| name | dpia-stakeholder-consult |
| description | Guides data subject and stakeholder consultation requirements during Data Protection Impact Assessments under GDPR Article 35(9). Covers consultation planning, data subject engagement methods, DPO involvement per Art. 35(2), and documentation of views received. Keywords: DPIA consultation, stakeholder engagement, Art. 35(9), data subject views, DPO advice, public consultation, representative groups. |
| license | Apache-2.0 |
| metadata | {"author":"mukul975","version":"1.0","domain":"privacy","subdomain":"privacy-impact-assessment","tags":"dpia-consultation, stakeholder-engagement, art-35-9, data-subject-views, dpo-advice"} |
DPIA Stakeholder Consultation
Overview
Article 35(9) GDPR requires that controllers "shall, where appropriate, seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations." This skill provides a structured approach to meeting this obligation.
Legal Requirements
Art. 35(9) -- Data Subject Consultation
The controller must seek data subject views "where appropriate." EDPB WP248rev.01 clarifies that failure to consult must be justified and documented.
Art. 35(2) -- DPO Involvement
"The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment."
Art. 36(1) -- Prior Consultation Context
Where prior consultation with the supervisory authority is required, evidence of stakeholder consultation strengthens the submission.
Consultation Methods
| Method | Suitability | Scale | Cost |
|---|
| Focus groups | Deep qualitative insight | Small (8-12 participants) | Medium |
| Online surveys | Broad quantitative data | Large (hundreds+) | Low |
| Written consultation | Formal, documented responses | Medium | Low |
| Public meetings | Community engagement | Medium-Large | Medium |
| Representative body engagement | Sector-specific expertise | Varies | Low |
| Advisory panel | Ongoing input | Small (5-10 members) | Medium |
| User testing with privacy lens | Practical usability insight | Small-Medium | High |
Consultation Process
Step 1: Determine Appropriateness
- Assess whether consultation is feasible without compromising security
- Document any reasons for not consulting (Art. 35(9) exemption)
- Consider proportionality: scale of processing vs consultation effort
Step 2: Identify Stakeholders
- Direct data subjects (or representative sample)
- Data subject representative bodies (consumer associations, patient groups, trade unions)
- Data Protection Officer
- Processor representatives
- Relevant internal stakeholders (IT security, legal, business unit)
Step 3: Design Consultation
- Select appropriate method(s) from the table above
- Prepare accessible consultation materials explaining the processing
- Define the specific questions or areas for input
- Set timeline and response deadlines
Step 4: Execute and Document
- Conduct consultation activities
- Record all views received
- Analyse feedback for themes and concerns
- Document how feedback influenced the DPIA outcome
Step 5: Feedback Loop
- Inform consultees of the outcome and actions taken
- Explain where their views were incorporated or why they were not
- Maintain ongoing engagement channel for future DPIA reviews