
handle: 10197/28694
The Data Protection Impact Assessment (DPIA) is an innovative regulatory tool, first introduced in 2018 as part of the EU’s GDPR. Since then, it has been adopted by many jurisdictions globally. Its purpose is to compel data controllers to evaluate and document how high risk personal data processing impacts the rights and freedoms of people. Despite its importance, there is limited research on the DPIA, with most studies focusing only on its theoretical underpinnings. Notably, there is a scarcity of empirical research on the practical application of this risk management instrument. This thesis takes a significant step towards filling this gap by analysing and comparing DPIAs in the light of regulatory theory. I develop a structured framework for comparing DPIAs and present the first systematic analysis of multiple DPIAs addressing the same fact pattern. First, I review the development of regulatory theory to show how DPIAs fit into the ‘ new governance’ model of regulation. I then trace the evolution of data protection across Europe, illustrating how it mirrors the shift from classical regulation to new governance. For the case study, I analyse twenty-three DPIAs produced by EEA states for their COVID proximity tracing apps. These DPIAs shared the same regulation, the same problem, and the same technical solution. The variable lies in how the data controllers interpret the DPIA regulations, making this a unique experiment. The comparative analysis of these 23 DPIAs shows a high degree of commonality in the elements required for a DPIA but significant variations in how each DPIA addresses these elements. Risk identification and mitigation, in particular, exhibit wide divergence. These findings indicate that DPIAs would benefit from a greater emphasis on transparency, learning and objective standards. The findings point to the weakness of ex-ante risk and proportionality assessment. Based on these insights, I propose four recommendations to enhance the DPIA process, which could be implemented by SAs and data controllers without requiring legislative changes. This would move DPIA regulation towards a reflexive and meta-regulatory approach, leading to a more consistent level of fundamental rights protection across the EU.
Risk assessments, New governance, DPIA, Data protection
Risk assessments, New governance, DPIA, Data protection
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 0 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Average | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
