{"id":"https://openalex.org/W4415041389","doi":"https://doi.org/10.1007/978-3-032-07574-1_8","title":"Illuminating the\u00a0DPIA Blackbox \u2013 A Survey of\u00a0Data Protection Impact Assessment Practices in\u00a0Organisations","display_name":"Illuminating the\u00a0DPIA Blackbox \u2013 A Survey of\u00a0Data Protection Impact Assessment Practices in\u00a0Organisations","publication_year":2025,"publication_date":"2025-10-10","ids":{"openalex":"https://openalex.org/W4415041389","doi":"https://doi.org/10.1007/978-3-032-07574-1_8"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-032-07574-1_8","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-032-07574-1_8","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-032-07574-1_8.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://link.springer.com/content/pdf/10.1007/978-3-032-07574-1_8.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5083120600","display_name":"Malte Hansen","orcid":"https://orcid.org/0000-0003-4622-3819"},"institutions":[{"id":"https://openalex.org/I184942183","display_name":"University of Oslo","ror":"https://ror.org/01xtthb56","country_code":"NO","type":"education","lineage":["https://openalex.org/I184942183"]}],"countries":["NO"],"is_corresponding":true,"raw_author_name":"Malte Hansen","raw_affiliation_strings":["Department of Informatics, University of Oslo, Oslo, Norway"],"affiliations":[{"raw_affiliation_string":"Department of Informatics, University of Oslo, Oslo, Norway","institution_ids":["https://openalex.org/I184942183"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005338643","display_name":"Greta Runge","orcid":"https://orcid.org/0000-0002-6698-2073"},"institutions":[{"id":"https://openalex.org/I4210131336","display_name":"Fraunhofer Institute for Systems and Innovation Research","ror":"https://ror.org/03vyq6t71","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210131336","https://openalex.org/I4923324"]},{"id":"https://openalex.org/I4210148503","display_name":"Fraunhofer Institute for Production Systems and Design Technology","ror":"https://ror.org/045eg9c12","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210148503","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Greta Runge","raw_affiliation_strings":["Fraunhofer Institute for Systems and Innovation Research, Berlin, Germany"],"affiliations":[{"raw_affiliation_string":"Fraunhofer Institute for Systems and Innovation Research, Berlin, Germany","institution_ids":["https://openalex.org/I4210131336","https://openalex.org/I4210148503"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078229046","display_name":"Nils Gruschka","orcid":"https://orcid.org/0000-0001-7360-8314"},"institutions":[{"id":"https://openalex.org/I184942183","display_name":"University of Oslo","ror":"https://ror.org/01xtthb56","country_code":"NO","type":"education","lineage":["https://openalex.org/I184942183"]}],"countries":["NO"],"is_corresponding":false,"raw_author_name":"Nils Gruschka","raw_affiliation_strings":["Department of Informatics, University of Oslo, Oslo, Norway"],"affiliations":[{"raw_affiliation_string":"Department of Informatics, University of Oslo, Oslo, Norway","institution_ids":["https://openalex.org/I184942183"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5069686143","display_name":"Meiko Jensen","orcid":"https://orcid.org/0009-0003-2397-9813"},"institutions":[{"id":"https://openalex.org/I43968019","display_name":"Karlstad University","ror":"https://ror.org/05s754026","country_code":"SE","type":"education","lineage":["https://openalex.org/I43968019"]}],"countries":["SE"],"is_corresponding":false,"raw_author_name":"Meiko Jensen","raw_affiliation_strings":["Karlstad University, Karlstad, Sweden"],"affiliations":[{"raw_affiliation_string":"Karlstad University, Karlstad, Sweden","institution_ids":["https://openalex.org/I43968019"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5083120600"],"corresponding_institution_ids":["https://openalex.org/I184942183"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":{"value":5000,"currency":"EUR","value_usd":5392},"fwci":6.9991,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.97451193,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"178","last_page":"201"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11719","display_name":"Data Quality and Management","score":0.9714999794960022,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T11719","display_name":"Data Quality and Management","score":0.9714999794960022,"subfield":{"id":"https://openalex.org/subfields/1803","display_name":"Management Science and Operations Research"},"field":{"id":"https://openalex.org/fields/18","display_name":"Decision Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T11045","display_name":"Privacy, Security, and Data Protection","score":0.9638000130653381,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9463000297546387,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/data-protection-act-1998","display_name":"Data Protection Act 1998","score":0.7760000228881836},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.6341000199317932},{"id":"https://openalex.org/keywords/general-data-protection-regulation","display_name":"General Data Protection Regulation","score":0.6033999919891357},{"id":"https://openalex.org/keywords/impact-assessment","display_name":"Impact assessment","score":0.5680000185966492},{"id":"https://openalex.org/keywords/privacy-protection","display_name":"Privacy protection","score":0.47600001096725464},{"id":"https://openalex.org/keywords/data-processing","display_name":"Data processing","score":0.4016000032424927},{"id":"https://openalex.org/keywords/state","display_name":"State (computer science)","score":0.39480000734329224},{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.3862999975681305}],"concepts":[{"id":"https://openalex.org/C69360830","wikidata":"https://www.wikidata.org/wiki/Q1172237","display_name":"Data Protection Act 1998","level":2,"score":0.7760000228881836},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7361999750137329},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.6341000199317932},{"id":"https://openalex.org/C3090818","wikidata":"https://www.wikidata.org/wiki/Q1172506","display_name":"General Data Protection Regulation","level":3,"score":0.6033999919891357},{"id":"https://openalex.org/C111874474","wikidata":"https://www.wikidata.org/wiki/Q6005872","display_name":"Impact assessment","level":2,"score":0.5680000185966492},{"id":"https://openalex.org/C3017597292","wikidata":"https://www.wikidata.org/wiki/Q25052250","display_name":"Privacy protection","level":2,"score":0.47600001096725464},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4555000066757202},{"id":"https://openalex.org/C138827492","wikidata":"https://www.wikidata.org/wiki/Q6661985","display_name":"Data processing","level":2,"score":0.4016000032424927},{"id":"https://openalex.org/C48103436","wikidata":"https://www.wikidata.org/wiki/Q599031","display_name":"State (computer science)","level":2,"score":0.39480000734329224},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.3862999975681305},{"id":"https://openalex.org/C198477413","wikidata":"https://www.wikidata.org/wiki/Q7647069","display_name":"Survey data collection","level":2,"score":0.36399999260902405},{"id":"https://openalex.org/C168297262","wikidata":"https://www.wikidata.org/wiki/Q6031182","display_name":"Information protection policy","level":2,"score":0.3528999984264374},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.3481999933719635},{"id":"https://openalex.org/C2776035688","wikidata":"https://www.wikidata.org/wiki/Q1606558","display_name":"Affect (linguistics)","level":2,"score":0.32580000162124634},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.31220000982284546},{"id":"https://openalex.org/C527821871","wikidata":"https://www.wikidata.org/wiki/Q228502","display_name":"Access control","level":2,"score":0.31060001254081726},{"id":"https://openalex.org/C2775924081","wikidata":"https://www.wikidata.org/wiki/Q55608371","display_name":"Control (management)","level":2,"score":0.30480000376701355},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.29409998655319214},{"id":"https://openalex.org/C10511746","wikidata":"https://www.wikidata.org/wiki/Q899388","display_name":"Data security","level":3,"score":0.2888999879360199},{"id":"https://openalex.org/C49895821","wikidata":"https://www.wikidata.org/wiki/Q5227368","display_name":"Data verification","level":2,"score":0.28540000319480896},{"id":"https://openalex.org/C33762810","wikidata":"https://www.wikidata.org/wiki/Q461671","display_name":"Data integrity","level":2,"score":0.27959999442100525},{"id":"https://openalex.org/C173481278","wikidata":"https://www.wikidata.org/wiki/Q7257997","display_name":"Survey research","level":2,"score":0.26339998841285706},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.26089999079704285},{"id":"https://openalex.org/C93360035","wikidata":"https://www.wikidata.org/wiki/Q17055852","display_name":"Impact evaluation","level":2,"score":0.2605000138282776},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.2572999894618988},{"id":"https://openalex.org/C2985331491","wikidata":"https://www.wikidata.org/wiki/Q5227298","display_name":"Data format","level":2,"score":0.25540000200271606}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1007/978-3-032-07574-1_8","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-032-07574-1_8","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-032-07574-1_8.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:publica.fraunhofer.de:publica/497426","is_oa":true,"landing_page_url":"https://publica.fraunhofer.de/handle/publica/497426","pdf_url":null,"source":{"id":"https://openalex.org/S4306400318","display_name":"Fraunhofer-Publica (Fraunhofer-Gesellschaft)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4923324","host_organization_name":"Fraunhofer-Gesellschaft","host_organization_lineage":["https://openalex.org/I4923324"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"conference paper"}],"best_oa_location":{"id":"doi:10.1007/978-3-032-07574-1_8","is_oa":true,"landing_page_url":"https://doi.org/10.1007/978-3-032-07574-1_8","pdf_url":"https://link.springer.com/content/pdf/10.1007/978-3-032-07574-1_8.pdf","source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":"cc-by-nc-nd","license_id":"https://openalex.org/licenses/cc-by-nc-nd","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4415041389.pdf"},"referenced_works_count":23,"referenced_works":["https://openalex.org/W1129193082","https://openalex.org/W1548561497","https://openalex.org/W2513682819","https://openalex.org/W2529628152","https://openalex.org/W2762468264","https://openalex.org/W2805964993","https://openalex.org/W2811114113","https://openalex.org/W2915282285","https://openalex.org/W2971861433","https://openalex.org/W2973086080","https://openalex.org/W3030209542","https://openalex.org/W3043493810","https://openalex.org/W3097722188","https://openalex.org/W3132112090","https://openalex.org/W3195943331","https://openalex.org/W4206323904","https://openalex.org/W4210933416","https://openalex.org/W4286542295","https://openalex.org/W4294934854","https://openalex.org/W4390947937","https://openalex.org/W4391454415","https://openalex.org/W4407405508","https://openalex.org/W4409672841"],"related_works":[],"abstract_inverted_index":{"According":[0],"to":[1,31,99,108],"the":[2,33,42,48,70,77,101],"European":[3],"General":[4],"Data":[5,10],"Protection":[6,11],"Regulation":[7],"(GDPR),":[8],"a":[9,59,73],"Impact":[12],"Assessment":[13],"(DPIA)":[14],"is":[15,29],"mandatory":[16],"for":[17],"all":[18],"ongoing":[19],"and":[20,35,39,95],"planned":[21],"processing":[22,28],"of":[23,41,51,62,72,79,81,122],"personal":[24],"data":[25,36,43],"if":[26],"said":[27],"likely":[30],"affect":[32],"privacy":[34],"protection":[37],"rights":[38],"freedoms":[40],"subjects.":[44],"However,":[45],"upon":[46],"examining":[47],"real-world":[49,86],"implementation":[50],"this":[52,66],"requirement,":[53],"various":[54],"approaches":[55],"emerged,":[56],"resulting":[57],"in":[58,85,104,120],"heterogeneous":[60],"landscape":[61,103],"DPIA":[63,82,93,102],"processes.":[64],"In":[65],"paper,":[67],"we":[68],"present":[69],"results":[71],"survey":[74,89],"that":[75,91],"investigated":[76],"state":[78],"adoption":[80],"process":[83],"methodologies":[84],"organisations.":[87],"Our":[88],"reveals":[90],"handwritten":[92],"reports":[94],"ad-hoc":[96],"methods":[97],"continue":[98],"dominate":[100],"Europe.":[105],"Moreover,":[106],"according":[107],"our":[109],"data,":[110],"processes":[111],"involving":[112],"multiple":[113],"stakeholders":[114],"are":[115],"often":[116],"not":[117],"adequately":[118],"assessed":[119],"terms":[121],"DPIA-related":[123],"risks.":[124]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-03-28T08:17:26.163206","created_date":"2025-10-11T00:00:00"}
