DPIA questions for identity and age systems
A DPIA should describe the real identity or age-assurance data flow, not a generic vendor diagram. It must test necessity, proportionality, roles, risks, safeguards and alternatives before high-risk processing begins.
GDPR Article 35 governs DPIAs. The EUDI Regulation expressly preserves GDPR responsibilities, and age-assurance guidance emphasises necessity, proportionality, effectiveness and data minimisation.
For: DPOs, privacy counsel, product owners, security and risk teams. This is independent information, not legal, compliance or security advice.
Purpose and necessity
- What exact service decision requires identity or age evidence?
- Which rule, risk or contract drives it?
- Can fewer attributes or a less intrusive method achieve the purpose?
- Is the method effective enough to justify its impact?
Data-flow inventory
- Raw document images and extracted attributes.
- NFC/chip data and digital signatures.
- Selfie/video, face template or age-estimation output.
- Device, session and fraud signals.
- Wallet requests, presentations and logs.
- Manual-review records, decisions and appeals.
Roles and lifecycle
- Controller, joint controller and processor per operation.
- Recipients, subprocessors and transfer locations.
- Collection, access, retention, deletion and backup behaviour.
- Model improvement or secondary use.
- Incident, correction and data-subject request responsibility.
People and failure
- False acceptance, false rejection and discriminatory impact.
- Children and vulnerable people.
- People without documents, devices, stable connectivity or conventional appearance.
- Coercion, identity theft and account recovery.
- Transparent explanation, human review and redress.
Decision record
Record rejected alternatives, residual risks, approving roles, consultation and conditions for reassessment. Revisit the DPIA after a new method, model, provider, purpose, geography, material incident or regulatory change.
Evidence and limits
MyID separates enacted rules, official implementation material, testing and vendor claims. A source can establish what its publisher says; it does not prove that every product, deployment or interpretation works as claimed. Where Irish implementation remains unsettled, this page says so.
- General Data Protection Regulation
- Data Protection Commission
- EDPB Statement 1/2025 on Age Assurance
- Regulation (EU) 2024/1183
Sources checked 22 August 2026. Re-check the linked primary material before making a consequential decision.
Next useful pages
Follow the Irish evidence
Get the business briefing when Irish wallet, verification and age-assurance evidence changes.
Join the business briefing