ssm.ro Docs
Compliance & Data ProtectionGDPR

Data Protection Impact Assessment (DPIA)

Data protection impact assessment for high-risk processing activities

The Data Protection Impact Assessment (DPIA) is carried out for processing activities likely to result in a high risk to the rights and freedoms of data subjects (Art. 35 GDPR).

When it is required

A DPIA is particularly indicated for:

  • Large-scale processing of identification data (CNP, ID document series/number) for the purpose of qualified electronic signature
  • The introduction of new technologies or data flows impacting data subjects
  • Systematic and extensive processing underlying decisions that affect individuals

Elements of the assessment

ElementContent
Description of processingPurpose, categories of data, flows (see Register of Processing Activities)
Necessity and proportionalityJustification of the legal basis and data minimization
Risk assessmentLikelihood and impact on data subjects' rights
Mitigation measuresEncryption, tenant isolation, minimization (hashing at signing), access control

The DPIA is corroborated with the platform's Risk Register, which assesses security risks (including compliance with retention and data subject rights — risk #11) and the associated controls.

Role of the DPO

The DPO (Neoprivacy SRL) advises on and monitors the performance of the DPIA. For processing where SSM.ro acts as processor, the DPIA is primarily the responsibility of the controller (the client), with informational support from SSM.ro.