Skip to main content

Security, privacy, and governance

A practical DPIA for psychometric assessment workflows

A step-by-step DPIA method for identifying and reducing privacy risks before introducing or materially changing a digital assessment workflow.

Screen for a DPIA early

Under GDPR Article 35, a controller must perform a DPIA before processing that is likely to result in a high risk to people's rights and freedoms. Assessment workflows can combine sensitive health data, vulnerable people, systematic evaluation, new technology, and linked datasets, so screening should happen while the workflow can still be changed. [1][2]

Describe the workflow as it will operate

A useful DPIA follows data from invitation to deletion. It identifies people affected, data categories, collection channels, scoring, clinical access, exports, integrations, support access, recipients, locations, retention, and exceptional paths such as a withdrawn invitation or a disputed record. [1]

  • State the intended clinical and operational purposes in plain language.
  • Explain why each data field and each recipient is necessary and proportionate.
  • Separate deterministic scoring from any profiling, automated decision, or secondary analytics.
  • Include manual workarounds, downloads, email, and support tools rather than documenting only the main interface.
[3]
Lirena original visual

The living DPIA loop

A five-stage loop that keeps privacy-risk decisions connected to the live assessment workflow.

  • Screen

    Identify high-risk indicators before design and procurement decisions harden.

  • Map

    Describe purposes, people, data, systems, recipients, and retention end to end.

  • Assess

    Evaluate necessity, proportionality, harms, likelihood, and severity.

  • Treat

    Select evidence-backed controls and obtain accountable approval.

  • Review

    Reopen the analysis when the workflow or risk changes.

A five-stage loop that keeps privacy-risk decisions connected to the live assessment workflow. This diagram was created by Lirena for this guide.

Express risks as consequences for people

A DPIA should not stop at technical events such as an exposed link or excessive permission. Connect each event to possible effects on a person, including loss of confidentiality, distress, stigma, discrimination, loss of control, inaccurate records, unavailable care information, or an inability to exercise a right. [2][3]

  • Describe the threat or failure and the affected people.
  • Rate likelihood and severity using defined criteria, including the sensitivity and scale of data.
  • Record existing controls and evidence that they operate.
  • Estimate residual risk after planned controls, not merely inherent risk.

Choose controls and consult the people who understand the work

Controls can include data minimisation, short-lived invitations, role-based access, strong authentication, encryption, audit trails, retention automation, incident procedures, accessible explanations, and a non-digital alternative. Their suitability depends on the identified risk and workflow, not on a generic checklist. [1][3]

Consult clinicians, administrators, security and privacy specialists, and representatives of affected people where appropriate. Document disagreements and constraints. Consultation is most valuable before a product configuration or operating procedure becomes difficult to change. [1]

Approve residual risk and keep the DPIA alive

Assign every action an owner and deadline, state who accepts residual risk, and prevent launch until mandatory actions are complete. If high residual risk remains and cannot be mitigated, GDPR provides for prior consultation with the supervisory authority. Review the DPIA when processing risk changes. [1]

  • Trigger review for a new measure category, population, integration, subprocessor, data location, retention rule, or analytic purpose.
  • Link control claims to test results, configuration evidence, policies, or supplier documentation.
  • Record the approval decision, open actions, residual risks, and next review date.

Sources and further reading

  1. Regulation (EU) 2016/679, Articles 35 and 36 (opens in a new tab)European Union. Accessed 2026-07-13. Primary EU law defining DPIA content, timing, review, data protection officer advice, and prior consultation.
  2. Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679 (WP248 rev.01) (opens in a new tab)Article 29 Working Party. Published 2017-10-13. Accessed 2026-07-13. EU guidance describing high-risk criteria and characteristics of an acceptable DPIA. The EDPB endorsed this WP29 guideline.
  3. Data Protection Impact Assessments (opens in a new tab)Data Protection Commission Ireland. Accessed 2026-07-13. Irish supervisory-authority guidance and practical DPIA resources. Page contents may change and should be checked at use.

Next step

Map governance into the product walkthrough

Bring your DPIA questions to a workflow-focused demonstration of Lirena.

Book a demo