CompanyAssessments

Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment (DPIA) identifies and reduces privacy risks when personal data is processed. Under the General Data Protection Regulation (GDPR), a DPIA is required when processing is likely to create a high risk to people's rights and freedoms. It should be completed before that processing starts.

2024 assessment

PhaseDateDescription
Assessment PhaseDecember 2023Evaluate the need for a DPIA based on new or significantly altered data processing activities.
Planning PhaseJanuary 2024Outline the scope, objectives, and methodology of the DPIA, including stakeholder engagement plans.
Discovery PhaseFebruary 2024Catalog and assess data processing activities, identifying the types of data collected, processed, and stored.
Start of ImplementationFebruary 2024Implement measures to address and mitigate any identified privacy risks, enhancing data protection practices.
Assessment reportApril 2024Finalize and document the DPIA findings, including risk assessment results and mitigation measures implemented.

Status

The 2024 DPIA was completed. The assessment is maintained within our internal compliance structure and is current.

We review and update the DPIA when our processing, systems, or privacy risks materially change. The assessment itself is not published because it contains internal details about our processing and security measures.

Last reviewed: August 2026.

On this page