Bitkom welcomes the EDPB’s objective of making Data Protection Impact Assessments (DPIAs) more consistent across the EU and supporting their implementation through standardised templates.
At the same time, Bitkom suggests that the template should focus more closely on the requirements of Article 35(7) GDPR and clearly prioritise the four core elements of a DPIA: a description of the processing, an assessment of necessity and proportionality, a risk assessment, and measures to mitigate risks. These correspond to the minimum elements set out in the official English version of Article 35(7) GDPR.
In Bitkom’s view, supplementary content and best practices can be helpful, but should be clearly distinguished from the mandatory elements in order to make the template as straightforward and easy to follow as possible in practice.