Module V: Data Protection Impact
Assessment
Module Overview
This module introduces Data Protection Impact Assessments (DPIAs) as a tool for identifying,
assessing, and mitigating risks to the rights and freedoms of data subjects. It covers the legal
framework, key processes, and practical application through a case study.
Learning Objectives
By the end of this module, learners should be able to:
Define a DPIA
Explain the importance of DPIAs
Identify when a DPIA is required
Describe the steps involved in conducting a DPIA
Understand the legal and regulatory framework governing DPIAs
Analyse a practical case study
Module Structure
Unit 1: What is a DPIA?
Definition of a DPIA
Purpose of a DPIA
Legal basis under Section 31 of the Data Protection Act, 2019
Unit 2: Why are DPIAs Important?
Protection of data subjects’ rights
Legal and regulatory compliance
Risk management and accountability
Building public trust
Page 1 of 3
Unit 3: When Do You Undertake a DPIA?
High-risk processing activities
Situations requiring a DPIA:
Large-scale data processing
Processing of sensitive personal data
Systematic monitoring of public spaces
Automated decision-making and profiling
Use of new technologies
Consultation with the regulator where risks cannot be mitigated
Unit 4: Examples of Activities Requiring DPIAs
National digital ID systems
Facial recognition/biometric technologies
AI-driven profiling
Large-scale health or financial databases
Smart city surveillance systems
Unit 5: How to Undertake a DPIA (Process)
Step 1: Data mapping and description of processing
Step 2: Analysis of each processing activity
Step 3: Analysis of all activities collectively
Step 4: Risk determination (likelihood and severity)
Step 5: Reporting to management
Step 6: Monitoring and evaluation
Page 2 of 3
Unit 6: Legal and Regulatory Framework
Data Protection Act, 2019 (Section 31)
Requirement to conduct a DPIA
Contents of a DPIA
Consultation with the Data Commissioner
Data Protection (General) Regulations, 2021 (Part VIII)
Data Protection (Civil Registration) Regulations
ODPC Guidance Note on DPIAs
Unit 7: International / Comparative Frameworks
General Data Protection Regulation (GDPR)
African Union Convention on Cyber Security and Personal Data Protection (Malabo
Convention)
Unit 8: Case Study – Worldcoin Case
Unit 9: Conclusion
Page 3 of 3