
Why a DPIA is Mandatory for Cloud Projects
The cloud offers enormous opportunities, but it also poses risks to data protection. The General Data Protection Regulation (GDPR) therefore requires a Data Protection Impact Assessment (DPIA) when there is a high risk to the rights and freedoms of natural persons. For the public sector, which works with sensitive citizen data, this is almost always the case for cloud projects.
A DPIA is not an obstacle; it is a tool for risk minimisation. It forces a systematic engagement with data protection and creates legal certainty for your cloud project. A missing DPIA can lead to significant fines and the halting of the project.
When Exactly is a DPIA Required?
Article 35 of the GDPR is clear. A DPIA is required, in particular, for:
- Large-scale processing of special categories of data (e.g., health data).
- Systematic and extensive evaluation of personal aspects (profiling).
- Large-scale monitoring of publicly accessible areas.
The German Data Protection Conference (DSK) has published a positive list of processing activities for which a DPIA is generally required. The use of cloud services for specialised procedures with large amounts of data often falls into this category.

The 4 Steps of a Data Protection Impact Assessment
A DPIA follows a structured process. It is not a one-time document but a living process.
Step 1: Systematic Description
- What? What data is being processed?
- Why? What is the purpose of the processing?
- Who? Who are the parties involved (controller, processor)?
- How? What technologies and processes are being used?
Step 2: Assessment of Necessity and Proportionality
Is the processing truly necessary for the purpose? Are there milder, more data-minimising alternatives? The legal basis must be clear.
Step 3: Risk Assessment
What are the risks to the data subjects (citizens)? (e.g., unauthorised access, data loss, discrimination). The likelihood of occurrence and the severity of the potential harm are assessed.
Step 4: Remedial Measures
What technical and organisational measures (TOMs) will be taken to minimise the risks? This includes encryption, access controls, and contractual arrangements with the cloud provider. We show how to implement them in Azure and GCP in GDPR-Compliant Cloud Usage: TOMs in Azure and GCP.
Quick Checklist: DPIA for the Cloud
| Step | Key Question | Done? |
| 1. Description | Is the processing completely described? | ☐ |
| 2. Necessity | Is the legal basis clear and the processing proportionate? | ☐ |
| 3. Risk Assessment | Are the risks to data subjects identified and assessed? | ☐ |
| 4. Measures | Are effective remedial measures defined? | ☐ |
| 5. Documentation | Is the entire DPIA comprehensibly documented? | ☐ |
| 6. Consultation | Must the Data Protection Officer or the supervisory authority be consulted? | ☐ |
To-Do List for the DPIA
- Immediately: Clarify whether a DPIA is mandatory for the cloud project.
- Week 1: Appoint a responsible team for the DPIA.
- Week 2: Involve the Data Protection Officer at an early stage.
- Month 1: Begin the systematic description of the processing.
- Month 2: Conduct the risk assessment.
- Month 3: Define remedial measures with the cloud service provider and the IT security team.
- Ongoing: Update the DPIA whenever the system changes.
The Challenge: Third-Country Transfers
Since the Schrems II ruling, data transfers to the US and other third countries have become complex. Cloud providers like Microsoft (Azure), Amazon (AWS) and Google (GCP) are US companies. A DPIA must explicitly assess this risk — including the possibility of access under the US CLOUD Act regardless of where the data centre is located.
Remedial measures for this include:
- Standard Contractual Clauses (SCCs): The standard mechanism, but often not sufficient on its own.
- Additional TOMs: Strong encryption (ideally with your own keys – BYOK/HYOK), pseudonymisation, anonymisation.
- Sovereign Cloud Options: Use of EU-operated platforms and contractual assurances — see Sovereign Cloud Germany.
Insight42: Your Partner for the Cloud DPIA
A DPIA for cloud services requires legal, technical, and procedural knowledge. We connect these worlds. Our Data Protection Impact Assessment consulting is practice-oriented and tailored to the public sector.
We help you identify risks, define effective measures, and design your cloud projects to be legally compliant, in line with BSI C5 and IT Baseline Protection.
Make your data protection future-proof. See NIS2 & Cloud Security Beratung (German) or contact us.