6.3.2 Business case and allocated resources for the PIA |
| Plan | Pre-Assessment Phase | Define Objectives—ensuring data minimisation | Limits processing to what is strictly necessary; critical for big data. Addresses L3, S3 | §6.3.4 Risk criteria (linked to data minimisation principle) | A.1.4.2 Limit collection; A.1.4.3 Limit processing; A.1.4.5 PII minimisation | §6.4.3 Privacy safeguarding requirements (data minimisation) |
| Plan | Pre-Assessment Phase | Define Objectives—assessing data quality and sources | Evaluates accuracy, completeness, reliability and lawful sourcing | §6.3.3 External context (data sources) | A.1.4.4 Accuracy and quality of PII | §6.4.1 Identify information flows of PII (sources) |
| Plan | Pre-Assessment Phase | Data Flow Mapping | Charts data movement (collection, processing, storage, sharing) using APSIA interdependency graphs (Papamartzivanos et al. [35]). Addresses R4, C3, C7 | §6.3.2 Defining the scope (boundaries and interfaces); §6.4.2 Risk identification (sources and events) | A.1.2.9 Records related to processing PII; A.3.5 Classification of information | §6.4.1 Identify information flows of PII; §7.3.1.2 System requirement information |
| Plan | Pre-Assessment Phase | Stakeholder Engagement (Stakeholder Management—see notes) | Multidisciplinary engagement throughout the DPIA. Operationalises ISO 31000 §6.2 Communication and Consultation as a continuous activity, framed as Stakeholder Management within the framework. Addresses L1, C9, C10, S1 | §6.2 Communication and consultation (continuous, spanning all phases) | §4.2 Understanding needs and expectations of interested parties; §7.4 Communication | §6.3.4 Identify stakeholders; §6.3.5 Establish a consultation plan; §6.3.6 Consult with stakeholders |
| PLAN—Risk Identification and Impact Evaluation (aligns with ISO 31000 §6.4 Risk Assessment) | ||||||
| Plan | Risk Identification and Impact Evaluation | Risk Policy—based on ISO 31000 to systematically identify risks, mitigations, consequences, and impacts | Establishes structured, repeatable risk methodology integrating PTPs (Georgiadis & Poels [40]) and DPV ontology (Pandit [31]). Addresses R1, R6 | §5.4.2 Establishing a risk management policy; §6.1 General; §6.4.1 General | §5.2 Policy; §6.1.2 Risk assessment (built on ISO 31000); §6.1.3 Risk treatment | §6.3.1 Set up PIA team and provide direction (ISO 31000-based criteria) |
| Plan | Risk Identification and Impact Evaluation | Risk Analysis | Applies CLIFOD framework (Henriksen-Bulmer et al. [29]) based on Contextual Integrity. Addresses R1, R3, R4, R5, R7, C3 | §6.4.2 Risk identification; §6.4.3 Risk analysis (likelihood and consequences) | §6.1.2 Risk assessment process (criteria, identification, analysis, evaluation); A.5.7 Threat intelligence | §6.4.4 Privacy risk analysis; §6.4.5 Privacy risk evaluation; Annex A scale criteria; Annex B Generic threats |
| Plan | Risk Identification and Impact Evaluation | Fairness Assessment | Operationalises GDPR Article 5(1)(a) fairness; complements EU AI Act Article 27 FRIA. Addresses C6, C8, S1, S3 | Extends ISO 31000 §6.4.2 risk identification toward algorithmic bias as a non-traditional risk source | Partial—A.1.3.11 Automated decision-making addresses individual rights, not systemic fairness. Framework extends 27701 in line with AI Act | Partial—fairness not in §6.3.1 harm dimensions. Framework extends PIA toward algorithmic fairness assessment |
| Plan | Risk Identification and Impact Evaluation | Ethical Analysis | Human-rights-oriented ethical analysis (Mantelero [41]; Gültekin-Várkonyi [43]) addressing surveillance, autonomy, vulnerable groups. Addresses C1, C6, S1, S2, S4 | Extends ISO 31000 §6.4.3 consequences analysis toward socio-ethical impact | Not addressed—beyond 27701 privacy/security scope. Framework extension complementing AI Act FRIA | Not addressed—beyond 29134 PIA scope. Framework extension toward socio-ethical evaluation |
| Plan | Risk Identification and Impact Evaluation | User Rights Impact Analysis | Evaluates GDPR Articles 15-22 rights impact in identity management and big data contexts. Addresses R5, R6, C8 | §6.4.3 Risk analysis (consequences for affected parties) | A.1.3.2 Obligations to PII principals; A.1.3.3–3.10 Rights of access, correction, erasure, objection | §6.4.3 Privacy safeguarding requirements; §7.3.2 Privacy requirements |
| Plan | Risk Identification and Impact Evaluation | Technical Feasibility | Assesses scalability, reliability, integration of privacy-enhancing technologies. Addresses C5 | §6.4.4 Risk evaluation (informed by feasibility); §6.5.2 Selection of risk treatment options | §6.1.3 Risk treatment (selection of options); A.3.29 Secure system architecture | §6.4.6 Determine controls (consider feasibility); §6.4.7 Risk treatment plans |
| DO—Mitigation Strategies (aligns with ISO 31000 §6.5 Risk Treatment) | ||||||
| Do | Mitigation Strategies | Technical and Organisational Measures (TOMs) | Implements TOMs through PACTS methodology of TRUSTEE framework (Grammatopoulos et al. [30]). Addresses C12, C13 | §6.5.2 Selection of risk treatment options; §6.5.3 Preparing and implementing risk treatment plans | A.1.4.6 De-identification; A.1.4.10 Transmission controls; A.3.7–3.9 Information transfer, identity, access; A.3.20–3.26 Security baseline | §6.4.6 Determine controls; §6.5.3 Implement privacy risk treatment plans |
| Do | Mitigation Strategies | Cybersecurity Integration | Applies APSIA methodology (Papamartzivanos et al. [35] integrating privacy and security. Aligned with ISO/IEC 27001:2022 ISMS baseline. Addresses C2, C7 | §6.5.2 Treatment options including risk reduction through technical and organisational controls | Annex A Table A.3 (security controls from ISO/IEC 27001:2022 baseline); §0.2 Compatibility with ISO/IEC 27001 ISMS; A.3.11–3.12 Incident management | §4 Relationship with ISO/IEC 27001 and 27002 [69] (security controls drawn from these baselines) |
| DO—Documentation and Reporting (aligns with ISO 31000 §6.7 Recording and Reporting) | ||||||
| Do | Documentation and Reporting | Comprehensive Documentation | Uses Data Privacy Vocabulary (Pandit [31]) for structured, reusable DPIA documentation. Addresses L2, C13, C15 | §6.7 Recording and reporting (structured documentation of risk management process) | §7.5 Documented information; A.1.2.9 Records related to processing PII; A.3.14 Protection of records | §6.5.1 Prepare the report; §7 PIA report (full structure) |
| Do | Documentation and Reporting | Transparent Reporting | Establishes regular reporting protocols communicating DPIA findings to stakeholders and authorities. Addresses L2, C8, C15, S4 | §6.7 Recording and reporting (communication with internal and external stakeholders) | A.1.3.4 Providing information to PII principals; §7.4 Communication | §6.5.2 Publication of the PIA; §7.6 PIA public summary |
| CHECK—Continuous Monitoring (aligns with ISO 31000 §6.6 Monitoring and Review) | ||||||
| Check | Continuous Monitoring | Monitoring and Review | Implements automated monitoring and periodic audits, drawing on the continuous-assessment dimension of CLIFOD. Addresses C13 | §6.6 Monitoring and review (effectiveness of risk management process and controls) | §9.1 Monitoring, measurement, analysis and evaluation; §9.2 Internal audit; §9.3 Management review; A.3.15 Independent review; A.3.25 Logging | §6.5.4 Review and/or audit of the PIA |
| CHECK—Compliance Verification (extends ISO 31000 §6.6 with privacy-specific compliance verification) | ||||||
| Check | Compliance Verification | Legal Compliance Check | Verifies compliance with GDPR, EU AI Act, Data Act, local regulations (Article 29 Data Protection Working Party [12]; Richter [68]; (Moniz [37]). Addresses L1, L2, L3 | Extends §6.6 Monitoring and review with privacy-specific legal/regulatory verification (not a discrete ISO 31000 step) | A.3.13 Legal, statutory, regulatory and contractual requirements; A.3.16 Compliance with policies, rules and standards | §7.4.6 Compliance analysis (dedicated section of PIA report) |
| Check | Compliance Verification | Fairness Validation | Applies fairness metrics (Calvi & Kotzinos [32]; Kasirzadeh & Clifford [52]) and proportionality (Moniz [37]), aligned with AI Act post-market monitoring. Addresses C6, C8, S1, S3 | Extends §6.6 Monitoring and review with AI Act bias-monitoring verification (not a discrete ISO 31000 step) | Partial—A.3.16 validates adopted policies; A.1.3.11 addresses individual rights but not systemic fairness. Framework extends 27701 | Not addressed—§7.4.6 is restricted to legal/regulatory compliance. Framework extends PIA toward fairness validation |
| ACT—Review and Adaptation (aligns with ISO 31000 §6.6 Monitoring and Review—recurring/adaptive) | ||||||
| Act | Review and Adaptation | Periodic Reviews | Regular review programmes incorporating regulatory and technological developments. Addresses L1, L2, C14 | §6.6 Monitoring and review (periodic effectiveness review and process improvement) | §10 Improvement; §10.1 Continual improvement; §10.2 Nonconformity and corrective action; §9.3 Management review | §6.5.5 Reflect changes to the process; §6.2 Threshold analysis re-applied |
| Act | Review and Adaptation | Emerging Technologies | Adapts framework to AI, blockchain, IoT, big data developments. Addresses L2, L3, S3, S5, C14 | §6.6 Monitoring and review (adaptive response to changes in external context, including emerging technology landscape) | §6.1.1 Actions to address risks (re-assessed when context changes); A.1.2.6 PIA triggered by new processing or changes | §6.5.5 Reflect changes (re-trigger PIA on significant technological change). Framework extends with dedicated emerging-tech treatment |
| Challenge Category | Specific Challenge Codes | Required DPIA Activity | Risk Management Domain |
|---|---|---|---|
| Legal and regulatory | L1, L2, L3 | Compliance verification; legal scope definition | Compliance Verification; Pre-Assessment Phase |
| Risk assessment | R1, R2, R3, R4, R5, R6, R7 | Risk identification, analysis and treatment | Risk Identification and Impact Evaluation; Mitigation Strategies |
| Complexity (risk-related) | C12, C13, C14 | Risk treatment, monitoring and structured documentation | Risk Identification and Impact Evaluation; Mitigation Strategies; Documentation and Reporting (C13); Continuous Monitoring; Review and Adaptation (C14) |
| Complexity (collaboration) | C5, C9, C10 | Continuous stakeholder engagement and interdisciplinary consultation | Pre-Assessment Phase (continuous Stakeholder Engagement, aligned with ISO 31000 §6.2 Communication and Consultation); Risk Identification and Impact Evaluation (Technical Feasibility, C5) |
| Complexity (implementation) | C1, C2, C3, C4, C6, C7, C8, C11, C15 | Cross-cutting activities including risk analysis, fairness assessment, ethical analysis, cybersecurity integration, and structured documentation | Multiple domains (cross-cutting) |
| Scope (regulatory) | S3, S4 | Compliance verification; regulatory adaptation | Compliance Verification; Review and Adaptation |
| Scope (stakeholder) | S1, S2 | Contextual scoping; stakeholder consultation; ethical analysis | Pre-Assessment Phase; Risk Identification and Impact Evaluation |
| Scope (technological) | S5 | Adaptation to emerging technologies and big data analytics environments | Review and Adaptation |
| Challenge Code | PDCA Phase | Risk Management Domain | Operational Activity (Figure 4) |
|---|---|---|---|
| L1 | PLAN, CHECK, ACT | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Compliance Verification; Review & Adaptation | Articulation of processing activities (Define Scope) [PLAN] Aligning processing with business goals (Define Objectives) [PLAN] Stakeholder Engagement [PLAN] Risk Policy [PLAN] Legal Compliance Check [CHECK] Periodic Reviews [ACT] |
| L2 | PLAN, DO, CHECK, ACT | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Documentation & Reporting; Compliance Verification; Review and Adaptation | Articulation of processing activities (Define Scope) [PLAN] Consideration of technological context (Define Scope) [PLAN] Aligning processing with business goals (Define Objectives) [PLAN] Addressing business needs (Define Objectives) [PLAN] Risk Policy [PLAN] Comprehensive Documentation [DO] Transparent Reporting [DO] Legal Compliance Check [CHECK] Periodic Reviews [ACT] Emerging Technologies [ACT] |
| L3 | PLAN, CHECK, ACT | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Review and Adaptation | Consideration of technological context (Define Scope) [PLAN] Ensuring data minimisation (Define Objectives) [PLAN] Technical Feasibility [PLAN] Legal Compliance Check [CHECK] Emerging Technologies [ACT] |
| R1 | PLAN | Risk Identification and Impact Evaluation | Risk Policy [PLAN] Risk Analysis [PLAN] |
| R2 | PLAN, DO | Pre-Assessment Phase; Mitigation Strategies | Data Flow Mapping [PLAN] Cybersecurity Integration [DO] |
| R3 | PLAN, DO | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Mitigation Strategies | Assessing data quality and sources (Define Objectives) [PLAN] Risk Analysis [PLAN] Cybersecurity Integration [DO] |
| R4 | PLAN | Pre-Assessment Phase; Risk Identification and Impact Evaluation | Data Flow Mapping [PLAN] Risk Analysis [PLAN] |
| R5 | PLAN | Risk Identification and Impact Evaluation | Risk Analysis [PLAN] User Rights Impact Analysis [PLAN] |
| R6 | PLAN, CHECK | Risk Identification and Impact Evaluation; Continuous Monitoring | Risk Policy [PLAN] User Rights Impact Analysis [PLAN] Monitoring and Review [CHECK] |
| R7 | PLAN | Risk Identification and Impact Evaluation | Risk Analysis [PLAN] |
| C1 | PLAN, DO | Risk Identification and Impact Evaluation; Mitigation Strategies | Ethical Analysis [PLAN] Technical and Organisational Measures [DO] |
| C2 | DO | Mitigation Strategies | Technical and Organisational Measures [DO] Cybersecurity Integration [DO] |
| C3 | PLAN, DO | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Mitigation Strategies | Data Flow Mapping [PLAN] Risk Analysis [PLAN] Technical and Organisational Measures [DO] |
| C4 | PLAN | Pre-Assessment Phase; Risk Identification and Impact Evaluation | Addressing business needs (Define Objectives) [PLAN] Assessing data quality and sources (Define Objectives) [PLAN] Technical Feasibility [PLAN] |
| C5 | PLAN | Risk Identification and Impact Evaluation | Technical Feasibility [PLAN] |
| C6 | PLAN, CHECK | Risk Identification and Impact Evaluation; Compliance Verification | Fairness Assessment [PLAN] Ethical Analysis [PLAN] Fairness Validation [CHECK] |
| C7 | PLAN, DO | Pre-Assessment Phase; Mitigation Strategies | Data Flow Mapping [PLAN] Cybersecurity Integration [DO] |
| C8 | PLAN, DO, CHECK | Risk Identification & Impact Evaluation; Documentation & Reporting; Compliance Verification | Fairness Assessment [PLAN] User Rights Impact Analysis [PLAN] Transparent Reporting [DO] Fairness Validation [CHECK] |
| C9 | PLAN | Pre-Assessment Phase | Stakeholder Engagement [PLAN] |
| C10 | PLAN | Pre-Assessment Phase | Stakeholder Engagement [PLAN] |
| C11 | DO * | Mitigation Strategies * | Not directly annotated in Figure 4; addressed implicitly through Technical Feasibility and Technical and Organisational Measures (see note). |
| C12 | PLAN, DO, CHECK | Risk Identification and Impact Evaluation; Mitigation Strategies; Continuous Monitoring | Risk Policy [PLAN] Technical and Organisational Measures [DO] Monitoring and Review [CHECK] |
| C13 | DO, CHECK | Mitigation Strategies; Documentation and Reporting; Continuous Monitoring | Technical and Organisational Measures [DO] Comprehensive Documentation [DO] Monitoring and Review [CHECK] |
| C14 | ACT | Review and Adaptation | Periodic Reviews [ACT] Emerging Technologies [ACT] |
| C15 | PLAN, DO | Risk Identification & Impact Evaluation; Documentation & Reporting | Risk Policy [PLAN] Comprehensive Documentation [DO] Transparent Reporting [DO] |
| S1 | PLAN, CHECK | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Compliance Verification | Stakeholder Engagement [PLAN] Fairness Assessment [PLAN] Ethical Analysis [PLAN] Fairness Validation [CHECK] |
| S2 | PLAN | Risk Identification and Impact Evaluation | Ethical Analysis [PLAN] |
| S3 | PLAN, CHECK, ACT | Pre-Assessment Phase; Risk Identification and Impact Evaluation; Compliance Verification; Review and Adaptation | Ensuring data minimisation (Define Objectives) [PLAN] Fairness Assessment [PLAN] Fairness Validation [CHECK] Emerging Technologies [ACT] |
| S4 | PLAN, DO | Risk Identification & Impact Evaluation; Documentation & Reporting | Ethical Analysis [PLAN] Transparent Reporting [DO] |
| S5 | ACT | Review and Adaptation | Emerging Technologies [ACT] |
Appendix C. Illustrative Application of the Proposed Framework: AI-Based Recruitment Screening and Ranking
| No. | WP248rev.01 Criterion | Legal Reference | AI Recruitment System—Case-Specific Justification | DPIA Required? |
|---|---|---|---|---|
| 1 | Systematic and extensive profiling or automated decision-making with legal or similarly significant effects on individuals. | GDPR Art. 35(3)(a) | The ML system produces a ranked candidate shortlist that determines access to employment interviews. Shortlisting outcomes have direct and significant effects on individuals’ access to employment. | YES—mandatory DPIA. |
| 2 | Large-scale processing of special categories of personal data (Art. 9) or criminal offence data (Art. 10). | GDPR Art. 35(3)(b) | Demographic data (ethnicity, disability status) is processed for fairness monitoring and held in a segregated data environment. Data covers all applicants across the organisation. | YES—mandatory DPIA. |
| 3 | Systematic monitoring of a publicly accessible area on a large scale. | GDPR Art. 35(3)(c) | Not applicable. The system processes CV data submitted by applicants; no public-area monitoring is involved. | NO. |
| 4 | Data concerning vulnerable data subjects who may be less able to freely consent or object. | WP248rev.01, Criterion 7 | Candidates from non-traditional educational routes (apprenticeships, part-time degrees) were identified during stakeholder consultation as potentially vulnerable to algorithmic disadvantage. | YES—combined with No. 1, triggers DPIA. |
| 5 | Innovative or novel use of new technologies or organisational solutions. | GDPR Art. 35(1); WP248rev.01, Criterion 8 | The ML-based CV ranking pipeline is a novel deployment with no prior use in the organisation’s recruitment process. | YES—combined with No. 1, triggers DPIA. |
| 6 | Combining or matching data sets from two or more processing operations carried out for different purposes. | WP248rev.01, Criterion 6 | Historical shortlisting records (ten years) are combined with current CV submissions and fairness-monitoring demographic data from a segregated store. | YES—combined with No. 1, triggers DPIA. |
| 7 | Processing that prevents data subjects from exercising a right or using a service or entering into a contract. | WP248rev.01 Criterion 9 | A negative shortlisting outcome directly prevents candidates from accessing an employment opportunity, with potential financial and social consequences. | YES—mandatory DPIA. |
| DECISION | Two or more criteria satisfied. Criteria No. 1, 2, 4, 5, 6 and 7 are engaged. | GDPR [6] Art. 35(1); WP248rev.01, Section III.B.a | All applicable criteria confirm that a DPIA is mandatory prior to deployment of the AI recruitment screening system. | DPIA MANDATORY. |
| Business Process | Data Type | Data Owner | Shared Party (3rd Party) | Retention Period | Confidentiality (C) | Integrity (I) | Availability (A) | Risk Value | Lawful Basis (GDPR Art. 6) | AI Act Classification |
|---|---|---|---|---|---|---|---|---|---|---|
| CV Screening and Ranking | CV Text, Employment History | HR Technology | ATS Provider | During processing | High | High | Medium | High | Art. 6(1)(b)—Performance of contract (recruitment); Art. 6(1)(f)—Legitimate interest (fair hiring). | High-Risk AI System—Annex III, Point 4 (Employment and workers management). |
| Fairness Monitoring | Demographic Data (Gender, Ethnicity) | Monitoring Team | Not Shared | During monitoring | Very High | High | Low | Critical | Art. 5(1)(d) accuracy); Art. 6(1)(f)—Legitimate interest (fairness compliance), Art. 9(2) (where applicable for special category data). | Not an AI system—human-led monitoring process using demographic statistics only. |
| Service Code | Controller (Client) Details | DPO Contact (Processor) | Categories of Processing | Third-Country Transfers | Security Measures (TOMs) |
|---|---|---|---|---|---|
| SRV-ATS-01 | Professional Services Organisation (3500 employees)—HR Technology Function. DPO: [Organisation DPO contact details]. | dpo@ats-provider.eu | Applicant Tracking System: CV ingestion, storage, routing to ML ranking engine, delivery of ranked shortlists to HR managers. Access logging and retention scheduling. | Remediated: processing initially routed through non-EEA infrastructure. Following the pre-deployment audit, the provider agreed to restrict all processing to EEA infrastructure. No third-country transfers remained following remediation, eliminating the need for SCCs. | ISO/IEC 27001:2022 certified. AES-256 encryption at rest (remediated). Role-based access controls (RBACs). Access logs retained per ISMS requirements. |
| SRV-ML-01 | Professional Services Organisation (3500 employees)—HR Technology Function. DPO: [Organisation DPO contact details]. | dpo@ml-vendor.eu | ML model training on historical shortlisting data, fairness re-weighting, SHAP-based explainability layer generation, model inference for candidate scoring. | No third-country transfers. All processing within EEA. | Pseudonymisation of CV pipeline inputs. Demographic data technically isolated from inference pipeline. Automated deletion workflows for unsuccessful candidates. |
| Processor/Partner | GDPR Role | DPA (Art. 28) Status | Destination Country | Transfer Mechanism | TIA Status | Supplementary Safeguards |
|---|---|---|---|---|---|---|
| ATS Provider | Data Processor | DPA executed following pre-deployment audit finding; signed prior to go-live. | EEA (post-remediation). Original undisclosed destination: non-EEA third country. | Not applicable following remediation, as restricting processing to EEA infrastructure eliminated the need for a Chapter V transfer mechanism. | Not required following remediation, as no third-country transfers remained. | Contractual obligation on provider to notify any future infrastructure change outside EEA within 5 business days. |
| ML Vendor | Data Processor | DPA executed at contract signature. | EEA—no third-country transfer. | Not applicable. | Not required. | Model artefacts and training data held on EEA infrastructure under Role-Based Access Controls (RBACs). |
| Fairness Adviser | Independent Data Controller/Data Recipient | Data Sharing Agreement covering aggregate fairness statistics only. No individual-level data shared. | EEA. | Not applicable—aggregate statistics only; no personal data transferred. | Not required. | Adviser accesses aggregate outputs only; no access to candidate-level or demographic data. |
| Stakeholder Group | Identified Concern/Finding | Applied Mitigation/Control Action | Challenge Code/Reference | Accountability/Ownership |
|---|---|---|---|---|
| Employee Resource Groups | Educational route disadvantage due to reliance on degree classification and university prestige, including potential proxy discrimination arising from historical training data (Calvi & Kotzinos [32]). | Application of re-weighting techniques to reduce the influence of university prestige and degree classification in the training dataset. | C6—Algorithmic bias via feature weighting; S2—Structural disadvantage. | ML Engineer; DPO. |
| Employee Resource Groups/External Ethics Adviser | Explainability of shortlisting decisions and risks of automation bias and candidates’ ability to meaningfully contest AI-assisted decisions (Lazcoz et al. [51]; Janssen et al. [36]). | Deployment of SHAP value attribution; displaying candidates in alphabetical order; conducting HR manager training. | C9—Explainability; S1—Automation bias risk. | Head of HR Technology; ML Engineer. |
| External Ethics Adviser | Disadvantage for candidates with non-standard CV formats due to feature extraction pipeline calibration, potentially affecting data quality and representativeness (Calvi & Kotzinos [32]). | Interface redesign incorporated into the provider’s scope of work. | C3—Data quality; S3—Input normalisation. | ATS Provider; HR Technology Lead. |
| Risk ID | Identified Risk | Domain/Regulatory Context | Likelihood | Impact | Overall Risk Level | Inherent Risk Level | Residual Risk Level | Treatment Status |
|---|---|---|---|---|---|---|---|---|
| R01 | Proxy discrimination based on historical shortlisting data including risks arising from insufficiently representative training data (Calvi & Kotzinos [32]) | Algorithmic Fairness, EU AI Act | High | High | Critical | Critical—no controls in place at assessment date. | Low—post fairness re-weighting and quarterly audit. | Treated. Re-weighting applied; quarterly fairness audit ongoing. |
| R02 | Opacity of the scoring process making GDPR [6] compliance difficult, limiting meaningful explanation and contestability of AI-assisted decisions (Lazcoz et al. [51]; Calvi & Kotzinos [32]). | GDPR [6] Articles 13, 14, 15 and 22 | High | Medium-High | High | High—no explainability mechanism at assessment date. | Low—post SHAP deployment and explainability portal. | Treated. SHAP deployed; candidate portal live. |
| R03 | Data quality risk arising from structurally heterogeneous CV data. | GDPR [6] Article 5(1)(d) | Medium | Medium | Medium | Medium—heterogeneous CV formats degrading feature extraction. | Low—post interface redesign. | Treated. CV interface redesign completed pre-go-live. |
| R04 | Re-identification risk associated with demographic attributes collected for monitoring. | GDPR [6] Articles 25 and 32 | Low | High | Medium | Medium—demographic attributes accessible to monitoring environment prior to technical isolation. | Very Low—post technical isolation control and role-based access restrictions. | Treated. Demographic data technically isolated from inference pipeline; access restricted to authorised monitoring personnel. |
| Regulatory Framework | Specific Requirement/Right | System Feature/Operational Safeguard | Evidence Artefact | Verification Criterion |
|---|---|---|---|---|
| GDPR [6] Article 22 | Protection against automated individual decision-making. | Ranked list requires human recruiter review and approval before any rejection (Human-in-the-loop). | HR manager shortlist approval log; system audit trail. | 100% of shortlists reviewed by HR manager before any rejection; zero automated rejections without human sign-off. |
| EU AI Act [7] | Post-market monitoring requirements for high-risk AI systems. | Implementation of quarterly audits using live shortlisting data and an automated threshold-based alerting system. | Q1 and Q2 fairness audit reports; automated alerting system log. | Quarterly audit cycle completed on schedule; threshold alerts triggered within 24 h of breach. |
| GDPR [6] Articles 13-14 | Right to be informed. | Publication of a public-facing summary on the careers portal and revision of candidate-facing language. | Careers portal privacy notice (revised); candidate-facing summary published. | Privacy notice reviewed annually; accessibility and accuracy verified by legal counsel (Janssen et al. [36]). |
| FRIA Element (Art. 27(1)) | Legal Basis | Assessment Question | Implemented Measure | Review Frequency |
|---|---|---|---|---|
| Deployment process and intended purpose | AI Act [7] Art. 27(1)(a); Art. 13 | How will the high-risk AI system be used, and does its use align with the provider’s documented intended purpose? | System deployed as a candidate ranking tool for interview shortlisting, consistent with provider’s Art. 13 instructions for use. HR manager review required before any rejection is applied (human-in-the-loop). | At each deployment scope change. |
| Period and frequency of use | AI Act [7] Art. 27(1)(b) | For how long and how frequently will the system operate, and are processing volumes proportionate to the stated purpose? | System operates continuously during active recruitment cycles. Volumes are proportionate to organisational hiring needs. Quarterly fairness audits are scheduled throughout the operational period. | Annually. |
| Categories of persons and groups likely to be affected | AI Act [7] Art. 27(1)(c) | Which individuals and groups are affected by the system, including those at particular risk of algorithmic disadvantage? | All external applicants. At-risk groups identified: candidates from non-traditional educational routes, female candidates (demographic parity monitoring), candidates from underrepresented ethnic backgrounds (equal opportunity monitoring). Intersectional analysis commissioned to identify potential compound disadvantage affecting individuals belonging to multiple protected groups (Calvi [53]; Janssen et al. [36]). | Following each quarterly audit. |
| Specific risks of harm to fundamental rights | AI Act [7] Art. 27(1)(d) | What are the specific risks of harm to non-discrimination, dignity, and access to legal remedy posed by the AI system? | R01: Proxy discrimination via institutional prestige weighting and insufficiently representative training data (Calvi & Kotzinos [32])—mitigated by fairness re-weighting (Table A9, Table A12 and Table A15. Table A9 records re-weighting as a processing activity the vendor performs, whereas Table A15 frames it as an applied mitigation measure with an effectiveness KPI and residual-risk score, and A12 records the residual risk. R02: Opacity of scoring undermining Art. 22 rights—mitigated by SHAP explainability. R04: Re-identification of demographic attributes—mitigated by technical data isolation. Residual risk documented in Risk Register (Table A12). | Quarterly—aligned with fairness audit cycle. |
| Human oversight measures | AI Act [7] Art. 27(1)(e); Art. 26(2); GDPR [6] Art. 22 | Who is responsible for oversight, do they have authority to override AI outputs, and have they received appropriate training? | Human recruiter reviews and approves ranked list before any rejection. Alphabetical candidate presentation reduces anchoring bias. HR manager training completed pre-go-live. DPO notified immediately on threshold breach; automated shortlisting suspended for affected role pending investigation (Table A12). | Pre-deployment + annually. |
| Measures upon risk materialisation and complaint mechanism | AI Act [7] Art. 27(1)(f); Art. 86; GDPR [6] Art. 22(3) | What actions are taken if a risk materialises, and how can affected candidates seek remedy? | Escalation: automated threshold alert to DPO, Head of HR Technology, and ML Engineer simultaneously; automated processing suspension for affected role category. SHAP-based portal assists candidates to exercise their rights under GDPR [6] Art. 22(3) by providing meaningful information about the factors influencing the AI-assisted ranking. Complaint route published on careers portal. Governance log maintained (Table A13). | Annually + post-incident. |
| Targeted Risk | Applied Technical and Organisational Measure (TOM) | Responsible Function | Status | Implementation Timing | Effectiveness KPI | Residual Risk Score |
|---|---|---|---|---|---|---|
| R01 | Application of re-weighting techniques to the training dataset to reduce the influence of university prestige. | ML Engineer | Completed | Pre-deployment—completed prior to go-live. | Demographic parity ratio ≥ 0.80 across all role categories; confirmed in Q1 fairness audit. | Low. Residual proxy discrimination risk managed through quarterly audit cycle. |
| R01, R04 | Isolation of demographic attributes in a dedicated data store with role-based access control. | Data Architect/HR | Completed | Pre-deployment—completed prior to go-live. | Zero unauthorised access events; RBACs verified in Q1 security review. | Very Low. Re-identification risk effectively controlled by technical isolation. |
| R02 | Deployment of a SHAP-based explainability layer connected to a candidate-facing portal. | ML Engineer/Legal Counsel | Completed | Pre-deployment—completed prior to go-live. | 100% of shortlisting decisions accompanied by SHAP-based explanation accessible via candidate portal. | Low. Residual opacity risk for complex multi-feature interactions managed through DPO review. |
| Security | Remediation of outdated encryption at rest algorithms for CV data. | Information Security Team | Completed | Pre-deployment—remediated within 30-day window following pre-deployment audit finding. | AES-256 encryption verified by Information Security Team; confirmed in Q1 security audit. | Very Low. Encryption standard meets ISO/IEC 27001 requirements; no residual risk identified. |
| R03 | Standardisation of CV submission format through structured application templates and interface redesign to improve feature extraction quality. | ATS Provider / HR Technology Lead | Completed | Pre-deployment—completed prior to go-live. | ≥95% successful feature extraction rate; no material parsing errors identified during Q1 validation. | Low. Residual data quality risk managed through periodic validation of CV parsing performance. |
| Evaluation Metric | Pre-Deployment (Sandbox) | Q1 Audit (Live) | Q2 Audit (Distribution Shift) | Remediation Action (ACT Phase) | Acceptable Threshold | Escalation Trigger |
|---|---|---|---|---|---|---|
| Demographic Parity | Potential disparities observed but addressed via re-weighting. | Within acceptable ranges. | Disparities affecting candidates from underrepresented ethnic backgrounds for technology roles. | Automated shortlisting suspended; manual shortlisting implemented temporarily. | Demographic parity ratio ≥ 0.80 (4/5ths rule; EEOC standard). | Ratio < 0.75 in any role category or across the overall shortlist. |
| Equal Opportunity | Differences initially observed, subsequently mitigated. | Within acceptable ranges. | Within acceptable ranges. | Model feature weighting recalibrated using a supplementary dataset. Model performance revalidated using updated fairness metrics before redeployment. | Equal opportunity difference ≤ 0.05 between protected and reference groups. | Difference > 0.08 sustained across two consecutive audit periods. |
| Equalised Odds | Maintained within acceptable ranges. | Consistent with pre-deployment. | Consistent with pre-deployment. | Continuous monitoring maintained. | Equalised odds difference ≤ 0.05 across protected and reference groups. | Difference > 0.10 in any single audit period. |
| Phase/Date | Identified Incident/Finding | Corrective and Preventive Action (CAPA) | Lessons Learned | Policy/Control Update | Governance Decision |
|---|---|---|---|---|---|
| Q2 Audit (Live) | Distribution shift causing disparities for candidates from underrepresented ethnic backgrounds in technology roles. | Automated shortlisting suspended; manual shortlisting implemented; model recalibrated using a supplementary dataset. | Distribution shift in low-volume niche roles is not detected by existing demographic parity thresholds; role-category volume must be a separate monitoring dimension. Continuous monitoring should also account for changes in data distributions over time (Pandit [31]). | Monitoring protocol updated to include role-category volume thresholds; supplementary training dataset sourced for technology roles. | Steering committee approved temporary manual shortlisting for technology roles; model recalibration signed off by DPO before reinstatement. |
| Annual Review | Proposal for a Natural Language Processing (NLP) module to analyse unstructured cover letter text. | NLP module deferred pending a supplementary DPIA specifically covering inferential detection risks. | Novel inferential risks from unstructured text require a separate DPIA before any expansion of the feature set beyond structured CV data. Significant modifications to high-risk AI systems should prompt a renewed DPIA before deployment (Georgiadis & Poels [3]). | DPIA pre-approval policy formalised as a mandatory gate for all future feature additions to the ML pipeline. | Steering committee deferred NLP module pending supplementary DPIA; DPO scheduled assessment within 60 days. |
| Annual Review | Need for intersectional fairness metrics not captured by existing tools. | Fairness adviser commissioned to design an intersectional analysis for future audit protocols. | Single-axis fairness metrics are insufficient for detecting compound disadvantage; intersectional analysis must be built into the audit protocol from the outset. Intersectional discrimination may remain undetected where fairness monitoring relies solely on single-axis metrics (Calvi [53]). | Fairness audit protocol updated to include intersectional analysis from Q3 audit cycle onwards; fairness audit methodology updated to incorporate intersectional fairness assessment. | Steering committee approved commissioning of external fairness adviser to design the intersectional analysis methodology; approved implementation of the revised fairness monitoring methodology for future audit cycles. |
References
- Brunswicker, S.; Bertino, E.; Soein, M. Big Data for Open Digital Innovation—A Research Roadmap. Big Data Res. 2015, 2, 53–58. [Google Scholar] [CrossRef]
- Hönigsberg, S.; Manhai Li, M.; Korneeva, E.; Wache, H.; Dinter, B. The impact of digital platform introduction on business models in SMEs—The interplay of efficiency and innovation orientation. J. Strateg. Inf. Syst. 2026, 35, 101967. [Google Scholar] [CrossRef]
- Georgiadis, G.; Poels, G. Towards a privacy impact assessment methodology to support the requirements of the general data protection regulation in a big data analytics context: A systematic literature review. Comput. Law Secur. Rev. 2022, 44, 105640. [Google Scholar] [CrossRef]
- Tikkinen-Piri, C.; Rohunen, A.; Markkula, J. EU General Data Protection Regulation: Changes and implications for personal data collecting companies. Comput. Law Secur. Rev. 2018, 34, 134–153. [Google Scholar] [CrossRef]
- Guillaume, O. Digitalisation, Safety and Privacy. In Safety in the Digital Age; Springer Briefs in Applied Sciences and Technology; Le Coze, J.C., Antonsen, S., Eds.; Springer: Cham, Switzerland, 2023. [Google Scholar] [CrossRef]
- European Union. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (General Data Protection Regulation). Official Journal of the European Union. 2016. Available online: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:32016R0679 (accessed on 15 April 2026).
- European Union. Regulation (EU) 2024/1689 Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024. Available online: https://eur-lex.europa.eu/eli/reg/2024/1689/oj (accessed on 12 January 2026).
- Neubauer, A.; Wynn, M.; Bown, R. AI, Authorship, Copyright, and Human Originality. Encyclopedia 2026, 6, 9. [Google Scholar] [CrossRef]
- Rintamäki, T.; Golpayegani, D.; Lewis, D.; Celeste, E.; Pandit, H.J. Impact assessment requirements in the GDPR vs the AI Act: Overlaps, divergence, and implications. Comput. Law Secur. Rev. 2026, 61, 106317. [Google Scholar] [CrossRef]
- Clarke, R. Privacy impact assessment: Its origins and development. Comput. Law Secur. Rev. 2009, 25, 123–135. [Google Scholar] [CrossRef]
- Information Commissioner’s Office. Conducting Privacy Impact Assessments Code of Practice. 2014. Available online: https://www.privacy-advocaat.nl/public/documents/184/ico-pia-code-of-practice.pdf (accessed on 16 March 2026).
- Article 29 Data Protection Working Party. Guidelines on Data Protection Impact Assessment (DPIA) and Determining Whether Processing Is “Likely to Result in a High Risk” for the Purposes of Regulation 2016/679. 2017. Available online: https://ec.europa.eu/newsroom/article29/items/611236/en (accessed on 11 February 2026).
- Hansen, M.; Runge, G.; Gruschka, N.; Jensen, M. Illuminating the DPIA Blackbox—A Survey of Data Protection Impact Assessment Practices in Organisations. In Privacy Technologies and Policy. APF 2025. Lecture Notes in Computer Science; Arastouei, N., Jensen, M., Rannenberg, K., Eds.; Springer: Cham, Switzerland, 2026; Volume 16183, p. 8. [Google Scholar] [CrossRef]
- ISO/IEC 27701:2025; International Organization for Standardization, Information Security, Cybersecurity and Privacy Protection. Privacy Information Management Systems. Requirements and Guidance. International Organization for Standardization: Geneva, Switzerland, 2025. Available online: https://www.iso.org/standard/27701 (accessed on 12 January 2026).
- Flick, U.; von Kardoff, E.; Steinke, I.; Jenner, B. A Companion to Qualitative Research; SAGE Publications: Thousand Oaks, CA, USA, 2004; Available online: https://books.google.com.tr/books?id=F6O-Ru4Ag1IC (accessed on 15 January 2026).
- Thomas, D.R. A General Inductive Approach for Analyzing Qualitative Evaluation Data. Am. J. Eval. 2006, 27, 237–246. [Google Scholar] [CrossRef]
- Saunders, M.; Lewis, P.; Thornhill, A. Research Methods for Business Students; Pearson: New York, NY, USA, 2019; Available online: https://www.scirp.org/reference/referencespapers?referenceid=2907709 (accessed on 24 December 2025).
- Page, M.J.; McKenzie, J.E.; Bossuyt, P.M.; Boutron, I.; Hoffmann, T.C.; Mulrow, C.D.; Shamseer, L.; Tetzlaff, J.M.; Akl, E.A.; Brennan, S.E.; et al. The PRISMA 2020 statement: An updated guideline for reporting systematic reviews. BMJ 2021, 372, n71. [Google Scholar] [CrossRef] [PubMed]
- Diepenbrock, S.S.A. Towards a Conceptual Framework for Data Protection Impact Assessments of Smart City Data Ecosystems. In Proceedings of the 2025 IEEE European Technology and Engineering Management Summit, Bruges, Belgium, 26–28 May 2025; Available online: https://www.researchgate.net/publication/392228520_Towards_a_Conceptual_Framework_for_Data_Protection_Impact_Assessments_of_Smart_City_Data_Ecosystems (accessed on 23 September 2025).
- Kitchenham, B.; Charters, S. Guidelines for Performing Systematic Literature Reviews in Software Engineering; Keele University, Keele, UK; University of Durham: Durham, UK, 2007; Available online: https://www.researchgate.net/publication/302924724_Guidelines_for_performing_Systematic_Literature_Reviews_in_Software_Engineering (accessed on 19 October 2025).
- Petersen, K.; Vakkalanka, S.; Kuzniarz, L. Guidelines for conducting systematic mapping studies in software engineering: An update. Inf. Softw. Technol. 2015, 64, 1–18. [Google Scholar] [CrossRef]
- Mbozi, P.; Ratcliff, C.; Roberts, D. Critical Appraisal Skills Programme (CASP) Systematic Review Checklist. 2018. Available online: https://casp-uk.net/wp-content/uploads/2018/03/CASP-Systematic-Review-Checklist-2018_fillable-form.pdf (accessed on 13 March 2026).
- ISO/IEC 29134:2023; Guidelines for Privacy Impact Assessment. International Organization for Standardization: Geneva, Switzerland, 2023. Available online: https://www.iso.org/standard/86012.html (accessed on 12 April 2026).
- Huberman, A.; Miles, M.; Ritchie, J.; Spencer, L. Qualitative Data Analysis for Applied Policy Research; Sage: Thousand Oaks, CA, USA, 2022. [Google Scholar] [CrossRef]
- Gale, N.K.; Heath, G.; Cameron, E.; Rashid, S.; Redwood, S. Using the framework method for the analysis of qualitative data in multi-disciplinary health research. BMC Med. Res. Methodol. 2013, 13, 117. [Google Scholar] [CrossRef] [PubMed]
- Goldsmith, L.J. Using Framework Analysis in Applied Qualitative Research. Qual. Rep. 2021, 26, 2061–2076. [Google Scholar] [CrossRef]
- Jabareen, Y. Building a Conceptual Framework: Philosophy, Definitions, and Procedure. Int. J. Qual. Methods 2009, 8, 49–62. [Google Scholar] [CrossRef]
- ISO 31000:2018; Risk Management—Guidelines. International Organization for Standardization: Geneva, Switzerland, 2018. Available online: https://www.iso.org/standard/65694.html (accessed on 15 March 2026).
- Henriksen-Bulmer, J.; Faily, S.; Jeary, S. DPIA in Context: Applying DPIA to Assess Privacy Risks of Cyber Physical Systems. Future Internet 2020, 12, 93. [Google Scholar] [CrossRef]
- Grammatopoulos, A.; Stylianou, I.; Barud, K.; Saillant, C.; Politis, I. TRUSTEE’s Framework for DPIAs: Safeguarding personal information in the Digital Era. In Proceedings of the 2023 IEEE 28th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks, Edinburgh, UK, 6–8 November 2023. [Google Scholar] [CrossRef]
- Pandit, H. A Semantic Specification for Data Protection Impact Assessments (DPIA). In Towards a Knowledge-Aware AI. Studies on the Semantic Web; Ebook; IOS Press: Amsterdam, The Netherlands, 2022; Volume 55, pp. 36–50. [Google Scholar] [CrossRef]
- Calvi, A.; Kotzinos, D. Enhancing AI fairness through impact assessment in the European Union: A legal and computer science perspective. In Proceedings of the 2023 ACM Conference on Fairness, Accountability, and Transparency, Chicago, IL, USA, 12–15 June 2023. [Google Scholar] [CrossRef]
- Rehak, R.; Kuhne, C. The Processing goes far beyond “the app”—Privacy issues of decentralized Digital Contact Tracing using the example of the German Corona-Warn-App. In Proceedings of the 2022 6th International Conference on Cryptography, Security and Privacy, Tianjin, China, 14–16 January 2022. [Google Scholar] [CrossRef]
- Leesakul, N.; Morisset, C. Position Paper: The role of law in achieving privacy and security measures in smart buildings from the GDPR context. In Proceedings of the 2023 IEEE European Symposium on Security and Privacy Workshops, Delft, The Netherlands, 3–7 July 2023. [Google Scholar] [CrossRef]
- Papamartzivanos, D.; Menesidou, S.; Gouvas, P.; Giannetsos, T. A Perfect Match: Converging and Automating Privacy and Security Impact Assessment On-the-Fly. Future Internet 2021, 13, 30. [Google Scholar] [CrossRef]
- Janssen, H.; Seng Ah Lee, M.; Singh, J. Practical fundamental rights impact assessments. Int. J. Law Inf. Technol. 2022, 30, 200–232. [Google Scholar] [CrossRef]
- Moniz, G.C. DPIAs’ role in fundamental rights governance. Inf. Commun. Technol. Law 2026, 35, 1–20. [Google Scholar] [CrossRef]
- Campanile, L.; Iacono, M.; Marulli, F.; Mastroianni, M. Designing a GDPR compliant blockchain-based IoV distributed information tracking system. Inf. Process. Manag. 2021, 58, 102511. [Google Scholar] [CrossRef]
- López, C.T.; Domingo, I.A.; Torrijos, J.V. Approaching the Data Protection Impact Assessment as a legal methodology to evaluate the degree of privacy by design achieved in technological proposals. A special reference to Identity Management systems. In Proceedings of the 16th International Conference on Availability, Reliability and Security, Vienna, Austria, 17–20 August 2021. [Google Scholar] [CrossRef]
- Georgiadis, G.; Poels, G. Establishing a Comprehensive Data Protection Impact Assessment Methodology for Big Data Analytics in Compliance with the General Data Protection Regulation. Inf. Syst. E-Bus. Manag. 2025, 24, 87–132. [Google Scholar] [CrossRef] [PubMed]
- Mantelero, A. AI and Big Data: A blueprint for a human rights, social and ethical impact assessment. Comput. Law Secur. Rev. 2018, 34, 754–772. [Google Scholar] [CrossRef]
- Bisztray, T.; Gruschka, N.; Mavroeidis, V.; Fritsch, L. Data Protection Impact Assessment in Identity Control Management with a Focus on Biometrics; Gesellschaft für Informatik e.V.: Bonn, Germany, 2020; Available online: https://www.researchgate.net/publication/342304096_Data_Protection_Impact_Assessment_in_Identity_Control_Management_with_a_Focus_on_Biometrics (accessed on 12 February 2026).
- Gültekin-Várkonyi, G. Navigating data governance risks: Facial recognition in law enforcement under EU legislation. Internet Policy Rev. 2024, 13, 1–36. [Google Scholar] [CrossRef]
- Riemann, L.T.; Hähner, F.P.S.; Schmitz, A.-K.; Ataian, M.; Jaster, M.; Ückert, F. An Open-Source Software Tool to Facilitate Data Protection Impact Assessments. Appl. Sci. 2023, 13, 11230. [Google Scholar] [CrossRef]
- Wright, D.; Hert, P. Privacy Impact Assessment; Springer: Berlin/Heidelberg, Germany, 2012. [Google Scholar] [CrossRef]
- Johnson, R.; Onwuegbuzie, A. Mixed Methods Research: A Research Paradigm Whose Time Has Come. Educ. Res. 2004, 33, 14. [Google Scholar] [CrossRef]
- Vemou, K.; Karyda, M. Evaluating privacy impact assessment methods: Guidelines and best practice. Inf. Comput. Secur. 2019, 28, 35–53. [Google Scholar] [CrossRef]
- Bryman, A. Integrating Quantitative and Qualitative Research: How Is It Done? Qual. Res. 2006, 6, 97–113. [Google Scholar] [CrossRef]
- Bieker, F.; Friedewald, M.; Hansen, M.; Obersteller, H.; Rost, M. A Process for Data Protection Impact Assessment under the European General Data Protection Regulation. In Annual Privacy Forum; Springer: Cham, Switzerland, 2016; Available online: https://www.researchgate.net/publication/319276698_A_Process_for_Data_Protection_Impact_Assessment_under_the_European_General_Data_Protection_Regulation (accessed on 23 April 2026).
- Campanile, L.; Iacono, M.; Marulli, F.; Mastroianni, M. Privacy Regulations Challenges on Data-centric and IoT Systems: A Case Study for Smart Vehicles. In IoTBDS; SciTePress: Setúbal, Portugal, 2020. [Google Scholar] [CrossRef]
- Lazcoz, G.; Maiora, J.; de Miguel, Í.; Sanz, B. Regulating AI-Driven Triage: Fundamental Rights and Compliance Challenges in the European Union. AI 2026, 7, 86. [Google Scholar] [CrossRef]
- Kasirzadeh, A.; Clifford, D. Fairness and Data Protection Impact Assessments. In Proceedings of the 2021 AAAI/ACM Conference on AI, Ethics, and Society, Virtual Event, 19–21 May 2021. [Google Scholar] [CrossRef]
- Calvi, A. Gender, data protection & the smart city: Exploring the role of DPIA in achieving equality goals. Eur. J. Spat. Dev. 2022, 19, 24–47. [Google Scholar] [CrossRef]
- Jong, B.; Gaye, B.; Luyten, J.; Buitenen, B.; André, E.; Meehan, C.; O’Siochain, C.; Tomsu, K.; Urbain, J.; Peeters Grietens, K.; et al. Ethical Considerations for Movement Mapping to Identify Disease Transmission Hotspots. Emerg. Infect. Dis. 2019, 25, e181421. [Google Scholar] [CrossRef] [PubMed]
- Mittelstadt, B.; Allo, P.; Taddeo, M.; Wachter, S.; Floridi, L. The Ethics of Algorithms: Mapping the Debate. Big Data Soc. 2016, 3, 2053951716679679. [Google Scholar] [CrossRef]
- Binns, R. Fairness in Machine Learning: Lessons from Political Philosophy. In Proceedings of the Conference on Fairness, Accountability and Transparency, New York, NY, USA, 23–24 February 2018; Available online: https://proceedings.mlr.press/v81/binns18a.html (accessed on 29 January 2026).
- Custers, B.; Dechesne, F.; Sears, A.M.; Tani, T.; van der Hof, S. A comparison of data protection legislation and policies across the EU. Comput. Law Secur. Rev. 2018, 34, 234–243. [Google Scholar] [CrossRef]
- ISO/IEC 27001; International Organization for Standardization, Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements. International Organization for Standardization: Geneva, Switzerland, 2022. Available online: https://www.iso.org/standard/27001 (accessed on 12 May 2026).
- Irish Data Protection Commission. Data Protection Impact Assessments. Available online: https://www.dataprotection.ie/en/organisations/know-your-obligations/data-protection-impact-assessments (accessed on 11 May 2026).
- Information Commissioner’s Office. What is a DPIA? 2022. Available online: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/what-is-a-dpia/ (accessed on 10 May 2026).
- National Commission on Informatics and Liberty. Carrying Out a Data Protection Impact Assessment when Necessary. 2023. Available online: https://www.cnil.fr/en/carrying-out-protection-impact-assessment-if-necessary (accessed on 12 May 2026).
- Personal Data Protection Commission Singapore. Guide to Data Protection Impact Assessments. 2021. Available online: https://www.pdpc.gov.sg/organisations/resources/guidance-by-topic/guide-to-data-protection-impact-assessments (accessed on 15 May 2026).
- Office of the Privacy Commissioner of Canada. Expectations: OPC’s Guide to the Privacy Impact Assessment Process. Available online: https://www.priv.gc.ca/en/privacy-topics/federal-government-privacy/privacy-impact-assessments/gd_exp_202003/ (accessed on 15 May 2026).
- Information Commissioner’s Office. Sample DPIA Template. 2018. Available online: https://ico.org.uk/media2/migrated/2553993/dpia-template.docx (accessed on 15 May 2026).
- Nissenbaum, H. Privacy as Contextual Integrity. Wash. Law Rev. 2004, 79, 119. Available online: https://nissenbaum.tech.cornell.edu/papers/H.%20Nissenbaum,%20_Privacy%20as%20Contextual%20Integrity.pdf (accessed on 12 January 2026).
- UK-Government. Research and Analysis Cyber Security Risks to Artificial Intelligence. 2024. Available online: https://www.gov.uk/government/publications/research-on-the-cyber-security-of-ai/cyber-security-risks-to-artificial-intelligence (accessed on 17 February 2026).
- European Union Agency for Network and Information Security. Guideline on Security Measures Under the EECC. 2021. Available online: https://www.enisa.europa.eu/publications/guideline-on-security-measures-under-the-eecc (accessed on 27 May 2026).
- Richter, H. Looking at the Data Governance Act and Beyond: How to Better Integrate Data Intermediaries in the Market Order for Data Sharing. GRUR Int. 2023, 72, 458–470. [Google Scholar] [CrossRef]
- ISO/IEC 27002; Information Security, Cybersecurity and Privacy Protection—Information Security Controls. International Organization for Standardization: Geneva, Switzerland, 2022. Available online: https://www.iso.org/standard/75652.html (accessed on 24 June 2026).
- Metin, B.; Erkan, S.; Atasu, İ.; Yılmaz, E. Privacy Impact Assessment as a Tool for GDPR Compliance Preparation. Kişisel Verileri Koruma Derg. 2019, 1, 75–86. Available online: https://dergipark.org.tr/en/download/article-file/904860 (accessed on 13 April 2026).





| Criteria | Principle |
|---|---|
| Inclusion |
|
| Exclusion |
|
| Rintamäki et al. [9] Calvi and Kotzinos [32] Bisztray et al. [42] Campanile et al. [50] |
| Leesakul and Morisset [34] Henriksen-Bulmer et al. [29] Gültekin-Várkonyi [43] |
| Lazcoz et al. [51] Hansen et al. [13] Grammatopoulos et al. [30] Rehak and Kuhne [33] López et al. [39] Kasirzadeh and Clifford [52] Campanile et al. [50] Papamartzivanos et al. [35] Vemou and Karyda [47] Riemann et al. [44] Pandit [31] Georgiadis and Poels [40] Moniz [37] |
| Calvi [53] Jong et al. [54] Janssen et al. [36] Georgiadis and Poels [3] |
| Table | Mapping Direction | Source of Evidence | Validity Dimension |
|---|---|---|---|
| Table A3 | Operational Activity → Literature source | Phase 1 SLR (25 reviewed studies and supplementary sources) | Inductive grounding |
| Table A4 | Operational Activity → Standard clause | ISO 31000:2018, ISO/IEC 27701:2025, ISO/IEC 29134:2023 | Deductive grounding |
| Table A5 | Challenge category → Risk Management Domain | Phase 1 challenge taxonomy | Convergent construct validity |
| Table A6 | Challenge category → Operational Activity | Phase 1 challenge taxonomy and coding with the corresponding PDCA Phase and Risk Management Domain. | Convergent construct validity |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Metin, B.; Yey, N.E.; Wynn, M. Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework. Information 2026, 17, 679. https://doi.org/10.3390/info17070679
Metin B, Yey NE, Wynn M. Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework. Information. 2026; 17(7):679. https://doi.org/10.3390/info17070679
Chicago/Turabian StyleMetin, Bilgin, Nazlı Elif Yey, and Martin Wynn. 2026. "Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework" Information 17, no. 7: 679. https://doi.org/10.3390/info17070679
APA StyleMetin, B., Yey, N. E., & Wynn, M. (2026). Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework. Information, 17(7), 679. https://doi.org/10.3390/info17070679

