Your DPIA Passed Review. Would It Survive a Regulator?

Most organisations treat a DPIA as done once it's written and filed. Article 35 GDPR tells you when one is required and what it must contain. It says nothing about how to tell a rigorous risk analysis apart from a document that exists purely to check a box, until it lands in front of a supervisory authority and gets tested for real.
That gap now has a practical answer. In December 2025, the Dutch Ministry of Justice and Security released a DPO assessment framework built specifically to score DPIA quality in a consistent, defensible way. It was designed for Dutch central government use, but it's published openly, and its legal grounding sits in Article 35(7), (9), (10) and (11) GDPR; provisions that apply identically across every Member State. The Dutch terminology translates cleanly: what the framework calls "FG" is simply the DPO, and the relevant supervisory authorities become the GBA and the VTC in a Belgian context.
The framework doesn't tell you how to write a DPIA. It assumes one already exists and tests it afterward, across four areas tied directly to specific clauses of Article 35(7): whether the DPIA correctly describes scope, purpose, and the parties involved; whether it properly addresses necessity and proportionality, including legal basis and the use of AI; whether it genuinely assesses risk to the people affected, including whether they were consulted; and whether the mitigating measures it proposes are new safeguards, not just a restatement of controls that already existed.
Each area gets scored on a five-level scale, from absent to complete. Level three means the requirement is adequately covered. Level four, aligned with best practice, is the realistic target for most organisations. The scoring has real teeth: a DPIA that partially reaches a higher level but doesn't fully meet it gets marked at the lower level, no partial credit. And critically, the bar moves with the stakes: high-impact processing is judged against a higher target, so the same DPIA that would pass for a low-risk system can legitimately fail for a high-risk one.
This is where the framework earns its relevance beyond the Netherlands. Supervisory authorities already reason this way in practice: more sensitive processing gets more scrutiny. A framework that builds that logic into internal quality assurance, rather than leaving it to individual judgment, is exactly the kind of structured evidence that holds up under regulatory review. Accountability under GDPR was never about producing a document, it's about being able to demonstrate compliance. A DPIA that can't survive a basic quality check offers barely more protection than no DPIA at all.
Three things matter if you want to use this well. First, it belongs at the end of the process, as an independent quality check by the DPO, not a substitute for the risk assessment itself. Second, the levels are a conversation tool, not a certified standard: the framework says so explicitly, and every score should come with a justification, not just a number. Third, and most importantly for organisations juggling multiple systems of varying sensitivity, build the proportionality principle into how you review internally: treat your highest-impact processing with the highest bar, every time.
So the question for your next DPIA review: are you scoring it against what a supervisory authority would actually expect or just confirming that all the sections got filled in?



