Establishing a Comprehensive Data Protection Impact Assessment Methodology for Big Data Analytics in Compliance with the General Data Protection Regulation | Research Square window.SnipcartSettings = { analytics: { enabled: false } }; (function() { var accessVector = localStorage.getItem('access_vector') || ''; window.dataLayer = window.dataLayer || []; if (accessVector) { window.dataLayer.push({ user: { profile: { profileInfo: { snid: accessVector } } } }); } })(); (function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer','GTM-K279D39R'); Browse Preprints In Review Journals COVID-19 Preprints AJE Video Bytes Research Tools Research Promotion AJE Professional Editing AJE Rubriq About Preprint Platform In Review Editorial Policies Our Team Advisory Board Help Center Sign In Submit a Preprint Cite Share Download PDF Research Article Establishing a Comprehensive Data Protection Impact Assessment Methodology for Big Data Analytics in Compliance with the General Data Protection Regulation Georgios Georgiadis, Geert Poels This is a preprint; it has not been peer reviewed by a journal. https://doi.org/ 10.21203/rs.3.rs-5821174/v1 This work is licensed under a CC BY 4.0 License Status: Posted Version 1 posted You are reading this latest preprint version Abstract In today’s digital landscape, as big data analytics (BDA) gain increasing significance, it is vital to have robust strategies for safeguarding privacy and data protection. This paper focuses on improving data protection impact assessments (DPIAs) in the context of BDA, aligning them with the principles of the General Data Protection Regulation (GDPR). Through a study that combines a Delphi approach with individual expert interviews, we have validated nine critical privacy touch points (PTPs) for adapting DPIA methodology to BDA environments. These PTPs, identified in our previous research, address key privacy and data protection issues in BDA, including consent nuances, definitions of data control, and challenges such as re-identification and discrimination. The result is a framework tailored to the unique landscape of BDA technologies. This research stands out by thoroughly analysing and validating these nine PTPs and offering actionable recommendations to enhance the existing DPIA framework. With the anticipated growth of artificial intelligence and large language models, BDA will continue to attract attention. Our research therefore contributes both academically and practically by supporting the evolution of thorough DPIA practices while providing guidance for policymakers, businesses, and privacy advocates. Artificial Intelligence and Machine Learning Management Big data data protection Delphi study directive General Data Protection Regulation governance information security privacy privacy impact assessment Figures Figure 1 Figure 2 Figure 3 Figure 4 Figure 5 Figure 6 Figure 7 Figure 8 1 Introduction The advent of big data analytics (BDA) technologies has ushered in a transformative era, where data-driven decision-making has become a central strategy for both industry and individual success. These technologies have revolutionised the ability to capture, store, process, and analyse massive volumes of structured and unstructured data at unprecedented speeds, revealing insights that were previously unimaginable. At its core, BDA aims to decode intricate patterns and trends within vast amounts of data. To achieve this, BDA technologies utilise advanced algorithms, computational models, and statistical methods to uncover hidden correlations, causal relationships, market trends, customer preferences, and many other insights (Hordri et al., 2017). With this knowledge, businesses and organisations can optimise operations, devise more targeted marketing strategies, improve product development, and enhance the overall customer experience and satisfaction. BDA has also had a profound impact on individuals. It enables personalised healthcare through predictive analytics, anticipating health issues before they become critical. In finance, it facilitates tailored investment strategies, while in entertainment and social media, it improves user experiences by providing personalised content recommendations. However, the widespread adoption of BDA technologies has sparked discussions around privacy and personal data protection. A balanced approach is needed to address both data utility and the respect for individual rights and freedoms, as mandated by legal frameworks such as the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in the United States (EU, 2016; Pardau, 2018; Tene & Polonetsky, 2012). As we enter an increasingly data-centric world, it is crucial to address these concerns while harnessing the vast potential of big data. Similar to the CCPA, the GDPR establishes strict principles and rules for handling personal data. Concerns such as the unintended exposure of personal data and the processing of sensitive data, which could occur through various channels and pose high risks to individuals, have led to the need for data protection impact assessments (DPIAs). These assessments enable organisations to proactively identify and mitigate potential vulnerabilities in personal data processing before issues arise (WP29, 2017). DPIAs provide a structured approach for identifying, analysing, and mitigating risks to the rights and freedoms of individuals resulting from personal data processing. They also help organisations comply with data protection laws like the GDPR. In this context, and based on the results of a systematic literature review (Georgiadis & Poels, 2022b), nine privacy touch points (PTPs) related to BDA-specific risks and threats to personal data protection and privacy were identified. Our current research focuses on examining how these PTPs manifest themselves in real-world contexts by inquiring domain experts. We further provide recommendations to address gaps in the DPIA framework to improve its applicability in BDA environments. This paper aims to answer the following question: What changes or improvements should be considered to enhance the DPIA framework to make it more relevant for use in BDA contexts where personal data is processed? To investigate this question, we conducted a Delphi study, [1] using the nine PTPs as a starting point. We sought expert opinions on changes and improvements to the DPIA framework to make it more suitable for environments where BDA is used to process personal data. While this research question cannot be answered with a simple prescriptive response, we aim to provide an informed answer based on the analysis of feedback from the Delphi rounds and follow-up interviews, combined with our understanding of the subject matter. These findings form the basis of our knowledge contribution. This paper presents the results of the Delphi study and expert interviews, through which we address the research question. Our research builds upon previous work presented in conference papers (Georgiadis & Poels, 2022a, 2023a, 2023b), which reported the outcomes of three Delphi study rounds, focusing on expert validation of the PTPs resulting from our systematic literature review. However, this paper significantly extends that work by offering a deeper analysis of the Delphi study findings aimed at exploring solutions for addressing the PTPs through an improved DPIA. The paper also enhances the Delphi study findings by incorporating new insights from expert interviews. Ultimately, it leverages the results obtained from the Delphi study and expert interviews by presenting a refined DPIA framework specifically tailored to BDA. The unique and novel contribution of the paper lies in exploring how the validated PTPs can be operationalised within the existing DPIA framework – an area not covered in earlier publications. The remainder of this paper is organised as follows. Section 2 provides the background of our study. Section 3 describes the methodological framework, with a focus on the Delphi study technique. Section 4 discusses the findings from each Delphi round and integrates them with insights from individual interviews with members of the Delphi panel and additional experts. Section 5 presents lessons learned and recommendations for improving the DPIA framework for BDA processing operations. Section 6 outlines research contributions and limitations. Section 7 offers conclusions and an outlook, while Section 8 suggests potential future research directions. [1] The Delphi method is a consensus-building approach that uses a series of questionnaires to gather expert opinions on a specific research topic. The goal is to achieve general agreement among the participants, who form a panel of experts. This method operates on the assumption that the collective opinion of the group is more valid than that of any individual member. 2 Background 2.1 The Importance of Privacy Impact Assessments in the Protection of Personal Data DPIAs are a streamlined version of privacy impact assessments (PIAs) (Clarke, 2017 ) and are particularly relevant in today’s digital age. With the rapid spread of information technology and the large-scale processing of data, personal data has become crucial not only to businesses and governments but also to individuals, who are increasingly concerned about the risks of data mismanagement and breaches. Recent reports have shown that both the costs and frequency of such incidents are on the rise (IBM, 2023 ). DPIAs play a vital role in safeguarding individuals’ personal data rights by identifying and addressing potential risks arising from data processing activities (Kloza et al., 2018 ). By conducting a DPIA, organisations can systematically assess the potential impacts of data processing on individuals’ rights and freedoms, implementing strategies to mitigate risks and ensure compliance with data protection regulations. The main objective is to ensure that data protection considerations are integrated early in the planning stages of any project or initiative that involves personal data processing. The DPIA process consists of several key steps. First, organisations must determine when a DPIA is required, typically when processing operations are likely to pose high risks to individuals’ rights and freedoms. Second, the organisation must describe the nature, scope, context, and purposes of the proposed processing activities, including identifying data flows, which represent the movement and processing of personal data within and beyond the organisation. The next step is to evaluate whether the processing activities are necessary and proportionate to the intended purposes. This is followed by a thorough assessment of potential risks to individuals’ rights and freedoms, accounting for both existing risks and those that may arise from future changes. Based on the risk assessment, organisations should consider implementing appropriate measures to demonstrate compliance with relevant legislation, such as the GDPR. Although the GDPR does not mandate the direct implementation of results, measures may include legal, technical, or organisational safeguards, or consultations with key stakeholders, such as data subjects or supervisory authorities. In addition to ensuring legal compliance and promoting data governance, effective DPIA implementation offers numerous benefits. It demonstrates accountability in handling personal data and allows organisations to proactively identify and mitigate risks before they materialise, thereby reducing potential harm to individuals and building trust among data subjects. However, conducting DPIAs also poses challenges. Resource allocation is a significant issue, as DPIAs require time and expertise from professionals well-versed in data protection. Furthermore, balancing data protection concerns with business or governmental interests can be complex, particularly for organisations heavily reliant on personal data processing, such as those using AI solutions like BDA. Lastly, ongoing monitoring and review of the DPIA process is essential to ensure continued compliance (Ivanova, 2020 ; Wright, 2013 ). In this paper, we use several terms related to DPIA, and to avoid ambiguity, we define each as follows: DPIA Framework : The conceptual model or structure that guides the overall approach to conducting DPIAs. DPIA Methodology : Specific methods or approaches used within the framework to assess risks and impacts. DPIA Method : The detailed procedural steps followed by practitioners when performing a DPIA. DPIA Process : The full lifecycle of conducting a DPIA, from preparation to risk mitigation and review. DPIA Guidance : Recommendations or best practices that provide instructions on how to conduct DPIAs. DPIA Policy : Organisational policies that dictate when a DPIA should be conducted, who is responsible, and which elements must be considered. DPIA Templates : Predefined formats or forms used to standardise the documentation of DPIAs. DPIA Aids : Software tools, checklists, or other practical resources designed to help practitioners conduct DPIAs more effectively. 2.2 Key Challenges and Considerations for Personal Data Protection with Big Data Analytics BDA has immense potential to drive insights and innovation across various sectors by enabling organisations to analyse massive volumes of data and efficiently detect hidden patterns (Chen et al., 2012), thereby transforming raw data into valuable information. However, as data volumes continue to grow and BDA techniques advance to more sophisticated implementations, such as large language models (LLMs), the challenges of ensuring personal data protection and privacy also increase (Ammon, 2023 ; Jain et al., 2016 ). In this rapidly evolving landscape, understanding the interplay between technological, legal, and human-centric concerns becomes crucial, as these factors collectively shape the unique challenges posed by BDA processing operations. A systematic literature review by Georgiadis and Poels ( 2022b ) identified various risks and potential harms to individuals, which were interpreted as specific to BDA. These risks were grouped into nine PTPs (Fig. 2 − 1). The PTPs encompass a broad spectrum of challenges related to personal data protection and privacy in BDA environments. For instance, PTP (1) addresses the uncertainty surrounding data ownership, driven by the challenges of maintaining consistent compliance across data controllers. PTPs (2)–(6) focus on detailed risk assessments, highlighting issues related to personal data processing, such as potential discrimination and lack of transparency due to AI algorithmic biases, and the unclear handling of personal data in the creation and utilisation of BDA systems. These include the emergence of new privacy risks, such as data breaches, which can directly threaten individuals’ rights and freedoms. PTPs (7)–(9) explore the detailed procedures of DPIAs, addressing concerns such as the limited extent of stakeholder involvement and the ambiguity of DPIA processes, particularly in the context of BDA. These touch points also examine privacy and data protection challenges from social and ethical perspectives, which, while sometimes viewed as peripheral to data protection, are increasingly recognised as vital in DPIA discussions. Furthermore, the DPIA process often encounters conflicts between individual rights, organisational interests, and broader societal benefits. Managing these complexities while ensuring compliance with relevant laws and regulations requires a nuanced and sophisticated approach. In their (2022b) study, Georgiadis and Poels examined a variety of existing PIA and DPIA solutions or methodologies to assess whether they sufficiently addressed the nine PTPs. The evaluation of personal data operations in a BDA context revealed that the current solutions fall short, as none of them adequately cover all PTPs. This gap in coverage led us to formulate the research question that drives the investigation in this paper. 3 Research Method Our research methodology aligns with established approaches in the information systems literature (Petter et al., 2007 ). It consisted of three subsequent research stages. We began with a systematic literature review to build a foundational knowledge base, including the nine PTPs that express BDA-specific risks to privacy and personal data protection. We next organised a Delphi study with experts to validate the PTPs and explore changes and improvements to the DPIA framework needed to properly assess the PTPs. We finally conducted semi-structured interviews with experts to validate the suggested improvements to the DPIA framework and solicit additional suggestions for unresolved issues. This mixed-methods approach (Venkatesh et al., 2013 ) allowed combining quantitative and qualitative data collection and analysis techniques to obtain a comprehensive understanding for answering our research question. For the methodology of the systematic literature review, we refer to (Georgiadis & Poels, 2022b ). In this section, we first present the methodology of the Delphi study and next that of the expert interviews. 3.1 Delphi Study The Delphi method was originally developed by the RAND Corporation in the 1950s as a forecasting tool for military applications (Rowe and Wright, 1999). Since then, it has evolved into a versatile, widely recognised research method that facilitates structured group communication, gathering expert opinions through a series of feedback rounds. While full anonymity is not achievable as researchers can identify panel members and responses to some extent, the Delphi method remains valuable for tackling research questions that benefit from the input of domain experts. This method ensures controlled, iterative rounds of feedback, enabling consensus-building or highlighting areas of disagreement (Hsu & Sandford, 2007 ). It is also particularly useful for generating insights in complex areas with limited information (Beiderbeck et al., 2021 ; Okoli & Pawlowski, 2004 ). In our research context, the limited information pertains to the validity of the nine PTPs identified by Georgiadis and Poels ( 2022b ). These PTPs stem from the analysis of literature across diverse fields discussing considerations for BDA and data privacy. However, none of these fields fully integrate both aspects nor do they offer enhancements to the DPIA methodology that account for these PTPs. The expert input gathered via the Delphi study aims to ensure that the proposed DPIA framework is relevant for BDA processing operations. As such, our panel included experts from unrelated domains such as AI, security, and law. Figure 3 − 1 shows that our Delphi study consisted of preparatory, intermediate, and final phases. In the preparatory phase , we established qualifications for expert participants, aiming for diversity in background (e.g., private sector, academia, and public organisations) and expertise relevant to the study topics. We confirmed these qualifications through a preliminary screening survey. Our goal was to include knowledge areas such as law, security, and computer science, and we selected a balanced panel (see Fig. 3 − 2) with careful attention to size, diversity, and inclusivity, ensuring broad coverage across these domains. Our strategy was influenced by methodological perspectives from Baker et al. ( 2006 ) and Mullen ( 2003 ), who stress the importance of diverse expertise and highlight the challenge of defining who qualifies as an ‘expert’ in Delphi studies. For our study, experts were defined as individuals with significant experience in relevant fields, ensuring a wide range of perspectives. Although there are no specific requirements for panel size, we aimed to invite approximately 15 experts, enough to include all relevant viewpoints while reducing the likelihood of bias (Förster & von der Gracht, 2014 ). In line with the recommended diverse panel composition, we extended invitations to over 30 experts from academia, public institutions, and industry sectors. These experts brought experience across a range of relevant fields, including BDA, AI, data science, information security, law, privacy, and data protection (see Fig. 3 − 2). Ultimately, 18 experts agreed to participate in our Delphi study. As illustrated in Fig. 3 − 2, 2 while the majority of our participants had a strong understanding of data protection and privacy, their collective expertise also spanned other critical domains related to our study. During the intermediate phase , we presented the experts with three successive questionnaires (one for each Delphi study round), including questions 3 that could be reused across rounds until consensus was reached. The initial two rounds primarily aimed to validate and potentially expand upon the PTPs identified by (Georgiadis & Poels, 2022b ), while also gathering the expert panel’s perspectives on crucial elements of a DPIA framework. The third round focused on proposed improvements to the DPIA, tailored specifically to the BDA context, using the PTPs agreed upon by the expert panel for their relevance to BDA-specific risks and harms and their significance for the DPIA. After each round, we shared with the experts a detailed report summarising the anonymised survey responses and consensus scores, along with our analytical insights. Given that our surveys included open-ended sections, the experts were encouraged to provide reflections beyond their initial predefined answer choices for each question. In the final phase , we completed the consensus statements and conducted a thorough analysis of the survey results, considering both statistical and qualitative aspects. An addition to our Delphi study design was the inclusion of individual interviews with experts (see sub-section 3.2). These interviews aimed to clarify specific findings and gain further insights, particularly concerning recommendations to improve the DPIA framework. The final phase also involved creating a comprehensive final report for the panel members and preparing a scientific paper for publication in a reputable journal. As the Delphi study research method is a consensus-seeking approach, an important research design choice is the definition of consensus criteria, which are specific measures used to analyse the responses of the expert panel and assess the level of agreement among participants. Essentially, these criteria serve as benchmarks for determining when the study can be concluded. They are crucial for evaluating the results of iterative Delphi study rounds, allowing for an objective assessment of expert agreement, which helps researchers ensure rigor and establish the reliability of their findings. Typically, these criteria are predetermined and may vary depending on the subject and purpose of the study. They can be quantitative, such as a specified percentage of agreement among experts, or qualitative, based on the stability of responses across rounds. For our research, we utilised four distinct consensus criteria (see Table 3 − 1), which were derived and adapted from the work of Van Looy et al. ( 2017 ). Within our framework, consensus can be classified as either positive or negative. A positive consensus indicates agreement on a PTP’s relevance or importance, while a negative consensus signifies disagreement. We define consensus as ‘strong’ when all criteria are met and ‘almost strong’ when three out of the four criteria align (see Table 3 − 2). Additionally, we examined the experts’ rationales provided in open-ended questions to identify potential discrepancies in their scores. Table 3 − 1: Consensus Criteria Condition Definition (all scores indicated on a 5-point Likert scale) # 1 35% of the experts strongly agree (i.e., score 5) or strongly disagree (i.e., score 1) # 2 70% of the experts agree (i.e., score 4 or 5) or disagree (i.e., score 1 or 2) # 3 The interquartile range (i.e., the difference between the highest and lowest scores of the middle 50% of experts when scores are ranked) is less than or equal to 1.25 # 4 No expert strongly disagrees/agrees if conditions (1) and (2), based on the frequencies, indicate a tendency towards either positive or negative consensus Table 3 − 2: Consensus Types with Conditions Consensus Type Condition Strong Consensus All four conditions are met: #1–#4 Almost Strong Consensus At least three criteria are met No Consensus Fewer than three criteria are met 3.2 Expert Interviews Following the Delphi rounds, our study employed semi-structured interviews to gain a deeper understanding of expert opinions on specific topics. The selection of the interivew topics was informed by the findings from the Delphi study. Topics were selected to explore complexities related to data controllership, stakeholder involvement, and transparency – issues identified during the Delphi study as requiring additional expert input. For instance, the question of data controllership emerged as a significant challenge, particularly in BDA projects, where the boundaries between data controllers and processors are often blurred. Similarly, while stakeholder involvement and transparency are critical for ensuring accountability and fairness in DPIAs, the Delphi study revealed a lack of strong agreement on best practices to address these challenges. By focusing on these unresolved areas, the interviews complemented the Delphi study and provided clarity on key PTPs, thereby refining the DPIA framework. A questionnaire consisting of nine questions that are briefly described in the Appendix section along with relevant background information, was distributed to a group of nine experts whose areas of expertise aligned with those in the Delphi study (see Fig. 3–3 2 ). Four of these experts participated in the Delphi study and agreed to provide further input to elaborate on their responses, while the remaining five were invited based on their established academic and professional expertise in the field. The nine interviewees were selected based on two main criteria: (1) their expertise in areas relevant to the PTPs, and (2) their willingness to engage in a detailed exploration of the study topics. Representing both the private sector and academia, the interviewees averaged 15 years of professional experience, with many holding senior positions such as professors and company directors, ensuring a broad range of perspectives. Respondents were encouraged to submit detailed written responses, and follow-up interviews were conducted remotely via video conferencing platforms to obtain additional clarification or delve deeper into their viewpoints. The answers to each of the nine questions was carefully analysed in terms of expert consensus, the variety of suggestions to address the question and conclusive insights. The expert consensus overview captures areas where experts share overwhelmingly similar viewpoints, highlighting agreed-upon principles, practices, or directions. The diverse suggestions discussion shows the range of ideas or solutions proposed by the experts in their responses, included in our analysis as potential areas for innovation or alternative approaches for future research. Finally, the conclusive insights encapsulate actionable conclusions drawn from our analysis. [2] The percentages in Figures 3-2 and 3-3 do not directly correspond to the number of participants, as each expert was able to indicate expertise in multiple knowledge areas. Consequently, some participants may appear in more than one category. [3]Copies of the questionnaires, along with the raw data from the survey collections, are available at: https://github.com/georggr/bda-dpia-research-data 4 Results We conducted three rounds of the Delphi study between March 2022 and February 2023, with individual interviews held in January and February 2024. The process was meticulously planned over these months, ensuring thorough analysis and dissemination of preliminary results to the experts, validating our Delphi study design at conferences (Georgiadis & Poels, 2022a , 2023b , 2023a ), and rigorously testing the iterative questionnaires that form the backbone of the consecutive Delphi study rounds. Our analysis in this paper extends the preliminary findings from the Delphi rounds reported in these conference papers by integrating them with practical recommendations for enhancing the DPIA in the context of BDA. Additionally, we incorporate new findings from expert interviews, which provide further depth and contextualisation of the Delphi results. We were acutely aware of the demands on our expert participants’ time, many of whom are leading figures in their respective fields. Thus, the intervals between the rounds were carefully determined to accommodate their busy schedules. Identifying qualified individuals as experts to participate in the panel is one of the most crucial steps in conducting our Delphi study. Knowledge of the study context or the issues under investigation does not automatically qualify someone as an ‘expert’. Therefore, we sought relatively impartial participants for our target group to ensure that the information received reflects current knowledge and perceptions. Participants should have a keen interest in our research and a willingness to engage in all planned rounds. The cooperation and engagement we received from our expert cohort were commendable. Not only did they bring a wealth of knowledge to our study, but their enthusiasm and willingness to delve deeply into the subject matter greatly enriched our findings. Through their input, we gained profound insights into the DPIA methodology, which clarified its nuances and intricacies and highlighted areas of controversy. As the study progressed, insights into the ongoing developments in BDA were particularly enlightening. One notable revelation was the potential implications and considerations surrounding the introduction of LLMs, such as ChatGPT and Google Bard, 4 into the public domain, which have gained massive popularity in recent months. 4.1 First Round In the first round, participants received a questionnaire divided into two sections. The first part consisted of demographic questions, which provided contextual background about the participating experts. This allowed us to understand the composition and diversity of expertise within the panel. By collecting and analysing this information, we ensured a comprehensive representation of opinions, reducing potential biases that could arise from an excessively homogenous group. To strengthen the credibility and legitimacy of our research, and in line with the principles of respect and transparency (Keeney et al., 2011 ), panel participants were required to give explicit consent by reading and approving the terms and conditions governing our Delphi study. The second section contained questions designed to explore experts’ views on both the significance and importance of the PTPs. Our evaluation aimed to establish whether a diverse group of experts, including BDA specialists and privacy and data protection experts, could reach a consensus on the importance of the PTPs in addressing privacy and personal data protection issues specific to BDA. Regarding importance, we sought to determine if there was agreement among experts on incorporating these PTPs into the DPIA process. It was essential to distinguish between relevance and importance. On one hand, a PTP considered relevant might not be viewed as sufficiently crucial or feasible to warrant specific attention within the DPIA. On the other hand, a PTP that was not regarded as relevant to addressing BDA-specific risks or harms might still be seen as important to consider in the DPIA, possibly due to its relevance in more traditional data processing scenarios. Alongside the Likert scale items, our survey included open-ended questions to gather clarifying comments from experts. The qualitative information obtained from these responses was crucial for providing context to the quantitative evaluations. Delivering an interpretative summary of these ratings to the participants is essential to the consensus-building approach of the Delphi study method, allowing participants to review their views in subsequent rounds. This additional feedback enhanced our dataset, revealing potential areas for further investigation and highlighting areas of disagreement. Ultimately, 14 experts fully completed the first-round questionnaire. Our analysis of the collected responses revealed a strong positive consensus regarding the relevance of PTP (2) ‘identification of individuals from derived data’ and PTP (3) ‘discrimination issues affecting moral or material personal matters’. Additionally, an almost positive consensus on relevance was observed for three other PTPs: PTP (1) ‘unclear data controllership’, PTP (4) ‘lack of transparency’, and PTP (7) ‘limited range of stakeholders’ involvement’. When assessing importance, PTP (1) and PTP (3) demonstrated an almost strong positive consensus. Notably, no PTPs elicited either a strong negative or almost strong negative consensus regarding relevance and importance. These findings are detailed in Table 4 − 1. Table 4 − 1: Delphi Study Results on Relevance and Importance of Privacy Touchpoints (PTPs) after Round 1 Measurements Level of Consensus Strong Positive Almost Strong Positive No Consensus Relevance PTP (2), PTP (3) PTP (1), PTP (4), PTP (7) PTP (5), PTP (6), PTP (8), PTP (9) Importance PTP (1), PTP (3) PTP (2), PTP (4), PTP (5), PTP (6), PTP (7), PTP (8), PTP (9) The insights gathered from the open-ended questions broadly confirm the analytical findings. The panel unanimously agreed that PTP (1), PTP (2), PTP (3), PTP (4), and PTP (7) represent risks specific to BDA. Notably, the discussion surrounding PTP (2) ‘identification of individuals from derived data’ highlighted the inherent challenges posed by BDA inference methodologies, which are exacerbated by the looming threats of algorithmic bias and discrimination. Experts also observed that safeguarding privacy through anonymisation presents significant hurdles due to its inherent complexity. Regarding PTP (1), ‘unclear data controllership’, experts highlighted the multifaceted nature of data control, emphasising the need to address both legal and non-legal considerations in data processing operations. Some experts suggested measures to mitigate this risk, such as assigning different data controllers at various stages of the data analysis process. In discussions surrounding PTP (4) ‘lack of transparency’, the importance of transparency in BDA was emphasised, particularly due to its correlation with the level of expertise in BDA and relevant protective technologies. However, despite ongoing research efforts in fair and explainable AI, transparency continues to be a significant concern. The introduction of PTP (7) ‘limited range of stakeholders involvement’ was considered relevant; however, experts acknowledged the operational challenges of including a diverse set of stakeholders in the impact assessment process. Furthermore, experts emphasised the significance of both PTP (1) and PTP (3) in the DPIA process, particularly in addressing BDA-specific risks. However, there was a consensus that all PTPs warrant attention, with their importance varying depending on the specific circumstances of each case. 4.2 Second Round The questionnaire for the second round, completed by 12 participants, retained the same items and 5-point Likert scales as the first round. The purpose of repeating the initial questionnaire was to determine whether the experts could reach an agreement on outstanding PTPs after reviewing the results from the first round. The criteria for consensus remained unchanged from the previous round. In addition to assessing the experts’ agreement on the relevance and importance of PTPs that had not achieved strong positive or negative consensus in the first round, we introduced questions aimed at enhancing the DPIA to address the identified PTPs, which will be the main focus of Delphi round 3. Specifically, participants were asked to share their perspectives on the key components or building blocks of a prospective DPIA framework that should be prioritised for adaptation in a BDA context. These perspectives were solicited based on a conceptual model we developed, drawing on the research of Kloza et al. (2019) (refer to Fig. 4 − 1). The conceptual model provides a structured representation of the fundamental elements and their interconnections within a DPIA framework. At its core, the framework is centred around ‘policy’, which establishes relevant ‘conditions’ and ‘principles’. These ‘conditions’ indicate specific scenarios or triggers that necessitate a DPIA, while the ‘principles’ embody core values such as fairness, transparency, accountability, and risk management, ensuring compliance with ethical and legal goals. Kloza et al. (2021) present a comprehensive list of 16 such ‘conditions’ and ‘principles’ applicable to various impact assessments. Generally, a DPIA follows a specific ‘method’ as a guide, outlining the procedures for conducting the assessment. To enhance and support this ‘method’, additional resources are available: ‘aids’ and ‘templates’ provide practical tools, while the ‘knowledge base’ offers valuable insights through best practices, past assessments, case studies, and expert opinions. Further guidance is offered through ‘guidelines’, which provide detailed instructions on utilising the provided tools and documentation templates in the DPIA process. An example of such a template is the assessment documentation itself, which can be voluntarily shared with the public or made accessible upon request. Before starting the second round, all participants were briefed on the results of the first round through a detailed feedback report that included both our statistical and qualitative analyses, along with summaries of the experts’ responses to the open-ended questions. The main goal was to familiarise the experts with the perspectives of other panel members on each question while ensuring confidentiality. From the results of the second round (see Table 4 − 2), strong or almost strong positive agreement for relevance was achieved for five of the seven remaining PTPs. In terms of importance, the agreement rate was even more positive, with strong or almost strong positive agreement for seven of the nine PTPs under consideration. However, no agreement was reached for two PTPs in each category. PTP (8), which addresses operational challenges stemming from procedural ambiguity, underscores a potential lack of practical guidance for evaluating privacy or data protection risks in BDA processing. In contrast, PTP (6) focuses on the improper handling of different types of privacy risks and data breaches, while PTP (7) discusses the limited scope of stakeholder participation. Together, these PTPs highlight the need for a comprehensive approach to addressing various privacy risks and protecting personal data, as well as the importance of broadening stakeholder engagement in impact assessments related to BDA. Table 4 − 2: Delphi Study Results on Relevance and Importance of Privacy Touchpoints (PTPs) after Round 2 Measurements Level of Consensus Strong Positive Almost Strong Positive No Consensus Relevance PTP (2), PTP (3), PTP (4), PTP (5) PTP (1), PTP (7), PTP (9) PTP (6), PTP (8) Importance PTP (1), PTP (2), PTP (3), PTP (5) PTP (4), PTP (6), PTP (9) PTP (7), PTP (8) Analysing the responses to the open-ended questions helped us interpret the relevance and importance scores provided by the experts. Regarding PTP (4) ‘lack of transparency’ and PTP (5) ‘increased scope leading to further processing incompatible with the initial purpose’, experts emphasised the risks associated with data opacity and intervenability in BDA. These risks often arise from a lack of understanding of personal data collection and processing procedures, especially given the complex nature of certain BDA techniques, some of which operate like a ‘black box’ (Zeng & Glaister, 2018 ). This underscores how BDA techniques can uncover various sensitive personal information, and many companies are reluctant to forgo the potential for extracting valuable insights. For PTP (1) ‘unclear data controllership’, experts linked the ambiguity surrounding data controllership to challenges faced by controllers in discerning their obligations. This issue often stems from a limited understanding of the internal mechanics of BDA. One expert also highlighted disparities in the manuals and guidelines established by national data protection authorities (DPAs) across different EU/EEA Member States. Regarding PTP (7) ‘limited range of stakeholder involvement’, it was suggested that, barring exceptional circumstances (e.g., criminal suspects), the viewpoints of various stakeholders should consistently be incorporated. Concerning PTP (9) ‘treatment of indirect privacy harms’, while the ethical and societal implications are significant, the primary focus in an impact assessment should invariably pivot towards direct harms. When it comes to the level of importance, the panellists expressed similar views. The only exception was PTP (6) ‘improper treatment of different types of privacy risks and data breaches’, where no consensus was reached on its BDA-specific relevance; however, most experts still considered it an important aspect of the DPIA when applied in a BDA context. While such ambiguity may reflect doubts about this PTP’s relevance voiced by the experts, we decided to reassess PTP (6) in Delphi Round 3 to determine if this ambiguity persists. In their responses to the open-ended questions, experts suggested that BDA DPIAs require a more comprehensive scoping approach. One expert noted that this need has led some consulting firms to develop customised PIA or DPIA methodologies. Conversely, other experts believe that the existing templates within these methodologies are sufficient. They do not attribute the perceived shortcomings to the templates themselves but rather to the limited engagement of certain DPAs in the assessment process due to a lack of expertise. While there is consensus that privacy and personal data protection risks, including data breaches, frequently coexist in the realm of BDA, their interrelation is not always clear-cut. Additionally, the practicalities of involving a wider range of stakeholders in the assessment process can be challenging. However, including external participants is advantageous, particularly in identifying potential breaches that could elude internal stakeholders. When analysing the consensus results across rounds regarding response stability – which assesses the consistency of experts’ opinions in consecutive Delphi study rounds – it was evident that there was a significant increase in positive feedback about the relevance and importance of PTP (4) ‘lack of transparency’ and PTP (5) ‘increased scope leading to further processing incompatible with the initial purpose’ (refer to Figs. 4 − 2 5 and 4 − 3). Agreement on importance also showed a similar rise for most PTPs. In contrast, PTP (6) ‘inadequate management of varied privacy risks and data breaches’ and PTP (8) ‘operational challenges stemming from procedural ambiguity’ received lower relevance scores in the second round. Furthermore, PTP (8) also received lower importance scores in this round. This observation aligns with the results of our second-round consensus analysis, as the expert panel did not reach a consensus on including PTP (8) in the DPIA for BDA. When discussing which aspects of the DPIA framework displayed in Fig. 4 − 1 could be enhanced or extended, along with their associated priorities, the experts identified the highest priority areas as ‘guidelines’, ‘knowledge base’, and ‘method’. Conversely, the ‘software’ tool designed to facilitate impact assessments was deemed to have the lowest priority. Regarding expert involvement in the panel, the overall response rate was 70.5%, slightly exceeding the 70% threshold required in any Delphi round (Van Looy et al., 2017 ). Minimising expert dropout is generally essential in this process. In this round, only one expert explicitly requested to resign from the panel, citing family obligations and a lack of time as reasons for withdrawing. 4.3 Third Round The questionnaire for the third round was completed by 10 participants. This round consisted of the following two parts: Part A: We asked the experts to conduct a final review of the PTPs that had achieved a strong or almost strong positive consensus on either relevance or importance but not on both criteria in Round 2. Specifically, this pertained to PTP (6) ‘inadequate management of varied privacy risks and data breaches’ and PTP (7) ‘limited range of stakeholder involvement’, for which there was no consensus on relevance and importance, respectively. Part B: We gathered feedback from the experts on suggestions to enhance the DPIA framework, ensuring alignment with the PTPs already identified as relevant and important in Rounds 1 and 2. To assist with this, we referred to the guidelines outlined in DPIA WP29 (2017), the official guide for organisations conducting a DPIA to identify, analyse, and mitigate high-risk data processing activities, ensuring GDPR compliance and enhancing privacy protection. 4.3.1 Part A Table 4 − 3 shows the results of Round 3. PTP (6) achieved a strong positive consensus on relevance, and the nearly strong positive consensus on importance from Round 2 was confirmed. Virtually all experts expressed concerns about the high likelihood of data breaches associated with the use of BDA. They attributed this risk to the nature of analytics, which involves handling large amounts of personal data and utilising new and untested techniques and algorithms to uncover new information. While noting that not all risks are necessarily negative, experts emphasised the importance of thoroughly assessing and managing them. However, the complexity of BDA presents significant challenges in preventing potential violations and breaches, including the evolving landscape of data protection laws, which could affect the level of protection provided. Regarding the involvement of external stakeholders in the DPIA – PTP (7), which has now almost reached a strong positive consensus on its importance – experts concluded that engaging external stakeholders is not always essential or feasible. Stakeholders, such as data subjects, processors, controllers, and data analysts, should be informed about the issues, but involving all of them in the risk analysis process may present challenges. On the other hand, including external parties can offer valuable insights into privacy and data protection concerns and enhance transparency. Nevertheless, practical aspects, such as determining whom to include, ensuring their active participation, and addressing potential resistance from controllers, could make this approach challenging to implement. The significance of involving external stakeholders may vary depending on the context and scope of the DPIA. Finally, based on the results from the previous rounds, PTP (8) was excluded from further evaluations. The expert panel did not reach a consensus on the operational challenges arising from procedural ambiguities within the DPIA. However, given the differing perspectives on this issue, we plan to explore it further during individual interviews with the experts. This approach will provide a more detailed understanding of the reasons behind their viewpoints. Table 4 − 3: Delphi Study Results on Relevance and Importance of Privacy Touchpoints (PTPs) after Round 3. Measurements Level of Consensus Strong Positive Almost Strong Positive No Consensus Relevance PTP (2), PTP (3), PTP (4), PTP (5), PTP (6) PTP (1), PTP (7), PTP (9) PTP (8) Importance PTP (1), PTP (2), PTP (3), PTP (5) PTP (4), PTP (6), PTP (7), PTP (9) PTP (8) 4.3.2 Part B To identify ways to enhance the DPIA framework, we reviewed the experts’ input on the prioritisation of DPIA components based on their relevance to addressing the PTPs, as outlined in Section 4.2 and illustrated in Fig. 4.1. Based on the feedback from Round 2, the four key components, ranked in descending order along with the percentage of positive feedback rounded to the nearest whole number, are: ‘knowledge base’ and ‘method’ (33%), and ‘guidelines’ and ‘templates’ (17%). Table 4 – 4 presents the priority levels received based on expert feedback in Round 3, along with explanations of how these priority assessments influenced our suggestions to enhance the DPIA framework. Regarding the definition of ‘Essential’ and ‘High Priority’, the former refers to DPIA components that are critical for the effective functioning of the DPIA framework. On the other hand, the latter (‘High Priority’), indicates DPIA components that are important for improving the efficiency, transparency, and practical application of the DPIA framework. Table 4 4: Prioritisation of DPIA Framework Components Based on Expert Feedback DPIA Framework Component Priority Level Based on Expert Feedback How Feedback Can Influence Suggestions Conditions 42% High Priority, 0% Essential Conditions were not prioritised as essential, indicating a need for further clarification of scenarios for initiating DPIAs. Guidelines 42% High Priority, 17% Essential High priority and essential; experts emphasised the need for detailed guidelines to improve transparency and stakeholder engagement. Knowledge Base 25% High Priority, 33% Essential Experts prioritised the knowledge base to support practical applications in BDA with case studies and best practices. Method 33% High Priority, 33% Essential The method received strong consensus; experts stressed its importance in structuring DPIA processes, particularly in complex BDA contexts. Policy 17% High Priority, 0% Essential While deemed important, policy changes were not ranked as essential, suggesting it may need further refinement or specificity. Principles 50% High Priority, 8% Essential Principles were recognised as important, but received lower essential prioritisation, reflecting their supportive role in the DPIA process. Software Tools 17% High Priority, 0% Essential Software tools were ranked lower in priority, indicating that while useful, they may not be critical in all contexts. Templates 50% High Priority, 17% Essential Templates were viewed as highly important for standardising the DPIA process and were ranked as essential by some experts. Guided by the prioritization results, experts were provided with suggestions for each of the established PTPs. For example, 6 regarding PTP (1) ‘unclear data controllership’, we proposed further developing the components based on the tiered, layered, and staged consent model (Bunnik et al., 2013 ). This approach would enhance the understanding and completeness of consent for BDA operations in line with established guidelines, addressing the complexity of managing such consent and ultimately creating a new standardised template or consent management platform as a software support tool. Another example relates to the ‘knowledge base’ and ‘method’ components, where the need for dynamic, case-based learning resources was emphasised, particularly to tackle the challenges of de-identification and algorithmic transparency identified in PTPs (2) and (4). This feedback directly influenced the decision to prioritise the expansion of the ‘knowledge base’ as the top-ranked component. Our key findings regarding our suggestions to enhance the DPIA framework are: PTP (1) ‘unclear data controllership’: Responses reflected varied opinions on the effectiveness of current data controllership mechanisms within data protection law. Concerns were raised about the complexity of the consent model, particularly regarding BDA, and the need for improvements in guidelines. Some experts noted specific gaps in data protection laws and the impracticality of the consent model, citing challenges in obtaining ‘informed consent’ due to its complexity. The clarity of roles in data controllership emerged as a significant concern, with some experts highlighting organisations’ struggles in this area. Additionally, there were calls for refining regulations to better account for emerging technologies like ChatGPT and deepfakes, although reservations about potential category overlaps under the EU AI Act’s layered approach were also expressed. PTP (2) ‘identification of individuals from derived data’: Experts emphasised the need for more concrete guidelines, especially concerning the anonymisation and de-identification of data. While acknowledging the challenges inherent in these processes – particularly in BDA contexts – there was a clear sentiment that de-identification does not equate to complete anonymisation. Some experts expressed scepticism about the real-world significance of re-identification risks, suggesting they might be more theoretical than practical. There were positive views on the DPIA incorporating more specific elements, with suggestions to combine aspects of ISO standards and consider the proposed EU AI Act. However, a call for clarity on risk assessment types distinguishing between privacy and personal data protection risks was made. Given the vast amounts of personal data available online, there is a recognised need for effective de-identification measures. Nevertheless, concerns persist about the feasibility of achieving complete anonymisation, particularly from the perspective of regulatory bodies. PTP (3) ‘discrimination issues affecting moral or material personal matters’: Responses generally supported the incorporation of an ethical and social impact assessment framework for BDA, emphasising the importance of understanding the consequences for vulnerable populations and promoting diversity and inclusion. Experts acknowledged the risks posed by human involvement in algorithm design and provided additional references to ensure fair AI. However, challenges in ensuring fairness in AI beyond algorithmic considerations were noted. PTP (4) ‘lack of transparency’: Experts unanimously agreed on the importance of transparency in BDA. One expert pointed out that transparency can sometimes appear illusory, particularly within the context of data protection law. While regulators prioritise transparency, it was noted that data subjects may not place the same emphasis on it. Differentiating between various roles within organisations – such as managers, data analysts, and model users – underscored the critical need for transparency across these functions. The inherent challenges in achieving genuine transparency in BDA and AI were highlighted, with specific concerns raised about ‘black box’ algorithms. Reference was made to the work of Barredo Arrieta et al. ( 2020 ), which underscores the broader literature on fair AI, focusing primarily on algorithmic intricacies. Although the majority of experts agreed that the proposed solution represents a step in the right direction, there was consensus that further research is necessary to effectively implement transparency in AI. Additionally, the acknowledgement of systemic risks in BDA suggests that solutions may only provide limited relief. In summary, while transparency is considered crucial, its practical implementation within BDA and AI remains a multifaceted challenge that may require more nuanced approaches beyond merely opening the ‘black box’. PTP (5) ‘increased scope leading to further processing incompatible with the initial purpose’: Experts voiced concerns regarding excessive regulation and the potential proliferation of analyses and frameworks while also recognising the necessity for improvement. One expert highlighted the risks associated with additional frameworks and requirements, which could overwhelm the process and potentially divert attention from actual data analysis. Another expert expressed scepticism about the efficacy of these principles for data subjects, citing a specific opinion on purpose limitation (WP29, 2013 ) that has not yet been endorsed. There was a suggestion to consider ‘purpose limitation’ as a principle to address these concerns, along with a recommendation to examine relevant Court of Justice of the European Union cases. In summary, while there was consensus on the importance of minimising data collection and processing solely for legitimate purposes, questions remain regarding the practicality of conducting multiple complementary assessments. The responses from the Delphi study primarily emphasised the importance of addressing societal and ethical concerns in BDA. Many experts supported the idea of providing clear guidance, with some mentioning the fairness, accountability, and transparency framework, as well as the systematic description in the DPIA. A distinction was made between the scope of the DPIA and broader societal concerns, noting that the primary focus of the DPIA is on individual rights as defined in the Charter of Fundamental Rights of the European Union. Including other societal issues could potentially transform the DPIA into an integrated impact assessment. While some respondents recognised the value of addressing these broader concerns, others pointed out challenges in assessing certain societal impacts, such as quantifying the stress or anxiety experienced by individuals affected by identity theft. Two experts either expressed general agreement or admitted unfamiliarity with the topic. In terms of expert panel participation, we received responses from 10 participants in the third round. The decrease in participation can primarily be attributed to time constraints faced by the experts, many of whom requested deadline extensions. As the study progressed and the questions became more detailed, some experts felt unable to respond to these in-depth queries due to a perceived lack of relevant expertise or because they believed they did not possess the appropriate knowledge to address them. Although the number of experts decreased from 14 to 10, we accounted for this reduction when interpreting the consensus. Delphi studies often experience attrition, and a smaller number of experts in later rounds may impact the stability of consensus (Diamond et al., 2014 ; Trevelyan & Robinson, 2015 ). However, it is generally accepted in Delphi studies that as long as the group remains sufficiently diverse and expert participation is consistent, the final consensus remains valid. In our case, the remaining experts still represented key areas of expertise, and their feedback was consistent with earlier rounds, indicating that the smaller group did not significantly skew the results. We were not informed of other reasons for reduced participation that have been documented in the relevant literature, such as feedback frustration (Skulmoski et al., 2007 ), lack of incentive (Keeney et al., 2011 ), technical issues (Brady, 2015 ), and loss of anonymity (Linstone & Turoff, 2002 ). 4.4 Interviews with Experts Following the Delphi study, a targeted group of experts participated in semi-structured interviews, focusing on areas where consensus was not achieved. Specifically, these interviews explored topics related to PTP, such as data controllership, stakeholder involvement, and transparency, which were identified in the Delphi study as needing further examination. In other words, the interviews concentrated on areas where experts raised concerns or expressed divergent views in the Delphi rounds. This qualitative approach aimed to gain deeper insights and pinpoint specific elements of the DPIA requiring enhancement to adequately assess the PTPs. Consequently, the interviews consistently focused on improving the effectiveness of the DPIA for BDA operations. Nine experts, representing all key disciplines relevant to our study – such as AI, data protection law, BDA, cybersecurity and governance – took part in the interviews, which were conducted and analysed individually. Saturation of key insights or core ideas was reached after these interviews, leading to the decision to conclude this phase of data collection without soliciting additional interviews. Importantly, each interview began with a questionnaire and was followed by a one-on-one conversation for specific clarification, making the interviews semi-structured. Below, we present the convergence and divergence of the experts’ opinions for each question, along with a synthesis of the discussions leaning towards conclusions for each. By linking the interview findings to the components of the DPIA framework, we aimed to provide a more detailed understanding of how these components can be improved or extended to address the identified PTP risks. 1) Procedural Indeterminacy and BDA Complexity Consensus Overview Experts acknowledge the complexities and challenges inherent in procedural uncertainty within BDA contexts. They agree that navigating the DPIA process can be difficult due to the intricate and often evolving nature of BDA projects. There is a consensus that the DPIA process, when applied to BDA, would benefit from enhanced guidance, support tools, and resources tailored to address BDA’s unique complexities and the associated risk factors linked to the PTPs. While flexibility within the fundamental DPIA structure is valued, experts believe that procedural uncertainty is a key concern for practitioners. Consequently, the answers to this question highlight the need for clearer and more accessible guidance to help users effectively manage and mitigate these complexities. Diverse Suggestions While two experts regarded procedural indeterminacy as a less significant issue, the majority proposed specific solutions. These include guidelines, repositories, and checklists – such as the AI-HLEG’s Ethics Checklist for Trustworthy AI (EC, 2019 ) – which provide practical advice and tangible real-world examples. This indicates a preference for a structured approach to mitigate uncertainties within the DPIA process. Experts also emphasised the need for a comprehensive list of potential harms, advocating for a more risk-centric approach. Adapting models like FAIR (Factor Analysis of Information Risk) (Freund & Jones, 2014 ) and ISACA’s RiskIT framework (ISACA, 2020 ) for BDA risk quantification could further reduce ambiguity. Conclusive Insights The consensus favours enhancing DPIA guidance for practitioners. Whether through simplified guides, case studies, or clear risk listings, the goal is to make the DPIA process less intimidating and easier to follow. While there is some debate about how to address ‘indeterminacy’ directly, all experts emphasise the necessity of providing clearer resources to help practitioners understand the inherent complexities of BDA projects. These enhancements would primarily enrich the DPIA knowledge base, guidelines, and templates. 2) Enhancing Guidelines for BDA Consensus Overview Experts strongly agree on the need for enhanced DPIA guidelines specific to BDA. This reflects a common belief that the distinctive complexities of BDA require customised guidance, particularly focused on conducting thorough risk assessments tailored to BDA scenarios. Such enhancements are essential to ensure a robust and efficient DPIA process in this domain. Diverse Suggestions A comprehensive risk identification process is crucial for developing enhanced DPIA guidelines. BDA-specific guidelines should consider the unique aspects of BDA projects, emphasising the vital role of risk assessment. Additionally, they should clearly outline the responsibilities of data controllers and processors to ensure compliance with BDA initiatives. Understanding data flows is another key element for improved DPIA guidance. This involves thoroughly mapping data processes and establishing authoritative oversight bodies. One expert proposed creating a ‘BDA Body of Knowledge’ to facilitate understanding of the entire data lifecycle within the DPIA framework. Furthermore, taking inspiration from the AI Act’s emphasis on human rights impact assessments (FRA, 2021 ), guidelines should extend beyond data protection to address broader risks to fundamental rights arising from BDA technologies. Conclusive Insights Experts concur on the necessity to refine DPIA guidelines specifically for BDA projects, ensuring they align with European data protection legislation and the emerging AI Act. While the proposed strategies vary (see diverse suggestions), there is a strong consensus that enhanced BDA-specific guidance is essential for effectively navigating the complexities of this domain. These guidelines would ensure that DPIAs are not only compliant but also effective in identifying and mitigating the unique risks associated with big data, as highlighted by the PTPs. 3) Expanding the Knowledge Base for DPIA in BDA Consensus Overview Experts widely recognise the importance of expanding the knowledge base that supports the DPIA process in the context of BDA. This expansion involves developing resources, case studies, and examples tailored to the complexities of BDA, enabling practitioners to conduct more informed and effective assessments. Diverse Suggestions Experts propose creating a publicly available database containing relevant BDA case studies, including both successful and unsuccessful DPIA examples. Such a database would provide valuable insights and lessons for upcoming projects, fostering knowledge sharing and best practices within the DPIA community. Furthermore, there is a broader need for comprehensive guidance that integrates various perspectives (e.g., legal, ethical, technical, operational) while emphasising thorough risk assessment within BDA. Establishing a multi-stakeholder task force to develop BDA use cases for DPIA could lead to the creation of a code of conduct. Additionally, organising periodic forums by authoritative bodies, such as the European Data Protection Board, could facilitate knowledge exchange among stakeholders. These initiatives would significantly enhance the DPIA knowledge base for BDA. Conclusive Insights : Experts strongly agree on the necessity of enhancing the knowledge base for conducting DPIAs within BDA contexts. Although specific suggestions may vary, the consensus is clear: comprehensive and accessible resources are crucial. Such resources would enable practitioners to conduct customised and effective DPIAs, considering the diverse range of risks encompassed by the PTPs and the constantly evolving data analytics landscape. 4) DPIA Methodological Adaptations for BDA Consensus Overview Experts unanimously agree that the fundamental DPIA methodology outlined in Article 35 of the GDPR should remain unchanged. However, they emphasise the need for a robust BDA-specific knowledge base, which would include detailed guidelines, sector-specific risk scenarios, and practical use cases tailored to the DPIA process. This focus on practical resources aims to better equip practitioners to manage DPIAs in the context of BDA projects. Additionally, experts advocate for a shift from mere compliance to a more practical approach to risk assessment, grounded in a broader ethical impact assessment framework. Diverse Suggestions While experts recognise the limitations of the current DPIA framework for BDA, they advise against making drastic changes. Instead, they propose methodological adaptations to address the PTPs. These improvements include Seeking input from a variety of stakeholders to gain a broader perspective on risks. Creating customised tools, such as checklists and guidance, tailored to specific domains. Broadening the scope beyond GDPR to encompass ethical and societal consequences. Considering integration with frameworks such as the FRIA outlined in the AI Act. This strategy aims to create thorough DPIAs that not only comply with the law but also address the unique ethical and impact-related aspects of BDA projects. Conclusive Insights Experts provide clear guidance on effectively conducting DPIAs in BDA contexts. They stress the importance of establishing a comprehensive knowledge base that includes BDA-specific guidelines, risk assessment tools, and practical examples. Prioritising the identification of contextually relevant risks and offering practical solutions is crucial. Furthermore, experts recommend that DPIAs adhere to a holistic impact assessment model that considers ethical and societal considerations alongside legal requirements. Given the evolving regulatory environment, aligning with emerging frameworks like the AI Act is essential. This tailored approach ensures that existing DPIA methodologies can adapt to the specific needs of BDA, promoting both legal compliance and ethical best practices in this dynamic field. 5) Balancing Rigour and Flexibility in DPIA for BDA Consensus Overview Experts agree that achieving a balance between rigour and flexibility is essential for conducting effective DPIAs within BDA contexts. The GDPR’s accountability principle empowers data controllers to tailor DPIAs to meet diverse needs and risks. While there is no universal approach, experts emphasise that both rigour and flexibility are crucial components of an effective DPIA strategy in the BDA domain. Diverse Suggestions Experts propose several strategies to achieve this balance, including the implementation of a ‘four-eyes’ review/approval principle for the DPIA before launching BDA processing within the organisation. These strategies encompass Stakeholder Consultation : Seeking input from a broad range of perspectives to inform the DPIA process. Scaled Assessments : Introducing preliminary or ‘light touch’ evaluations based on assessed risk levels. Tool Support : Utilising tools like certification schemes (e.g., Europrivacy) for tailored BDA analysis. Principle-Driven : Establishing clear principles and evaluation criteria for conducting DPIAs. Risk-Focused : Advocating for a less rigid, outcome-driven approach centred on risk management rather than purely on documentation. These diverse strategies illustrate the potential for tailoring DPIAs to BDA projects while maintaining both rigour and flexibility. Conclusive Insights Achieving a balance between rigour and flexibility in BDA DPIAs necessitates a nuanced approach. Organisations should prioritise the adoption of BDA-specific risk assessment tools and guidelines, adjusting the intensity of DPIAs according to the specific context. To promote adaptability without compromising data protection, it is crucial to cultivate a privacy-by-design mindset. This involves moving beyond a mere ‘checklist’ mentality, embracing continuous risk assessment practices, and integrating DPIA principles throughout the development lifecycles of BDA projects. By adopting these strategies, organisations can effectively manage risks while remaining agile and compliant in the dynamic BDA landscape. 6) Incorporating Diverse Stakeholder Perspectives in a BDA DPIA Consensus Overview Experts agree that while the DPIA primarily functions as an internal risk assessment tool for data controllers, there is significant value in incorporating diverse stakeholder perspectives. This can include data subjects, data controllers, processors, privacy experts, legal advisors, and regulatory authorities. 7 However, the need for a comprehensive definition of stakeholders is emphasised. Diverse Suggestions To involve stakeholders from varied backgrounds, experts suggest conducting surveys, interviews, and focus groups led by the DPIA assessor. Some propose pilot projects that include post-DPIA stakeholder engagement monitoring, while others recommend structural changes such as mandatory stakeholder lists, analysis requirements, or reinterpreting Article 35(9) to standardise consultation practices. Additionally, experts advocate for expanding the stakeholder definition to encompass those indirectly affected by BDA processing. Conclusive Insights Incorporating stakeholder perspectives in BDA DPIAs necessitates careful consideration of the project’s nature, risk level, and potential impacts on specific groups. Organisations would benefit from sector-specific guidance on identifying key stakeholders and methods for their inclusion. Importantly, while stakeholder input is valuable, it should not overshadow the data controller’s primary responsibility for conducting a thorough DPIA. 7) Addressing Ethical and Societal Concerns in a BDA DPIA Consensus Overview Expert feedback highlights the critical importance of addressing the ethical and societal concerns unique to BDA. While the GDPR provides a foundational framework, the potential for broader harm posed by BDA necessitates a DPIA process that transcends mere legal compliance. A robust DPIA methodology must thoroughly engage with both regulatory requirements and the ethical and societal questions raised by BDA projects. Diverse Suggestions Experts propose various approaches for integrating ethical and societal considerations into BDA DPIAs Checklists : Covering aspects such as data governance, bias mitigation, and alignment with broader objectives like the UN Sustainable Development Goals (SDGs). Responsible AI Inspiration : Prioritising principles such as non-discrimination, protection of freedoms, and upholding human dignity. Beyond ‘Ethics’ : Emphasising measurable social values and the prevention of harm. Managing Scope : Some experts caution against extending DPIAs too broadly, suggesting the need for separate frameworks to conduct in-depth ethical analyses alongside DPIAs. These diverse perspectives underscore the necessity of a balanced approach that integrates ethical and societal considerations without compromising the core functions of DPIAs. Conclusive Insights Experts emphasise the importance of incorporating ethical and societal evaluations into BDA DPIAs. The focus should be on recognising actual harms such as discrimination, fairness issues, and social inequalities. Organisations can refer to responsible AI principles and fundamental rights frameworks (such as the AI Act) and possibly align with broader goals like the UN SDGs. To maintain the efficiency of DPIAs, a systematic approach is essential. This may require integrating ethical considerations proportionally with concurrent, thorough assessments for high-risk BDA projects. Such a holistic strategy aims to ensure responsible BDA execution that upholds individual rights and enhances societal welfare. 8) Enhancing Transparency and Accountability in a BDA DPIA Consensus Overview Experts strongly agree on the importance of transparency and accountability in BDA DPIAs. They emphasise the need for proactive communication with stakeholders, including public outreach about the project, its impacts, and how stakeholders can provide input. Furthermore, experts stress the importance of demonstrating accountability through documented risk assessments, well-defined mitigation plans, and clearly stated ownership at all stages of BDA implementation. Diverse Suggestions Experts propose a multifaceted approach to enhance transparency and accountability in BDA DPIAs. Key strategies include Public or Internal (Data Protection) Notices : Providing stakeholders with information about the project’s purpose, potential impact, and avenues for feedback. Meticulous Risk Analysis : Conducting thorough assessments of the risks associated with BDA projects and developing actionable mitigation plans. Specialised Guidelines : Developing BDA-specific tools and guidelines, potentially in collaboration with a dedicated task force, to promote transparency and accountability. Supervisory Authority Role : Engaging supervisory authorities in awareness campaigns and promoting best practices to enhance transparency and accountability. AI Act Inspiration : Drawing inspiration from principles outlined in the AI Act, such as those related to data quality and bias, and incorporating them into BDA DPIA documentation. This comprehensive approach aims to strengthen trust and responsibility within the BDA landscape. Conclusive Insights The consensus highlights the critical importance of improving transparency and accountability in a DPIA process tailored to BDA. This necessitates a proactive approach, with organisations openly engaging with stakeholders, providing clear project explanations, and actively soliciting feedback. To implement these principles, it is essential to thoroughly document assessments, risks, and mitigations, and clearly define ownership for oversight. Crafting BDA-specific guidelines and tools, as well as involving supervisory authorities in promoting best practices, are crucial for fostering a culture of trust within the BDA domain. Transparency and accountability go beyond mere compliance; they exemplify responsible BDA usage for the benefit of individuals and society. These principles are essential for ensuring that BDA technologies are developed and deployed responsibly, respecting privacy, upholding ethical standards, and contributing positively to society. 9) Future-proofing the DPIA process for BDA Consensus Overview Experts emphasise the need for the DPIA to evolve into a flexible framework that can adapt to the rapid advancements and innovations in BDA. They recognise that AI serves a dual purpose in BDA DPIAs, acting both as a tool for conducting assessments and as a key component of the assessment itself. While a complete overhaul may not be necessary at this stage, the DPIA must continuously develop to remain relevant in the changing landscape of BDA technologies and associated risks. Future-proofing involves anticipating challenges, incorporating adaptability into assessment procedures, and regularly updating the framework to address new risks and opportunities, thereby ensuring privacy and data security. Diverse Suggestions Experts propose several strategies to future-proof DPIAs for BDA Update Risk Catalogues : Stay informed about emerging BDA risks. Expand Impact Assessments : Incorporate societal values alongside data protection considerations. Develop Sector-Specific Use Cases : Provide tailored guidance for key BDA industries. Require Expertise : Ensure that DPIA practitioners possess the necessary knowledge in both privacy and BDA. Focus on Explainability : Mandate clear reasoning within BDA systems to enhance transparency. Regular Reviews : Continuously update DPIAs in response to technological advancements and evolving data usage. These actions aim to ensure the relevance of DPIAs amidst the rapid innovation occurring in the BDA field. Conclusive Insights Experts emphasise the critical importance of future-proofing DPIAs to keep pace with the ever-changing nature of BDA. This necessitates a shift towards a flexible, adaptable approach within organisations. Recognising the dual role of AI – both as a tool for conducting DPIAs and as a subject of assessment – is essential. Guidelines, resources, and risk catalogues must be consistently updated to align with emerging BDA technologies and their associated risks. Regular reviews of DPIAs, triggered by changes in technology or data usage, will help maintain their relevance. Furthermore, emphasising overarching principles of risk, ethics, and societal considerations will establish a stronger foundation for DPIAs to effectively address emerging challenges in the dynamic BDA landscape. Table 4 –5 summarises the consensus levels for the questions discussed by the experts regarding the necessary improvements and adaptations for DPIAs in the context of BDA. Although there is no universally accepted standard for categorising percentage ranges in consensus levels (Hasson, 2000 ), we classified ‘unanimous agreement’ as 100% agreement, ‘strong consensus’ for agreement above 75%, and ‘moderate consensus’ for the range of 50–74% agreement, based on the responses gathered during the interviews. This breakdown clarifies areas where expert opinions were closely aligned and where a greater diversity of perspectives emerged. Table 4 5: Summary of Consensus Levels Across Questions Question Consensus Level Agreement (%) Procedural Indeterminacy in BDA DPIAs Moderate Consensus 60 Enhancing Guidelines for BDA Strong Consensus 70 Expanding the Knowledge Base Strong Consensus 80 Methodological Adaptations for BDA DPIAs Moderate Consensus 50 Balancing Rigour and Flexibility Unanimous Agreement 100 Incorporating Stakeholder Perspectives Mixed Consensus 50 Addressing Ethical and Societal Implications Strong Consensus 75 Enhancing Transparency and Accountability Strong Consensus 80 Future-Proofing DPIA for BDA Strong Consensus 85 [4] As of February 2024, Google Bard has been renamed Gemini. [5] PTP (2) and (3) are not included in this graph as they received strong consensus in the first round and were therefore not subject to further evaluation in round 2. [6] For additional details on the remaining PTPs, please refer to the information provided in the third questionnaire, available at: https://github.com/georggr/bda-dpia-research-data [7] This typically refers to the prior checks and consultations with Supervisory Authorities, especially when the results of the DPIA indicate high residual data protection risks. 5 Lessons Learned and Recommendations for Improving the DPIA Framework for BDA This section translates the findings from the Delphi study and expert interviews into practical recommendations for adapting the DPIA framework to the BDA context, specifically addressing the PTPs validated in the Delphi study. We begin by summarising key lessons learned, highlighting crucial insights about the complexities of BDA, its nuanced privacy risks, and the shortcomings of the current DPIA framework. Based on this analysis, we provide specific recommendations for developing a more robust DPIA methodology tailored to BDA. Finally, we explore how the DPIA framework can be adjusted to incorporate these improvements, ensuring compliance with both legal and ethical aspects of BDA implementation. By implementing these insights and recommendations, the DPIA framework can better tackle the challenges and opportunities presented by BDA. This will not only strengthen data privacy and protection within BDA but also promote its sustainable and ethical use for innovation and development. 5.1 Lessons Learned Our study uncovered several complexities in BDA, highlighted data protection risks, and revealed limitations in the current DPIA framework, which are outlined below: Complexity of BDA : The integration of BDA into various sectors creates a complex landscape that poses significant challenges for personal data protection and privacy. BDA’s capacity to process vast volumes of data at high speeds introduces unique risks, underscoring the need for a DPIA framework that effectively addresses these complexities. Privacy and Data Protection Risks : The research identified specific PTPs that represent BDA-specific risks, including issues related to data controllership, identification from derived data, discrimination, transparency, and stakeholder involvement. The varying levels of consensus on these PTPs across the Delphi study rounds indicate the nuanced understanding required for effective mitigation. Current DPIA Limitations : The Delphi study and expert interviews revealed that the existing DPIA framework may not fully capture the intricacies and risks associated with BDA. This includes gaps in addressing the full scope of BDA-specific risks, procedural ambiguity, and the evolving nature of data protection laws. Expert Consensus on Improvement Needs : There is strong consensus among experts regarding the need to enhance the DPIA framework to increase its relevance for BDA. Recommendations include clearer guidelines, expanded knowledge bases, methodological adaptations, and a balance between rigour and flexibility. 5.2 Recommendations for Improving the DPIA Framework Based on our understanding of the challenges and limitations identified, we propose the following recommendations: Enhanced Guidelines and Clearer Procedures : Develop specific DPIA guidelines for BDA that provide clearer, actionable steps for identifying and mitigating risks. Include detailed risk assessment criteria and processes tailored to the unique challenges of BDA, as outlined in the PTPs. Expanded Knowledge Base : Create a comprehensive knowledge base that includes case studies, best practices, and lessons learned specific to BDA. This resource should be easily accessible and routinely updated to reflect the latest developments in BDA technologies and data protection regulations. Methodological Adaptations : Modify the DPIA methodology to incorporate BDA-specific data privacy and protection considerations, such as those introduced by sophisticated algorithms and advanced computational techniques. Provide tools and frameworks to facilitate thorough assessments of PTPs, focusing on issues related to discrimination and transparency. Incorporating Stakeholder Perspectives : Adopt a more inclusive approach by engaging a broader range of stakeholders in the DPIA process. Involve data subjects, data analysts, and external experts, including public authorities, particularly in cases indicating high residual data protection risks, to gather diverse perspectives on PTPs. Balancing Rigour and Flexibility : Achieve a balance between rigour and flexibility in the DPIA process to accommodate the dynamic nature of BDA projects. This should involve scalable assessments based on the level of risk and the complexity of data processing activities. Ethical and Societal Considerations : Broaden the scope of the DPIA to encompass the ethical and societal implications of BDA projects. Conduct holistic impact assessments that extend beyond legal compliance to evaluate effects on fundamental rights and societal values. Continuous Improvement and Future-Proofing : Establish a mechanism for ongoing review and enhancement of the DPIA framework in response to emerging BDA technologies and evolving data protection laws. Ensure regular updates to guidelines, templates, and the knowledge base to maintain the effectiveness and relevance of the DPIA. 5.3 Changing the Conceptual Model of the DPIA Framework to Incorporate Experts’ Recommendations Given the conceptual model of the DPIA framework and insights from the Delphi study and expert interviews, the components outlined below need adjustment to ensure the DPIA framework is usable and effective in a BDA context. Enhancing these components will enable organisations and regulatory bodies to effectively address the PTPs, ensuring that DPIA procedures align with legal requirements and broader ethical considerations, thereby fostering confidence and responsibility in data-centric innovation. Apart from stating the recommendations, we also clarify their motivation by tracing back to the relevant findings and insights obtained in the Delphi study and the expert interviews. Policy Enhancement : Update policies to explicitly include considerations for BDA, ensuring they effectively address the PTPs. Integrate revised data protection policies that reflect the latest legal and ethical standards related to BDA. Motivation : The Delphi study and expert interviews highlighted the need for clearer policies that specifically address the unique risks posed by BDA. This modification aligns with expert feedback recommending clearer regulatory guidance on using BDA in DPIAs. Conditions Refinement : Clearly define conditions or scenarios specific to BDA projects that necessitate a DPIA. This may involve identifying new or advanced analytics techniques that pose a higher probability of impacting data privacy and security. Incorporate conditions that consider the scale, complexity, and sensitivity of data processed by BDA technologies. Motivation : Experts noted the challenges of applying current conditions to the diverse and evolving nature of BDA. This modification responds to their recommendations, ensuring that the conditions are not overly prescriptive while effectively guiding risk assessments in BDA contexts. Principles Expansion : Introduce or expand existing principles particularly relevant to BDA, such as data minimisation, purpose limitation, and transparency in algorithmic decision-making processes. Strengthen principles related to fairness and non-discrimination, acknowledging BDA’s potential to exacerbate biases. Motivation : Experts called for a broader inclusion of ethical and societal considerations in BDA, emphasising the need for principles that extend beyond privacy and data protection to include fairness, transparency, and accountability. This modification integrates these additional principles to ensure that the DPIA framework accommodates the ethical complexities identified during the interviews and the Delphi study. Method Adaptation : Develop methodologies tailored to the intricacies of BDA, including guidelines for evaluating the impact of AI and machine learning models on privacy and data protection. Incorporate methodologies for dynamic and continuous risk assessment to accommodate the iterative nature of BDA projects. Motivation : Expert feedback consistently highlighted the need to adapt the DPIA method to account for specific risks associated with BDA. This modification ensures the method remains flexible enough to handle diverse BDA applications while maintaining rigour in the assessment of data protection risks. Aids and Templates Update : Create or revise aids and templates specifically designed for BDA projects, including risk assessment tools, consent forms, and impact assessment templates that address the unique aspects of BDA. Develop BDA-specific checklists and flowcharts to facilitate structured DPIA processes for data controllers. Motivation : Experts recommended developing practical tools, such as templates and aids, to assist organisations in conducting effective DPIAs in BDA contexts. This modification addresses the procedural gaps identified during the Delphi study and interviews, ensuring that the DPIA process is user-friendly and comprehensive. Knowledge Base Expansion : Substantially expand the knowledge base to include case studies, best practices, and lessons learned from BDA projects, highlighting both successes and challenges in safeguarding personal data. Incorporate insights from recent BDA advancements, including the use of emerging technologies and compliance with new data protection regulations. Motivation : The Delphi study and expert interviews consistently underscored the need to expand the knowledge base to support organisations conducting DPIAs for BDA. This modification implements that recommendation by creating a dynamic knowledge base populated with sector-specific guidelines, case studies, and best practices that evolve with new developments in the field, providing practitioners with essential resources to stay informed and compliant. Guidelines Clarification : Provide comprehensive guidelines for conducting DPIAs for BDA projects, offering clear instructions for addressing the PTPs. Include guidance on involving stakeholders, including data subjects, in the DPIA process for BDA projects to enhance transparency and accountability. Motivation : Experts expressed the need for clearer and more specific guidelines tailored to the unique challenges of BDA, balancing procedural flexibility in DPIAs with structured guidance and practical tools to effectively manage the complexities inherent in BDA. This modification addresses these concerns by offering detailed instructions on conducting DPIAs in BDA contexts, particularly regarding data controllership, stakeholder involvement, and transparency. In this context, our redefined DPIA conceptual model, as illustrated in Fig. 5 − 1, incorporates four additional elements, 8 each directly linked to existing concepts to ensure seamless integration. These new elements aim to enhance the DPIA framework by effectively addressing the complexities, ethical considerations, stakeholder input, and practical needs arising from BDA implementation: Ethical AI Guidelines (Linked to DPIA Principles) : This element underscores the fundamental importance of ethical considerations within the DPIA, expanding existing principles to advocate for responsible AI practices from the outset. BDA Risk Matrix (Linked to DPIA Method) : This matrix offers a structured understanding of BDA-specific risks. Its integration directly informs risk assessments within the DPIA, guiding mitigation strategies and shaping the overall approach. Stakeholder Engagement Framework (Linked to DPIA Method) : This framework establishes clear mechanisms and procedures for involving stakeholders throughout the DPIA process. Its connection emphasises a more dynamic and interactive approach, enhancing transparency and accountability. Privacy Engineering Tools (Linked to Aids and Templates) : These tools facilitate the implementation of technical solutions for data protection. This link bridges the gap between principles and practice, ensuring that tools are easily accessible and integrated into DPIA documentation. [8] The newly introduced concepts are highlighted in light blue for better visual distinction. Dotted lines show their direct connections to existing concepts within the DPIA conceptual model. 6 Research Contribution and Limitations This paper offers a comprehensive analysis of the challenges and considerations for enhancing the DPIA in the context of BDA. By leveraging an in-depth Delphi study comprising three rounds, alongside individual interviews with experts from various fields, our research underscores the necessity for an advanced DPIA approach capable of effectively managing the unique risks and complexities associated with BDA technologies. In our study, these risks are encapsulated as PTPs. The findings have enriched both academic understanding and practical implementations, particularly in designing a DPIA framework for large-scale data projects. The following subsections summarise our research contributions and limitations. 6.1 Research Contributions Our study thoroughly explores the challenge of making the DPIA more relevant and effective within the BDA context. To address this, we conducted a Delphi study complemented by expert interviews to analyse diverse perspectives, emphasising the need for a more advanced DPIA framework to manage specific BDA risks, encapsulated in our nine PTPs. Our research contributions extend those of the conference papers (i.e., (Georgiadis & Poels, 2022a , 2023a , 2023b )) that presented results from individual Delphi study rounds with the emphasis on expert validation of the PTPs that were synthesized from our systematic literature review (Georgiadis & Poels, 2022b ). In this paper, our research extends beyond mere analysis, providing additional insights and recommendations that were not covered in earlier publications. We not only rigorously validate the nine PTPs across the three Delphi study rounds but building on these insights and the findings from subsequent expert interviews, we offer practical suggestions for practitioners and policymakers, advocating for clearer DPIA guidelines, robust knowledge bases, and methodologies specifically adjusted to the complexities of BDA. Importantly, we propose actionable adjustments to the DPIA framework itself to ensure effective identification and mitigation of the PTPs. Our refined conceptual model lays the groundwork for extending the current DPIA framework, making it more robust and relevant for BDA environments. 6.2 Limitations While this study provides valuable insights into improving the DPIA framework for BDA scenarios, it is important to acknowledge its limitations. Although our Delphi panel was diverse, it may not fully capture the breadth of perspectives within the BDA and data privacy fields. Given the constant evolution of technology, it is essential to periodically review our research results to maintain the relevance of the identified key points and expert recommendations. Furthermore, as our research focuses on the GDPR framework for personal data protection and data privacy, further investigation is needed to assess its applicability in different legal and cultural contexts. Implementing the suggested enhancements to the DPIA may encounter challenges such as limited resources or varying levels of organisational support. To address these obstacles, future studies could adopt action research methodologies to bridge the gap between DPIA improvements and their real-world implementation. This approach could involve developing tailored guidelines and tools for various BDA settings, followed by collecting and analysing their impact to inform further improvements. 7 Future Research Directions To ensure that our proposed DPIA framework remains practical and effective, we recommend a multifaceted research roadmap. This roadmap should focus on the continuous revision and potential expansion of the PTPs to address emerging BDA-specific privacy and data protection risks. It is crucial to explore ways to develop and enrich the DPIA’s knowledge base, aligning it with BDA technologies, as well as strategies for improving and automating risk assessments, some of which may relate to complex cybersecurity issues. It is also important to investigate how to address ethical and societal considerations related to BDA within the DPIA by creating useful tools and guidelines for practitioners. Developing strategies to foster a culture of data privacy within organisations through continuous training and awareness programmes is essential. Additionally, conducting studies across industries and jurisdictions can help further tailor our proposed DPIA framework. Exploring methods to incorporate AI-driven enhancements for risk identification and assessment would significantly streamline the DPIA implementation process and reduce the overall effort required, especially considering the inherent complexity and occasional opacity of the underlying BDA processing activities. Within this scope, we can also investigate means of integrating models like FAIR and ISACA’s RiskIT framework. The ultimate goal of these future research initiatives is to further enhance the DPIA framework, ensuring it remains relevant and useful in light of technological advancements and legislative changes. By doing so, we aim to provide organisations with an easily adaptable tool to address data privacy and protection challenges within the rapidly evolving BDA landscape. 8 Conclusion and Outlook Our study on DPIAs in BDA settings highlights the connection between technological advancements and the safeguarding of privacy and personal data protection. Based on a Delphi study followed by expert interviews, it underscores the need for a DPIA framework that goes beyond mere legal compliance to address the unique challenges posed by BDA. To answer our research question – What changes or improvements should be considered to enhance the DPIA to make it more relevant for use in BDA contexts where personal data is processed? – we thoroughly analysed nine PTPs that capture BDA-related privacy and data protection risks. These risks correspond to key challenges, such as ambiguous data controllership, which emphasises the need for transparency and stakeholder involvement. A significant contribution of this study lies in the analysis and validation of these risks, enhancing our understanding of how BDA intersects with data privacy and protection concern. While our research has limitations, it provides recommendations for enhancing the existing DPIA process. These include suggestions for BDA-specific guidelines, an expanded knowledge base, and methodological adjustments to navigate the complexities of BDA. Incorporating Ethical AI Guidelines and a BDA Risk Matrix into the DPIA framework represents a substantial step towards robust data protection in the realm of big data. These recommendations serve as a foundation for ongoing discussion and development, promoting an approach that safeguards personal data within BDA initiatives. As BDA continues to expand across industries, having a forward-looking or ‘future-proof’ DPIA framework is essential. This framework must anticipate both existing and emerging challenges to uphold data protection as a fundamental principle of digital environments – ‘by design and by default’. The rapid pace of technological advancement underscores the importance of researching and adjusting privacy protocols. The limitations identified in this study, particularly regarding expertise and practical application, highlight areas that warrant further investigation. Engaging a diverse range of stakeholders – including technologists, policymakers, the general public, and public authorities in specific cases – is crucial for developing a DPIA framework that effectively balances data protection concerns with various perspectives. In conclusion, this study addresses our research question while advancing understanding of how to enhance the DPIA within the BDA context. By connecting technological advancements with data protection, the suggested recommendations foster an environment where big data can be responsibly utilised, ensuring that innovation and privacy are closely linked. Declarations Ethics approval and consent to participate: Informed consent was obtained from all individual participants included in the study Consent for publication: Both authors have read and approved the final version of the manuscript and consent to its submission for publication in Information Systems Frontiers . Availability of data and material: The datasets generated and analysed in the described research are publicly available in the GitHub repository at https://github.com/georggr/bda-dpia-research-data . Competing interests: The authors declare that they have no conflict of interest Funding: This research received no external funding Authors’ contributions: Georgios Georgiadis was responsible in conducting the study and drafting, analysing the manuscript. Geert Poels contributed significantly by reviewing, revising and improving the manuscript for intellectual content. Both authors read and approved the final version of the manuscript. Acknowledgments: Not applicable References Ammon K (2023) Generative AI, Bias, Hallucinations and GDPR . Fieldfisher. https://www.fieldfisher.com/en/insights/generative-ai-bias-hallucinations-and-gdpr Baker J, Lovell K, Harris N (2006) How expert are the experts? An exploration of the concept of ‘expert’ within Delphi panel techniques. Nurse Res 14(1):59–70. https://doi.org/10.7748/nr2006.10.14.1.59.c6010 Barredo Arrieta A, Díaz-Rodríguez N, Del Ser J, Bennetot A, Tabik S, Barbado A, Garcia S, Gil-Lopez S, Molina D, Benjamins R, Chatila R, Herrera F (2020) Explainable Artificial Intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI. Inform Fusion 58:82–115. https://doi.org/10.1016/j.inffus.2019.12.012 Beiderbeck D, Frevel N, von der Gracht HA, Schmidt SL, Schweitzer VM (2021) Preparing, conducting, and analyzing Delphi surveys: Cross-disciplinary practices, new directions, and advancements. MethodsX , 8 , 101401. https://doi.org/10/gmpjvv Brady SR (2015) Utilizing and Adapting the Delphi Method for Use in Qualitative Research. Int J Qualitative Methods 14(5):160940691562138. https://doi.org/10.1177/1609406915621381 Bunnik EM, Janssens ACJW, Schermer MHN (2013) A tiered-layered-staged model for informed consent in personal genome testing. Eur J Hum Genet 21(6):596–601. https://doi.org/10.1038/ejhg.2012.237 Chen C, Storey (2012) Business Intelligence and Analytics: From Big Data to Big Impact. MIS Q 36(4):1165. https://doi.org/10.2307/41703503 Clarke R (2017) The Distinction between a PIA and a Data Protection Impact Assessment (DPIA) under the EU GDPR . Roger Clarke’s Web-Site. http://www.rogerclarke.com/DV/PIAvsDPIA.html Diamond IR, Grant RC, Feldman BM, Pencharz PB, Ling SC, Moore AM, Wales PW (2014) Defining consensus: A systematic review recommends methodologic criteria for reporting of Delphi studies. J Clin Epidemiol 67(4):401–409. https://doi.org/10.1016/j.jclinepi.2013.12.002 EC (2019) Ethics Guidelines for Trustworthy AI . https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai EU (2016) Regulation (EU) 2016/679 of the European parliament and of the council . https://eur-lex.europa.eu/eli/reg/2016/679/oj Förster B, von der Gracht H (2014) Assessing Delphi panel composition for strategic foresight—A comparison of panels based on company-internal and external participants. Technol Forecast Soc Chang 84:215–229. https://doi.org/10.1016/j.techfore.2013.07.012 FRA (2021) Getting the future right. Artificial intelligence and fundamental rights . https://fra.europa.eu/en/about-fra Freund J, Jones J (2014) Measuring and managing information risk: A FAIR approach. Butterworth-Heinemann Georgiadis G, Poels G, Big Data Analytics (2022a) Delphi Study to Identify Criteria for the Systematic Assessment of Data Protection Risks in the Context of. 2022 IEEE Eighth International Conference on Big Data Computing Service and Applications (BigDataService) , 177–178. https://doi.org/10.1109/BigDataService55688.2022.00037 Georgiadis G, Poels G (2022b) Towards a privacy impact assessment methodology to support the requirements of the general data protection regulation in a big data analytics context: A systematic literature review. Comput Law Secur Rev 44. https://doi.org/10.1016/j.clsr.2021.105640 Georgiadis G, Poels G (2023a) A Methodology for the Assessment of the Impact of Data Protection Risks in the Context of Big Data Analytics: A Delphi Study. In S. Schiffner, S. Ziegler, & M. Jensen (Eds.), Privacy Symposium 2023 (pp. 1–15). Springer International Publishing Georgiadis G, Poels G, General Data Protection Regulation (2023b) Towards Establishing a Comprehensive Privacy Impact Assessment Methodology for Big Data Analytics in Compliance with the. International Conference on Information Systems (2023) Special Interest Group on Big Data Proceedings . ICIS 2023, Hyderabad, India. https://aisel.aisnet.org/sigbd2023 Hasson F (2000) Research guidelines for the Delphi survey technique Hordri N, Samar A, Yuhaniz S, Shamsuddin S (2017) A systematic literature review on features of deep learning in big data analytics. Int J Adv Soft Comput Its Appl, 9 (1) Hsu CC, Sandford BA (2007) The Delphi technique: Making sense of consensus. Practical Assess Res Evaluation 12(10):1–8 IBM (2023) Cost of a Data Breach Report 2023 . https://www.ibm.com/reports/data-breach ISACA (2020) ISACA’s Risk IT Framework Offers a Structured Methodology for Enterprises to Manage Information and Technology Risk . ISACA. https://www.isaca.org/about-us/newsroom/press-releases/2020/isacas-risk-it-framework-offers-a-structured-methodology Ivanova Y (2020) The Data Protection Impact Assessment as a Tool to Enforce Non-discriminatory AI. In: Antunes L, Naldi M, Italiano GF, Rannenberg K, Drogkaris P (eds) 8th Annual Privacy Forum, APF 2020. Springer International Publishing, pp 3–24 Jain P, Gyanchandani M, Khare N (2016) Big data privacy: A technological perspective and review. J Big Data 3(1):25. https://doi.org/10.1186/s40537-016-0059-y Keeney S, Hasson F, Mckenna H (2011) The Delphi Technique in Nursing and Health Research. Wiley-Blackwell Kloza D, van Dijk N, Casiraghi S, Vazquez Maymir S, Roda S, Tanas A, Konstantinou I (2018) Data protection impact assessments in the European Union: Designing an appraisal method towards a more robust protection of individuals. D.Pia.Lab Policy Brief, VUB , 2 , 4 Linstone HA, Turoff M (2002) The Delphi Method: Techniques and Applications. Addison-Wesley Educational Publishers Inc Mullen PM (2003) Delphi: Myths and reality. J Health Organ Manag 17(1):37–52. https://doi.org/10.1108/14777260310469319 Okoli C, Pawlowski SD (2004) The Delphi method as a research tool: An example, design considerations and applications. Inform Manage 42(1):15–29. https://doi.org/10.1016/j.im.2003.11.002 Pardau S (2018) The California Consumer Privacy Act: Towards a European-style privacy regime in the United States? J Technol Law Policy 23(1):68–114 Petter S, Straub D, Rai A (2007) Specifying formative constructs in information systems research. MIS Q 623–656. https://doi.org/10.2307/25148814 Skulmoski GJ, Hartman FT, Krahn J (2007) The Delphi method for graduate research. J Inform Technol Education: Res 6(1):1–21 Tene O, Polonetsky J (2012) Big Data for All: Privacy and User Control in the Age of Analytics. Northwest J Technol Intellect Property 11:xxvii–274 Trevelyan EG, Robinson N (2015) Delphi methodology in health research: How to do it? Eur J Integr Med 7(4):423–428. https://doi.org/10.1016/j.eujim.2015.07.002 Van Looy A, Poels G, Snoeck M (2017) Evaluating business process maturity models. J Association Inform Syst 18(6):461–486 Venkatesh V, Brown SA, Bala H (2013) Bridging the Qualitative-Quantitative Divide: Guidelines for Conducting Mixed Methods Research in Information Systems. MIS Q 37(1):21–54. https://doi.org/10.25300/MISQ/2013/37.1.02 WP29 (2013) Opinion 03/2013 on purpose limitation . https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2013/wp203_en.pdf Wright D (2013) Making Privacy Impact Assessment More Effective. Inform Soc 29(5):307–315. https://doi.org/10.1080/01972243.2013.825687 Zeng J, Glaister KW (2018) Value creation from big data: Looking inside the black box. Strategic Organ 16(2):105–140. https://doi.org/10.1177/1476127017697510 Additional Declarations The authors declare no competing interests. Supplementary Files Appendix.docx Cite Share Download PDF Status: Posted Version 1 posted You are reading this latest preprint version Research Square lets you share your work early, gain feedback from the community, and start making changes to your manuscript prior to peer review in a journal. As a division of Research Square Company, we’re committed to making research communication faster, fairer, and more useful. We do this by developing innovative software and high quality services for the global research community. Our growing team is made up of researchers and industry professionals working together to solve the most critical problems facing scientific publishing. Also discoverable on Platform About Our Team In Review Editorial Policies Advisory Board Help Center Resources Author Services Accessibility API Access RSS feed Manage Cookie Preferences © Research Square 2026 | ISSN 2693-5015 (online) Privacy Policy Terms of Service Do Not Sell My Personal Information {"props":{"pageProps":{"initialData":{"identity":"rs-5821174","acceptedTermsAndConditions":true,"allowDirectSubmit":true,"archivedVersions":[],"articleType":"Research Article","associatedPublications":[],"authors":[{"id":401585785,"identity":"ae3681b6-da3e-46e6-b740-dde997b69757","order_by":0,"name":"Georgios Georgiadis","email":"data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAZAAAAAyAQMAAABI0h/eAAAABlBMVEX///8AAABVwtN+AAAACXBIWXMAAA7EAAAOxAGVKw4bAAABPklEQVRIie2QMUvDQBTHXzhIl0uzvoDQr3AhEB2qGf0aDQedRIQugiBXhGY5MysiDn6BfISEg3ap9AN0aRE6daggEkpA01QF4SiOgvlN797dj/f+B1BT82dh3xUCKDBm2wP9vULYVtil/CAFE3cpreOr4cvrWTsA+zF7Pl8ftJqjxuKCrtunAVjZTKO44yG/22PdUOCCu08xureK+lMr7vYoNDnTKTcnHkGmOoBj3+lLNBJFzaklVSiB+qhTHpaVEgBO3jZKkKjGomfJ942yn+uyIPWMFVOGsKXpiBzDRIFPaJ5WU3TxGe1yAmWWAZqe2xfIyyyecy94KFWT6xZrRUoZedEObFvN56K4PIwno/lqWRyFUXSdrXRTUgCy+X8TOwDG4LNdFUS3VjlFlPdVSLuUofjqF/rnNTU1Nf+SD+TJZHwrNipjAAAAAElFTkSuQmCC","orcid":"https://orcid.org/0000-0003-0147-9167","institution":"Ghent University","correspondingAuthor":true,"prefix":"","firstName":"Georgios","middleName":"","lastName":"Georgiadis","suffix":""},{"id":401585786,"identity":"b46794a9-5978-497a-aabe-5638932fb46f","order_by":1,"name":"Geert Poels","email":"","orcid":"https://orcid.org/0000-0001-9247-6150","institution":"Ghent University","correspondingAuthor":false,"prefix":"","firstName":"Geert","middleName":"","lastName":"Poels","suffix":""}],"badges":[],"createdAt":"2025-01-13 15:31:14","currentVersionCode":1,"declarations":{"humanSubjects":true,"vertebrateSubjects":false,"conflictsOfInterestStatement":false,"humanSubjectEthicalGuidelines":true,"humanSubjectConsent":true,"humanSubjectClinicalTrial":false,"humanSubjectCaseReport":false,"vertebrateSubjectEthicalGuidelines":false},"doi":"10.21203/rs.3.rs-5821174/v1","doiUrl":"https://doi.org/10.21203/rs.3.rs-5821174/v1","draftVersion":[],"editorialEvents":[],"editorialNote":"","failedWorkflow":false,"files":[{"id":73840702,"identity":"397bc459-49e5-4be6-b518-454faab719ab","added_by":"auto","created_at":"2025-01-15 08:14:13","extension":"png","order_by":1,"title":"Figure 1","display":"","copyAsset":false,"role":"figure","size":103561,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 2‑1: Privacy Touch Points (PTPs)\u003c/p\u003e","description":"","filename":"1.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/a88ba91efad46d38428f9ba2.png"},{"id":73839481,"identity":"21025e95-56ec-4bf5-be8f-df5c8c653024","added_by":"auto","created_at":"2025-01-15 08:06:13","extension":"png","order_by":2,"title":"Figure 2","display":"","copyAsset":false,"role":"figure","size":205282,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 3‑1: Delphi Study Phases\u003c/p\u003e","description":"","filename":"2.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/b590b25057930375dc4a281b.png"},{"id":73839474,"identity":"afb43f91-2dee-4998-be05-9c11d517acea","added_by":"auto","created_at":"2025-01-15 08:06:12","extension":"png","order_by":3,"title":"Figure 3","display":"","copyAsset":false,"role":"figure","size":26491,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 3‑2: Domains of Expertise Present in the Delphi Study Expert Panel\u003cbr\u003e\n(percentages indicate the relative proportion of experts indicating expertise in a domain)\u003c/p\u003e","description":"","filename":"3.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/42c3ccd9494f4a184ad1e26d.png"},{"id":73839498,"identity":"11f9b364-cbcd-4650-9887-aedc96fe0828","added_by":"auto","created_at":"2025-01-15 08:06:14","extension":"png","order_by":4,"title":"Figure 4","display":"","copyAsset":false,"role":"figure","size":15619,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 3‑3: Domains of Expertise Present in the Group of Interviewees\u003cbr\u003e\n(percentages indicate the relative proportion of experts indicating expertise in a domain)\u003c/p\u003e","description":"","filename":"4.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/4ecc750b07c5c1b7da440348.png"},{"id":73840706,"identity":"a6590b00-e035-46c6-832b-a2891e76d4e8","added_by":"auto","created_at":"2025-01-15 08:14:13","extension":"png","order_by":5,"title":"Figure 5","display":"","copyAsset":false,"role":"figure","size":34213,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 4‑1: Conceptual Model of the DPIA Framework\u003c/p\u003e","description":"","filename":"5.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/881bcb684332e7dd027ca92d.png"},{"id":73840704,"identity":"ed618d1d-05fb-4529-9aae-7c26e5456d79","added_by":"auto","created_at":"2025-01-15 08:14:13","extension":"png","order_by":6,"title":"Figure 6","display":"","copyAsset":false,"role":"figure","size":26487,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 4‑2: Stability of Responses in Rounds 1 and 2 (Relevance)\u003c/p\u003e","description":"","filename":"6.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/2ee2c28fe5b55766a867acd7.png"},{"id":73839486,"identity":"6598f568-3b11-409b-b71a-098feeb16cbe","added_by":"auto","created_at":"2025-01-15 08:06:13","extension":"png","order_by":7,"title":"Figure 7","display":"","copyAsset":false,"role":"figure","size":31197,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 4‑3: Stability of Responses in Rounds 1 and 2 (Importance)\u003c/p\u003e","description":"","filename":"7.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/a8d8c6f667634e2cb523a217.png"},{"id":73839496,"identity":"9e73474b-0d89-432d-b7d7-99654f8410db","added_by":"auto","created_at":"2025-01-15 08:06:14","extension":"png","order_by":8,"title":"Figure 8","display":"","copyAsset":false,"role":"figure","size":47435,"visible":true,"origin":"","legend":"\u003cp\u003eFigure 5‑1: Conceptual Model of a DPIA Framework for BDA\u003c/p\u003e","description":"","filename":"8.png","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/e3b761d2aca47c83786383d3.png"},{"id":73841124,"identity":"9e6cd4b8-6771-4fd6-9de7-1b6887f916c6","added_by":"auto","created_at":"2025-01-15 08:22:13","extension":"pdf","order_by":0,"title":"","display":"","copyAsset":false,"role":"manuscript-pdf","size":2693740,"visible":true,"origin":"","legend":"","description":"","filename":"manuscript.pdf","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/49562943-e995-4179-81cb-1d7bf9d445f9.pdf"},{"id":73839477,"identity":"913d4cb8-f65f-4b04-a3b6-0307631000be","added_by":"auto","created_at":"2025-01-15 08:06:13","extension":"docx","order_by":1,"title":"","display":"","copyAsset":false,"role":"supplement","size":21862,"visible":true,"origin":"","legend":"","description":"","filename":"Appendix.docx","url":"https://assets-eu.researchsquare.com/files/rs-5821174/v1/e52e57e09d3bddd22b14274e.docx"}],"financialInterests":"The authors declare no competing interests.","formattedTitle":"\u003cp\u003e\u003cstrong\u003eEstablishing a Comprehensive Data Protection Impact Assessment Methodology for Big Data Analytics in Compliance with the General Data Protection Regulation\u003c/strong\u003e\u003c/p\u003e","fulltext":[{"header":"1 Introduction","content":"\u003cp\u003eThe advent of big data analytics (BDA) technologies has ushered in a transformative era, where data-driven decision-making has become a central strategy for both industry and individual success. These technologies have revolutionised the ability to capture, store, process, and analyse massive volumes of structured and unstructured data at unprecedented speeds, revealing insights that were previously unimaginable.\u003c/p\u003e\n\u003cp\u003eAt its core, BDA aims to decode intricate patterns and trends within vast amounts of data. To achieve this, BDA technologies utilise advanced algorithms, computational models, and statistical methods to uncover hidden correlations, causal relationships, market trends, customer preferences, and many other insights (Hordri et al., 2017). With this knowledge, businesses and organisations can optimise operations, devise more targeted marketing strategies, improve product development, and enhance the overall customer experience and satisfaction.\u003c/p\u003e\n\u003cp\u003eBDA has also had a profound impact on individuals. It enables personalised healthcare through predictive analytics, anticipating health issues before they become critical. In finance, it facilitates tailored investment strategies, while in entertainment and social media, it improves user experiences by providing personalised content recommendations.\u003c/p\u003e\n\u003cp\u003eHowever, the widespread adoption of BDA technologies has sparked discussions around privacy and personal data protection. A balanced approach is needed to address both data utility and the respect for individual rights and freedoms, as mandated by legal frameworks such as the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in the United States (EU, 2016; Pardau, 2018; Tene \u0026amp; Polonetsky, 2012). As we enter an increasingly data-centric world, it is crucial to address these concerns while harnessing the vast potential of big data.\u003c/p\u003e\n\u003cp\u003eSimilar to the CCPA, the GDPR establishes strict principles and rules for handling personal data. Concerns such as the unintended exposure of personal data and the processing of sensitive data, which could occur through various channels and pose high risks to individuals, have led to the need for data protection impact assessments (DPIAs). These assessments enable organisations to proactively identify and mitigate potential vulnerabilities in personal data processing before issues arise (WP29, 2017). DPIAs provide a structured approach for identifying, analysing, and mitigating risks to the rights and freedoms of individuals resulting from personal data processing. They also help organisations comply with data protection laws like the GDPR.\u003c/p\u003e\n\u003cp\u003eIn this context, and based on the results of a systematic literature review (Georgiadis \u0026amp; Poels, 2022b), nine privacy touch points (PTPs) related to BDA-specific risks and threats to personal data protection and privacy were identified. Our current research focuses on examining how these PTPs manifest themselves in real-world contexts by inquiring domain experts. We further provide recommendations to address gaps in the DPIA framework to improve its applicability in BDA environments.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThis paper aims to answer the following question: \u003cem\u003eWhat changes or improvements should be considered to enhance the DPIA framework to make it more relevant for use in BDA contexts where personal data is processed?\u003c/em\u003e To investigate this question, we conducted a Delphi study,\u003csup\u003e[1]\u003c/sup\u003e using the nine PTPs as a starting point. We sought expert opinions on changes and improvements to the DPIA framework to make it more suitable for environments where BDA is used to process personal data. While this research question cannot be answered with a simple prescriptive response, we aim to provide an informed answer based on the analysis of feedback from the Delphi rounds and follow-up interviews, combined with our understanding of the subject matter. These findings form the basis of our knowledge contribution.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003eThis paper presents the results of the Delphi study and expert interviews, through which we address the research question. Our research builds upon previous work presented in conference papers (Georgiadis \u0026amp; Poels, 2022a, 2023a, 2023b), which reported the outcomes of three Delphi study rounds, focusing on expert validation of the PTPs resulting from our systematic literature review. However, this paper significantly extends that work by offering a deeper analysis of the Delphi study findings aimed at exploring solutions for addressing the PTPs through an improved DPIA. The paper also enhances the Delphi study findings by incorporating new insights from expert interviews. Ultimately, it leverages the results obtained from the Delphi study and expert interviews by presenting a refined DPIA framework specifically tailored to BDA. The unique and novel contribution of the paper lies in exploring how the validated PTPs can be operationalised within the existing DPIA framework \u0026ndash; an area not covered in earlier publications.\u003c/p\u003e\n\u003cp\u003eThe remainder of this paper is organised as follows. Section 2 provides the background of our study. Section 3 describes the methodological framework, with a focus on the Delphi study technique. Section 4 discusses the findings from each Delphi round and integrates them with insights from individual interviews with members of the Delphi panel and additional experts. Section 5 presents lessons learned and recommendations for improving the DPIA framework for BDA processing operations. Section 6 outlines research contributions and limitations. Section 7 offers conclusions and an outlook, while Section 8 suggests potential future research directions.\u003c/p\u003e\n\u003cp\u003e[1] The Delphi method is a consensus-building approach that uses a series of questionnaires to gather expert opinions on a specific research topic. The goal is to achieve general agreement among the participants, who form a panel of experts. This method operates on the assumption that the collective opinion of the group is more valid than that of any individual member.\u003c/p\u003e"},{"header":"2 Background","content":"\u003cdiv id=\"Sec2\" class=\"Section2\"\u003e \u003ch2\u003e2.1 The Importance of Privacy Impact Assessments in the Protection of Personal Data\u003c/h2\u003e \u003cp\u003eDPIAs are a streamlined version of privacy impact assessments (PIAs) (Clarke, \u003cspan citationid=\"CR8\" class=\"CitationRef\"\u003e2017\u003c/span\u003e) and are particularly relevant in today\u0026rsquo;s digital age. With the rapid spread of information technology and the large-scale processing of data, personal data has become crucial not only to businesses and governments but also to individuals, who are increasingly concerned about the risks of data mismanagement and breaches. Recent reports have shown that both the costs and frequency of such incidents are on the rise (IBM, \u003cspan citationid=\"CR22\" class=\"CitationRef\"\u003e2023\u003c/span\u003e). DPIAs play a vital role in safeguarding individuals\u0026rsquo; personal data rights by identifying and addressing potential risks arising from data processing activities (Kloza et al., \u003cspan citationid=\"CR27\" class=\"CitationRef\"\u003e2018\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eBy conducting a DPIA, organisations can systematically assess the potential impacts of data processing on individuals\u0026rsquo; rights and freedoms, implementing strategies to mitigate risks and ensure compliance with data protection regulations. The main objective is to ensure that data protection considerations are integrated early in the planning stages of any project or initiative that involves personal data processing. The DPIA process consists of several key steps. First, organisations must determine when a DPIA is required, typically when processing operations are likely to pose high risks to individuals\u0026rsquo; rights and freedoms. Second, the organisation must describe the nature, scope, context, and purposes of the proposed processing activities, including identifying data flows, which represent the movement and processing of personal data within and beyond the organisation. The next step is to evaluate whether the processing activities are necessary and proportionate to the intended purposes. This is followed by a thorough assessment of potential risks to individuals\u0026rsquo; rights and freedoms, accounting for both existing risks and those that may arise from future changes. Based on the risk assessment, organisations should consider implementing appropriate measures to demonstrate compliance with relevant legislation, such as the GDPR. Although the GDPR does not mandate the direct implementation of results, measures may include legal, technical, or organisational safeguards, or consultations with key stakeholders, such as data subjects or supervisory authorities.\u003c/p\u003e \u003cp\u003eIn addition to ensuring legal compliance and promoting data governance, effective DPIA implementation offers numerous benefits. It demonstrates accountability in handling personal data and allows organisations to proactively identify and mitigate risks before they materialise, thereby reducing potential harm to individuals and building trust among data subjects. However, conducting DPIAs also poses challenges. Resource allocation is a significant issue, as DPIAs require time and expertise from professionals well-versed in data protection. Furthermore, balancing data protection concerns with business or governmental interests can be complex, particularly for organisations heavily reliant on personal data processing, such as those using AI solutions like BDA. Lastly, ongoing monitoring and review of the DPIA process is essential to ensure continued compliance (Ivanova, \u003cspan citationid=\"CR24\" class=\"CitationRef\"\u003e2020\u003c/span\u003e; Wright, \u003cspan citationid=\"CR39\" class=\"CitationRef\"\u003e2013\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eIn this paper, we use several terms related to DPIA, and to avoid ambiguity, we define each as follows:\u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Framework\u003c/b\u003e: The conceptual model or structure that guides the overall approach to conducting DPIAs.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Methodology\u003c/b\u003e: Specific methods or approaches used within the framework to assess risks and impacts.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Method\u003c/b\u003e: The detailed procedural steps followed by practitioners when performing a DPIA.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Process\u003c/b\u003e: The full lifecycle of conducting a DPIA, from preparation to risk mitigation and review.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Guidance\u003c/b\u003e: Recommendations or best practices that provide instructions on how to conduct DPIAs.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Policy\u003c/b\u003e: Organisational policies that dictate when a DPIA should be conducted, who is responsible, and which elements must be considered.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Templates\u003c/b\u003e: Predefined formats or forms used to standardise the documentation of DPIAs.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDPIA Aids\u003c/b\u003e: Software tools, checklists, or other practical resources designed to help practitioners conduct DPIAs more effectively.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec3\" class=\"Section2\"\u003e \u003ch2\u003e2.2 Key Challenges and Considerations for Personal Data Protection with Big Data Analytics\u003c/h2\u003e \u003cp\u003eBDA has immense potential to drive insights and innovation across various sectors by enabling organisations to analyse massive volumes of data and efficiently detect hidden patterns (Chen et al., 2012), thereby transforming raw data into valuable information. However, as data volumes continue to grow and BDA techniques advance to more sophisticated implementations, such as large language models (LLMs), the challenges of ensuring personal data protection and privacy also increase (Ammon, \u003cspan citationid=\"CR1\" class=\"CitationRef\"\u003e2023\u003c/span\u003e; Jain et al., \u003cspan citationid=\"CR25\" class=\"CitationRef\"\u003e2016\u003c/span\u003e). In this rapidly evolving landscape, understanding the interplay between technological, legal, and human-centric concerns becomes crucial, as these factors collectively shape the unique challenges posed by BDA processing operations.\u003c/p\u003e \u003cp\u003eA systematic literature review by Georgiadis and Poels (\u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2022b\u003c/span\u003e) identified various risks and potential harms to individuals, which were interpreted as specific to BDA. These risks were grouped into nine PTPs (Fig.\u0026nbsp;\u003cspan refid=\"Fig1\" class=\"InternalRef\"\u003e2\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1). The PTPs encompass a broad spectrum of challenges related to personal data protection and privacy in BDA environments. For instance, PTP (1) addresses the uncertainty surrounding data ownership, driven by the challenges of maintaining consistent compliance across data controllers. PTPs (2)\u0026ndash;(6) focus on detailed risk assessments, highlighting issues related to personal data processing, such as potential discrimination and lack of transparency due to AI algorithmic biases, and the unclear handling of personal data in the creation and utilisation of BDA systems. These include the emergence of new privacy risks, such as data breaches, which can directly threaten individuals\u0026rsquo; rights and freedoms. PTPs (7)\u0026ndash;(9) explore the detailed procedures of DPIAs, addressing concerns such as the limited extent of stakeholder involvement and the ambiguity of DPIA processes, particularly in the context of BDA. These touch points also examine privacy and data protection challenges from social and ethical perspectives, which, while sometimes viewed as peripheral to data protection, are increasingly recognised as vital in DPIA discussions. Furthermore, the DPIA process often encounters conflicts between individual rights, organisational interests, and broader societal benefits. Managing these complexities while ensuring compliance with relevant laws and regulations requires a nuanced and sophisticated approach.\u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003cp\u003eIn their (2022b) study, Georgiadis and Poels examined a variety of existing PIA and DPIA solutions or methodologies to assess whether they sufficiently addressed the nine PTPs. The evaluation of personal data operations in a BDA context revealed that the current solutions fall short, as none of them adequately cover all PTPs. This gap in coverage led us to formulate the research question that drives the investigation in this paper.\u003c/p\u003e \u003c/div\u003e"},{"header":"3 Research Method","content":"\u003cp\u003eOur research methodology aligns with established approaches in the information systems literature (Petter et al., \u003cspan citationid=\"CR32\" class=\"CitationRef\"\u003e2007\u003c/span\u003e). It consisted of three subsequent research stages. We began with a systematic literature review to build a foundational knowledge base, including the nine PTPs that express BDA-specific risks to privacy and personal data protection. We next organised a Delphi study with experts to validate the PTPs and explore changes and improvements to the DPIA framework needed to properly assess the PTPs. We finally conducted semi-structured interviews with experts to validate the suggested improvements to the DPIA framework and solicit additional suggestions for unresolved issues. This mixed-methods approach (Venkatesh et al., \u003cspan citationid=\"CR37\" class=\"CitationRef\"\u003e2013\u003c/span\u003e) allowed combining quantitative and qualitative data collection and analysis techniques to obtain a comprehensive understanding for answering our research question.\u003c/p\u003e \u003cp\u003eFor the methodology of the systematic literature review, we refer to (Georgiadis \u0026amp; Poels, \u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2022b\u003c/span\u003e). In this section, we first present the methodology of the Delphi study and next that of the expert interviews.\u003c/p\u003e \u003cdiv id=\"Sec5\" class=\"Section2\"\u003e \u003ch2\u003e3.1 Delphi Study\u003c/h2\u003e \u003cp\u003eThe Delphi method was originally developed by the RAND Corporation in the 1950s as a forecasting tool for military applications (Rowe and Wright, 1999). Since then, it has evolved into a versatile, widely recognised research method that facilitates structured group communication, gathering expert opinions through a series of feedback rounds. While full anonymity is not achievable as researchers can identify panel members and responses to some extent, the Delphi method remains valuable for tackling research questions that benefit from the input of domain experts. This method ensures controlled, iterative rounds of feedback, enabling consensus-building or highlighting areas of disagreement (Hsu \u0026amp; Sandford, \u003cspan citationid=\"CR21\" class=\"CitationRef\"\u003e2007\u003c/span\u003e). It is also particularly useful for generating insights in complex areas with limited information (Beiderbeck et al., \u003cspan citationid=\"CR4\" class=\"CitationRef\"\u003e2021\u003c/span\u003e; Okoli \u0026amp; Pawlowski, \u003cspan citationid=\"CR30\" class=\"CitationRef\"\u003e2004\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eIn our research context, the limited information pertains to the validity of the nine PTPs identified by Georgiadis and Poels (\u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2022b\u003c/span\u003e). These PTPs stem from the analysis of literature across diverse fields discussing considerations for BDA and data privacy. However, none of these fields fully integrate both aspects nor do they offer enhancements to the DPIA methodology that account for these PTPs. The expert input gathered via the Delphi study aims to ensure that the proposed DPIA framework is relevant for BDA processing operations. As such, our panel included experts from unrelated domains such as AI, security, and law.\u003c/p\u003e \u003cp\u003eFigure \u003cspan refid=\"Fig3\" class=\"InternalRef\"\u003e3\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1 shows that our Delphi study consisted of preparatory, intermediate, and final phases. In the \u003cem\u003epreparatory phase\u003c/em\u003e, we established qualifications for expert participants, aiming for diversity in background (e.g., private sector, academia, and public organisations) and expertise relevant to the study topics. We confirmed these qualifications through a preliminary screening survey. Our goal was to include knowledge areas such as law, security, and computer science, and we selected a balanced panel (see Fig.\u0026nbsp;\u003cspan refid=\"Fig3\" class=\"InternalRef\"\u003e3\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2) with careful attention to size, diversity, and inclusivity, ensuring broad coverage across these domains. Our strategy was influenced by methodological perspectives from Baker et al. (\u003cspan citationid=\"CR2\" class=\"CitationRef\"\u003e2006\u003c/span\u003e) and Mullen (\u003cspan citationid=\"CR29\" class=\"CitationRef\"\u003e2003\u003c/span\u003e), who stress the importance of diverse expertise and highlight the challenge of defining who qualifies as an \u0026lsquo;expert\u0026rsquo; in Delphi studies. For our study, experts were defined as individuals with significant experience in relevant fields, ensuring a wide range of perspectives. Although there are no specific requirements for panel size, we aimed to invite approximately 15 experts, enough to include all relevant viewpoints while reducing the likelihood of bias (F\u0026ouml;rster \u0026amp; von der Gracht, \u003cspan citationid=\"CR12\" class=\"CitationRef\"\u003e2014\u003c/span\u003e).\u003c/p\u003e \u003cp\u003eIn line with the recommended diverse panel composition, we extended invitations to over 30 experts from academia, public institutions, and industry sectors. These experts brought experience across a range of relevant fields, including BDA, AI, data science, information security, law, privacy, and data protection (see Fig.\u0026nbsp;\u003cspan refid=\"Fig3\" class=\"InternalRef\"\u003e3\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2). Ultimately, 18 experts agreed to participate in our Delphi study. As illustrated in Fig.\u0026nbsp;\u003cspan refid=\"Fig3\" class=\"InternalRef\"\u003e3\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2,\u003csup\u003e2\u003c/sup\u003e while the majority of our participants had a strong understanding of data protection and privacy, their collective expertise also spanned other critical domains related to our study.\u003c/p\u003e \u003cp\u003eDuring the \u003cem\u003eintermediate phase\u003c/em\u003e, we presented the experts with three successive questionnaires (one for each Delphi study round), including questions\u003csup\u003e3\u003c/sup\u003e that could be reused across rounds until consensus was reached. The initial two rounds primarily aimed to validate and potentially expand upon the PTPs identified by (Georgiadis \u0026amp; Poels, \u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2022b\u003c/span\u003e), while also gathering the expert panel\u0026rsquo;s perspectives on crucial elements of a DPIA framework. The third round focused on proposed improvements to the DPIA, tailored specifically to the BDA context, using the PTPs agreed upon by the expert panel for their relevance to BDA-specific risks and harms and their significance for the DPIA. After each round, we shared with the experts a detailed report summarising the anonymised survey responses and consensus scores, along with our analytical insights. Given that our surveys included open-ended sections, the experts were encouraged to provide reflections beyond their initial predefined answer choices for each question.\u003c/p\u003e \u003cp\u003eIn the \u003cem\u003efinal phase\u003c/em\u003e, we completed the consensus statements and conducted a thorough analysis of the survey results, considering both statistical and qualitative aspects. An addition to our Delphi study design was the inclusion of individual interviews with experts (see sub-section 3.2). These interviews aimed to clarify specific findings and gain further insights, particularly concerning recommendations to improve the DPIA framework. The final phase also involved creating a comprehensive final report for the panel members and preparing a scientific paper for publication in a reputable journal.\u003c/p\u003e \u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eAs the Delphi study research method is a consensus-seeking approach, an important research design choice is the definition of consensus criteria, which are specific measures used to analyse the responses of the expert panel and assess the level of agreement among participants. Essentially, these criteria serve as benchmarks for determining when the study can be concluded. They are crucial for evaluating the results of iterative Delphi study rounds, allowing for an objective assessment of expert agreement, which helps researchers ensure rigor and establish the reliability of their findings. Typically, these criteria are predetermined and may vary depending on the subject and purpose of the study. They can be quantitative, such as a specified percentage of agreement among experts, or qualitative, based on the stability of responses across rounds.\u003c/p\u003e\u003cp\u003eFor our research, we utilised four distinct consensus criteria (see Table\u0026nbsp;\u003cspan refid=\"Tab2\" class=\"InternalRef\"\u003e3\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1), which were derived and adapted from the work of Van Looy et al. (\u003cspan citationid=\"CR36\" class=\"CitationRef\"\u003e2017\u003c/span\u003e). Within our framework, consensus can be classified as either positive or negative. A positive consensus indicates agreement on a PTP\u0026rsquo;s relevance or importance, while a negative consensus signifies disagreement. We define consensus as \u0026lsquo;strong\u0026rsquo; when all criteria are met and \u0026lsquo;almost strong\u0026rsquo; when three out of the four criteria align (see Table\u0026nbsp;\u003cspan refid=\"Tab2\" class=\"InternalRef\"\u003e3\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2). Additionally, we examined the experts\u0026rsquo; rationales provided in open-ended questions to identify potential discrepancies in their scores.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab1\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 3\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1: Consensus Criteria\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"2\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eCondition\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eDefinition (all scores indicated on a 5-point Likert scale)\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e# 1\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e35% of the experts strongly agree (i.e., score 5) or strongly disagree (i.e., score 1)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e# 2\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e70% of the experts agree (i.e., score 4 or 5) or disagree (i.e., score 1 or 2)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e# 3\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eThe interquartile range (i.e., the difference between the highest and lowest scores of the middle 50% of experts when scores are ranked) is less than or equal to 1.25\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003e# 4\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eNo expert strongly disagrees/agrees if conditions (1) and (2), based on the frequencies, indicate a tendency towards either positive or negative consensus\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab2\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 3\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2: Consensus Types with Conditions\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"2\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eConsensus Type\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eCondition\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eStrong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eAll four conditions are met: #1\u0026ndash;#4\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eAlmost Strong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eAt least three criteria are met\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eNo Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eFewer than three criteria are met\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec6\" class=\"Section2\"\u003e \u003ch2\u003e3.2 Expert Interviews\u003c/h2\u003e \u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eFollowing the Delphi rounds, our study employed semi-structured interviews to gain a deeper understanding of expert opinions on specific topics. The selection of the interivew topics was informed by the findings from the Delphi study. Topics were selected to explore complexities related to data controllership, stakeholder involvement, and transparency \u0026ndash; issues identified during the Delphi study as requiring additional expert input. For instance, the question of data controllership emerged as a significant challenge, particularly in BDA projects, where the boundaries between data controllers and processors are often blurred. Similarly, while stakeholder involvement and transparency are critical for ensuring accountability and fairness in DPIAs, the Delphi study revealed a lack of strong agreement on best practices to address these challenges. By focusing on these unresolved areas, the interviews complemented the Delphi study and provided clarity on key PTPs, thereby refining the DPIA framework.\u003c/p\u003e\u003cp\u003eA questionnaire consisting of nine questions that are briefly described in the Appendix section along with relevant background information, was distributed to a group of nine experts whose areas of expertise aligned with those in the Delphi study (see Fig.\u0026nbsp;3\u0026ndash;3\u003csup\u003e2\u003c/sup\u003e). Four of these experts participated in the Delphi study and agreed to provide further input to elaborate on their responses, while the remaining five were invited based on their established academic and professional expertise in the field. The nine interviewees were selected based on two main criteria: (1) their expertise in areas relevant to the PTPs, and (2) their willingness to engage in a detailed exploration of the study topics. Representing both the private sector and academia, the interviewees averaged 15 years of professional experience, with many holding senior positions such as professors and company directors, ensuring a broad range of perspectives. Respondents were encouraged to submit detailed written responses, and follow-up interviews were conducted remotely via video conferencing platforms to obtain additional clarification or delve deeper into their viewpoints.\u003c/p\u003e\u003cp\u003eThe answers to each of the nine questions was carefully analysed in terms of expert consensus, the variety of suggestions to address the question and conclusive insights. The expert consensus overview captures areas where experts share overwhelmingly similar viewpoints, highlighting agreed-upon principles, practices, or directions. The diverse suggestions discussion shows the range of ideas or solutions proposed by the experts in their responses, included in our analysis as potential areas for innovation or alternative approaches for future research. Finally, the conclusive insights encapsulate actionable conclusions drawn from our analysis.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e \u003c/div\u003e\n\u003cp\u003e[2] The percentages in Figures 3-2 and 3-3 do not directly correspond to the number of participants, as each expert was able to indicate expertise in multiple knowledge areas. Consequently, some participants may appear in more than one category.\u003c/p\u003e\n\u003cp\u003e[3]Copies of the questionnaires, along with the raw data from the survey collections, are available at: https://github.com/georggr/bda-dpia-research-data\u003c/p\u003e\n\u003cp\u003e\u0026nbsp;\u003c/p\u003e"},{"header":"4 Results","content":"\u003cp\u003eWe conducted three rounds of the Delphi study between March 2022 and February 2023, with individual interviews held in January and February 2024. The process was meticulously planned over these months, ensuring thorough analysis and dissemination of preliminary results to the experts, validating our Delphi study design at conferences (Georgiadis \u0026amp; Poels, \u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e2022a\u003c/span\u003e, \u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e2023b\u003c/span\u003e, \u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e2023a\u003c/span\u003e), and rigorously testing the iterative questionnaires that form the backbone of the consecutive Delphi study rounds. Our analysis in this paper extends the preliminary findings from the Delphi rounds reported in these conference papers by integrating them with practical recommendations for enhancing the DPIA in the context of BDA. Additionally, we incorporate new findings from expert interviews, which provide further depth and contextualisation of the Delphi results. We were acutely aware of the demands on our expert participants\u0026rsquo; time, many of whom are leading figures in their respective fields. Thus, the intervals between the rounds were carefully determined to accommodate their busy schedules.\u003c/p\u003e \u003cp\u003eIdentifying qualified individuals as experts to participate in the panel is one of the most crucial steps in conducting our Delphi study. Knowledge of the study context or the issues under investigation does not automatically qualify someone as an \u0026lsquo;expert\u0026rsquo;. Therefore, we sought relatively impartial participants for our target group to ensure that the information received reflects current knowledge and perceptions. Participants should have a keen interest in our research and a willingness to engage in all planned rounds. The cooperation and engagement we received from our expert cohort were commendable. Not only did they bring a wealth of knowledge to our study, but their enthusiasm and willingness to delve deeply into the subject matter greatly enriched our findings. Through their input, we gained profound insights into the DPIA methodology, which clarified its nuances and intricacies and highlighted areas of controversy. As the study progressed, insights into the ongoing developments in BDA were particularly enlightening. One notable revelation was the potential implications and considerations surrounding the introduction of LLMs, such as ChatGPT and Google Bard,\u003csup\u003e4\u003c/sup\u003e into the public domain, which have gained massive popularity in recent months.\u003c/p\u003e \u003cdiv id=\"Sec8\" class=\"Section2\"\u003e \u003ch2\u003e4.1 First Round\u003c/h2\u003e \u003cp\u003eIn the first round, participants received a questionnaire divided into two sections. The first part consisted of demographic questions, which provided contextual background about the participating experts. This allowed us to understand the composition and diversity of expertise within the panel. By collecting and analysing this information, we ensured a comprehensive representation of opinions, reducing potential biases that could arise from an excessively homogenous group. To strengthen the credibility and legitimacy of our research, and in line with the principles of respect and transparency (Keeney et al., \u003cspan citationid=\"CR26\" class=\"CitationRef\"\u003e2011\u003c/span\u003e), panel participants were required to give explicit consent by reading and approving the terms and conditions governing our Delphi study.\u003c/p\u003e \u003cp\u003eThe second section contained questions designed to explore experts\u0026rsquo; views on both the significance and importance of the PTPs. Our evaluation aimed to establish whether a diverse group of experts, including BDA specialists and privacy and data protection experts, could reach a consensus on the importance of the PTPs in addressing privacy and personal data protection issues specific to BDA. Regarding importance, we sought to determine if there was agreement among experts on incorporating these PTPs into the DPIA process. It was essential to distinguish between relevance and importance. On one hand, a PTP considered relevant might not be viewed as sufficiently crucial or feasible to warrant specific attention within the DPIA. On the other hand, a PTP that was not regarded as relevant to addressing BDA-specific risks or harms might still be seen as important to consider in the DPIA, possibly due to its relevance in more traditional data processing scenarios.\u003c/p\u003e \u003cp\u003eAlongside the Likert scale items, our survey included open-ended questions to gather clarifying comments from experts. The qualitative information obtained from these responses was crucial for providing context to the quantitative evaluations. Delivering an interpretative summary of these ratings to the participants is essential to the consensus-building approach of the Delphi study method, allowing participants to review their views in subsequent rounds. This additional feedback enhanced our dataset, revealing potential areas for further investigation and highlighting areas of disagreement.\u003c/p\u003e \u003cp\u003eUltimately, 14 experts fully completed the first-round questionnaire. Our analysis of the collected responses revealed a strong positive consensus regarding the relevance of PTP (2) \u0026lsquo;identification of individuals from derived data\u0026rsquo; and PTP (3) \u0026lsquo;discrimination issues affecting moral or material personal matters\u0026rsquo;. Additionally, an almost positive consensus on relevance was observed for three other PTPs: PTP (1) \u0026lsquo;unclear data controllership\u0026rsquo;, PTP (4) \u0026lsquo;lack of transparency\u0026rsquo;, and PTP (7) \u0026lsquo;limited range of stakeholders\u0026rsquo; involvement\u0026rsquo;. When assessing importance, PTP (1) and PTP (3) demonstrated an almost strong positive consensus. Notably, no PTPs elicited either a strong negative or almost strong negative consensus regarding relevance and importance. These findings are detailed in Table\u0026nbsp;\u003cspan refid=\"Tab7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab3\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1: Delphi Study Results on Relevance and Importance of Privacy Touchpoints (PTPs) after Round 1\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\" morerows=\"1\" rowspan=\"2\"\u003e \u003cp\u003eMeasurements\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colspan=\"3\" nameend=\"c4\" namest=\"c2\"\u003e \u003cp\u003eLevel of Consensus\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Positive\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eAlmost Strong Positive\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eNo Consensus\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eRelevance\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003ePTP (2), PTP (3)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePTP (1), PTP (4), PTP (7)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003ePTP (5), PTP (6), PTP (8), PTP (9)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eImportance\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e\u0026nbsp;\u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePTP (1), PTP (3)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003ePTP (2), PTP (4), PTP (5), PTP (6), PTP (7), PTP (8), PTP (9)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003e \u003cdiv class=\"BlockQuote\"\u003e \u003cp\u003eThe insights gathered from the open-ended questions broadly confirm the analytical findings. The panel unanimously agreed that PTP (1), PTP (2), PTP (3), PTP (4), and PTP (7) represent risks specific to BDA. Notably, the discussion surrounding PTP (2) \u0026lsquo;identification of individuals from derived data\u0026rsquo; highlighted the inherent challenges posed by BDA inference methodologies, which are exacerbated by the looming threats of algorithmic bias and discrimination. Experts also observed that safeguarding privacy through anonymisation presents significant hurdles due to its inherent complexity.\u003c/p\u003e \u003cp\u003eRegarding PTP (1), \u0026lsquo;unclear data controllership\u0026rsquo;, experts highlighted the multifaceted nature of data control, emphasising the need to address both legal and non-legal considerations in data processing operations. Some experts suggested measures to mitigate this risk, such as assigning different data controllers at various stages of the data analysis process.\u003c/p\u003e \u003cp\u003eIn discussions surrounding PTP (4) \u0026lsquo;lack of transparency\u0026rsquo;, the importance of transparency in BDA was emphasised, particularly due to its correlation with the level of expertise in BDA and relevant protective technologies. However, despite ongoing research efforts in fair and explainable AI, transparency continues to be a significant concern.\u003c/p\u003e \u003cp\u003eThe introduction of PTP (7) \u0026lsquo;limited range of stakeholders involvement\u0026rsquo; was considered relevant; however, experts acknowledged the operational challenges of including a diverse set of stakeholders in the impact assessment process.\u003c/p\u003e \u003cp\u003eFurthermore, experts emphasised the significance of both PTP (1) and PTP (3) in the DPIA process, particularly in addressing BDA-specific risks. However, there was a consensus that all PTPs warrant attention, with their importance varying depending on the specific circumstances of each case.\u003c/p\u003e \u003c/div\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec9\" class=\"Section2\"\u003e \u003ch2\u003e4.2 Second Round\u003c/h2\u003e \u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eThe questionnaire for the second round, completed by 12 participants, retained the same items and 5-point Likert scales as the first round. The purpose of repeating the initial questionnaire was to determine whether the experts could reach an agreement on outstanding PTPs after reviewing the results from the first round. The criteria for consensus remained unchanged from the previous round.\u003c/p\u003e\u003cp\u003eIn addition to assessing the experts\u0026rsquo; agreement on the relevance and importance of PTPs that had not achieved strong positive or negative consensus in the first round, we introduced questions aimed at enhancing the DPIA to address the identified PTPs, which will be the main focus of Delphi round 3. Specifically, participants were asked to share their perspectives on the key components or building blocks of a prospective DPIA framework that should be prioritised for adaptation in a BDA context. These perspectives were solicited based on a conceptual model we developed, drawing on the research of Kloza et al. (2019) (refer to Fig.\u0026nbsp;\u003cspan refid=\"Fig7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1).\u003c/p\u003e\u003cp\u003eThe conceptual model provides a structured representation of the fundamental elements and their interconnections within a DPIA framework. At its core, the framework is centred around \u0026lsquo;policy\u0026rsquo;, which establishes relevant \u0026lsquo;conditions\u0026rsquo; and \u0026lsquo;principles\u0026rsquo;. These \u0026lsquo;conditions\u0026rsquo; indicate specific scenarios or triggers that necessitate a DPIA, while the \u0026lsquo;principles\u0026rsquo; embody core values such as fairness, transparency, accountability, and risk management, ensuring compliance with ethical and legal goals. Kloza et al. (2021) present a comprehensive list of 16 such \u0026lsquo;conditions\u0026rsquo; and \u0026lsquo;principles\u0026rsquo; applicable to various impact assessments. Generally, a DPIA follows a specific \u0026lsquo;method\u0026rsquo; as a guide, outlining the procedures for conducting the assessment. To enhance and support this \u0026lsquo;method\u0026rsquo;, additional resources are available: \u0026lsquo;aids\u0026rsquo; and \u0026lsquo;templates\u0026rsquo; provide practical tools, while the \u0026lsquo;knowledge base\u0026rsquo; offers valuable insights through best practices, past assessments, case studies, and expert opinions. Further guidance is offered through \u0026lsquo;guidelines\u0026rsquo;, which provide detailed instructions on utilising the provided tools and documentation templates in the DPIA process. An example of such a template is the assessment documentation itself, which can be voluntarily shared with the public or made accessible upon request.\u003c/p\u003e\u003cp\u003eBefore starting the second round, all participants were briefed on the results of the first round through a detailed feedback report that included both our statistical and qualitative analyses, along with summaries of the experts\u0026rsquo; responses to the open-ended questions. The main goal was to familiarise the experts with the perspectives of other panel members on each question while ensuring confidentiality.\u003c/p\u003e\u003cp\u003eFrom the results of the second round (see Table\u0026nbsp;\u003cspan refid=\"Tab7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2), strong or almost strong positive agreement for relevance was achieved for five of the seven remaining PTPs. In terms of importance, the agreement rate was even more positive, with strong or almost strong positive agreement for seven of the nine PTPs under consideration.\u003c/p\u003e\u003cp\u003eHowever, no agreement was reached for two PTPs in each category. PTP (8), which addresses operational challenges stemming from procedural ambiguity, underscores a potential lack of practical guidance for evaluating privacy or data protection risks in BDA processing. In contrast, PTP (6) focuses on the improper handling of different types of privacy risks and data breaches, while PTP (7) discusses the limited scope of stakeholder participation. Together, these PTPs highlight the need for a comprehensive approach to addressing various privacy risks and protecting personal data, as well as the importance of broadening stakeholder engagement in impact assessments related to BDA.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab4\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2: Delphi Study Results on Relevance and Importance of Privacy Touchpoints (PTPs) after Round 2\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\" morerows=\"1\" rowspan=\"2\"\u003e \u003cp\u003eMeasurements\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colspan=\"3\" nameend=\"c4\" namest=\"c2\"\u003e \u003cp\u003eLevel of Consensus\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Positive\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eAlmost Strong Positive\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eNo Consensus\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eRelevance\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003ePTP (2), PTP (3), PTP (4), PTP (5)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePTP (1), PTP (7), PTP (9)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003ePTP (6), PTP (8)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eImportance\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003ePTP (1), PTP (2), PTP (3), PTP (5)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePTP (4), PTP (6), PTP (9)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003ePTP (7), PTP (8)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003e\u003cdiv class=\"BlockQuote\"\u003e\u003cp\u003eAnalysing the responses to the open-ended questions helped us interpret the relevance and importance scores provided by the experts. Regarding PTP (4) \u0026lsquo;lack of transparency\u0026rsquo; and PTP (5) \u0026lsquo;increased scope leading to further processing incompatible with the initial purpose\u0026rsquo;, experts emphasised the risks associated with data opacity and intervenability in BDA. These risks often arise from a lack of understanding of personal data collection and processing procedures, especially given the complex nature of certain BDA techniques, some of which operate like a \u0026lsquo;black box\u0026rsquo; (Zeng \u0026amp; Glaister, \u003cspan citationid=\"CR40\" class=\"CitationRef\"\u003e2018\u003c/span\u003e). This underscores how BDA techniques can uncover various sensitive personal information, and many companies are reluctant to forgo the potential for extracting valuable insights.\u003c/p\u003e\u003cp\u003eFor PTP (1) \u0026lsquo;unclear data controllership\u0026rsquo;, experts linked the ambiguity surrounding data controllership to challenges faced by controllers in discerning their obligations. This issue often stems from a limited understanding of the internal mechanics of BDA. One expert also highlighted disparities in the manuals and guidelines established by national data protection authorities (DPAs) across different EU/EEA Member States. Regarding PTP (7) \u0026lsquo;limited range of stakeholder involvement\u0026rsquo;, it was suggested that, barring exceptional circumstances (e.g., criminal suspects), the viewpoints of various stakeholders should consistently be incorporated. Concerning PTP (9) \u0026lsquo;treatment of indirect privacy harms\u0026rsquo;, while the ethical and societal implications are significant, the primary focus in an impact assessment should invariably pivot towards direct harms. When it comes to the level of importance, the panellists expressed similar views. The only exception was PTP (6) \u0026lsquo;improper treatment of different types of privacy risks and data breaches\u0026rsquo;, where no consensus was reached on its BDA-specific relevance; however, most experts still considered it an important aspect of the DPIA when applied in a BDA context. While such ambiguity may reflect doubts about this PTP\u0026rsquo;s relevance voiced by the experts, we decided to reassess PTP (6) in Delphi Round 3 to determine if this ambiguity persists.\u003c/p\u003e\u003cp\u003eIn their responses to the open-ended questions, experts suggested that BDA DPIAs require a more comprehensive scoping approach. One expert noted that this need has led some consulting firms to develop customised PIA or DPIA methodologies. Conversely, other experts believe that the existing templates within these methodologies are sufficient. They do not attribute the perceived shortcomings to the templates themselves but rather to the limited engagement of certain DPAs in the assessment process due to a lack of expertise. While there is consensus that privacy and personal data protection risks, including data breaches, frequently coexist in the realm of BDA, their interrelation is not always clear-cut. Additionally, the practicalities of involving a wider range of stakeholders in the assessment process can be challenging. However, including external participants is advantageous, particularly in identifying potential breaches that could elude internal stakeholders.\u003c/p\u003e\u003cp\u003eWhen analysing the consensus results across rounds regarding response stability \u0026ndash; which assesses the consistency of experts\u0026rsquo; opinions in consecutive Delphi study rounds \u0026ndash; it was evident that there was a significant increase in positive feedback about the relevance and importance of PTP (4) \u0026lsquo;lack of transparency\u0026rsquo; and PTP (5) \u0026lsquo;increased scope leading to further processing incompatible with the initial purpose\u0026rsquo; (refer to Figs.\u0026nbsp;\u003cspan refid=\"Fig7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;2\u003csup\u003e5\u003c/sup\u003e and 4\u0026thinsp;\u0026minus;\u0026thinsp;3). Agreement on importance also showed a similar rise for most PTPs. In contrast, PTP (6) \u0026lsquo;inadequate management of varied privacy risks and data breaches\u0026rsquo; and PTP (8) \u0026lsquo;operational challenges stemming from procedural ambiguity\u0026rsquo; received lower relevance scores in the second round. Furthermore, PTP (8) also received lower importance scores in this round. This observation aligns with the results of our second-round consensus analysis, as the expert panel did not reach a consensus on including PTP (8) in the DPIA for BDA.\u003c/p\u003e\u003cp\u003eWhen discussing which aspects of the DPIA framework displayed in Fig.\u0026nbsp;\u003cspan refid=\"Fig7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1 could be enhanced or extended, along with their associated priorities, the experts identified the highest priority areas as \u0026lsquo;guidelines\u0026rsquo;, \u0026lsquo;knowledge base\u0026rsquo;, and \u0026lsquo;method\u0026rsquo;. Conversely, the \u0026lsquo;software\u0026rsquo; tool designed to facilitate impact assessments was deemed to have the lowest priority.\u003c/p\u003e\u003cp\u003eRegarding expert involvement in the panel, the overall response rate was 70.5%, slightly exceeding the 70% threshold required in any Delphi round (Van Looy et al., \u003cspan citationid=\"CR36\" class=\"CitationRef\"\u003e2017\u003c/span\u003e). Minimising expert dropout is generally essential in this process. In this round, only one expert explicitly requested to resign from the panel, citing family obligations and a lack of time as reasons for withdrawing.\u003c/p\u003e\u003c/div\u003e\u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec10\" class=\"Section2\"\u003e \u003ch2\u003e4.3 Third Round\u003c/h2\u003e \u003cp\u003eThe questionnaire for the third round was completed by 10 participants. This round consisted of the following two parts:\u003c/p\u003e \u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003ePart A: We asked the experts to conduct a final review of the PTPs that had achieved a strong or almost strong positive consensus on either relevance or importance but not on both criteria in Round 2. Specifically, this pertained to PTP (6) \u0026lsquo;inadequate management of varied privacy risks and data breaches\u0026rsquo; and PTP (7) \u0026lsquo;limited range of stakeholder involvement\u0026rsquo;, for which there was no consensus on relevance and importance, respectively.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePart B: We gathered feedback from the experts on suggestions to enhance the DPIA framework, ensuring alignment with the PTPs already identified as relevant and important in Rounds 1 and 2. To assist with this, we referred to the guidelines outlined in DPIA WP29 (2017), the official guide for organisations conducting a DPIA to identify, analyse, and mitigate high-risk data processing activities, ensuring GDPR compliance and enhancing privacy protection.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e \u003cdiv id=\"Sec11\" class=\"Section3\"\u003e \u003ch2\u003e4.3.1 Part A\u003c/h2\u003e \u003cp\u003eTable\u0026nbsp;\u003cspan refid=\"Tab7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026thinsp;\u003cb\u003e\u0026minus;\u0026thinsp;3\u003c/b\u003e shows the results of Round 3. PTP (6) achieved a strong positive consensus on relevance, and the nearly strong positive consensus on importance from Round 2 was confirmed. Virtually all experts expressed concerns about the high likelihood of data breaches associated with the use of BDA. They attributed this risk to the nature of analytics, which involves handling large amounts of personal data and utilising new and untested techniques and algorithms to uncover new information. While noting that not all risks are necessarily negative, experts emphasised the importance of thoroughly assessing and managing them. However, the complexity of BDA presents significant challenges in preventing potential violations and breaches, including the evolving landscape of data protection laws, which could affect the level of protection provided.\u003c/p\u003e \u003cp\u003eRegarding the involvement of external stakeholders in the DPIA \u0026ndash; PTP (7), which has now almost reached a strong positive consensus on its importance \u0026ndash; experts concluded that engaging external stakeholders is not always essential or feasible. Stakeholders, such as data subjects, processors, controllers, and data analysts, should be informed about the issues, but involving all of them in the risk analysis process may present challenges. On the other hand, including external parties can offer valuable insights into privacy and data protection concerns and enhance transparency. Nevertheless, practical aspects, such as determining whom to include, ensuring their active participation, and addressing potential resistance from controllers, could make this approach challenging to implement. The significance of involving external stakeholders may vary depending on the context and scope of the DPIA.\u003c/p\u003e \u003cp\u003eFinally, based on the results from the previous rounds, PTP (8) was excluded from further evaluations. The expert panel did not reach a consensus on the operational challenges arising from procedural ambiguities within the DPIA. However, given the differing perspectives on this issue, we plan to explore it further during individual interviews with the experts. This approach will provide a more detailed understanding of the reasons behind their viewpoints.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab5\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e\u0026thinsp;\u0026minus;\u0026thinsp;3: Delphi Study Results on Relevance and Importance of Privacy Touchpoints (PTPs) after Round 3.\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"4\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c4\" colnum=\"4\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\" morerows=\"1\" rowspan=\"2\"\u003e \u003cp\u003eMeasurements\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colspan=\"3\" nameend=\"c4\" namest=\"c2\"\u003e \u003cp\u003eLevel of Consensus\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Positive\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eAlmost Strong Positive\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c4\"\u003e \u003cp\u003eNo Consensus\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eRelevance\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003ePTP (2), PTP (3), PTP (4), PTP (5), PTP (6)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePTP (1), PTP (7), PTP (9)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003ePTP (8)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eImportance\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003ePTP (1), PTP (2), PTP (3), PTP (5)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePTP (4), PTP (6), PTP (7), PTP (9)\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c4\"\u003e \u003cp\u003ePTP (8)\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec12\" class=\"Section3\"\u003e \u003ch2\u003e4.3.2 Part B\u003c/h2\u003e \u003cp\u003eTo identify ways to enhance the DPIA framework, we reviewed the experts\u0026rsquo; input on the prioritisation of DPIA components based on their relevance to addressing the PTPs, as outlined in Section 4.2 and illustrated in Fig.\u0026nbsp;4.1. Based on the feedback from Round 2, the four key components, ranked in descending order along with the percentage of positive feedback rounded to the nearest whole number, are: \u0026lsquo;knowledge base\u0026rsquo; and \u0026lsquo;method\u0026rsquo; (33%), and \u0026lsquo;guidelines\u0026rsquo; and \u0026lsquo;templates\u0026rsquo; (17%). Table\u0026nbsp;\u0026lt;link rid=\"tb7\"\u0026gt;\u003cspan refid=\"Tab7\" class=\"InternalRef\"\u003e4\u0026lt;/link\u0026gt;\u003c/span\u003e\u0026ndash;\u003cspan refid=\"Tab7\" class=\"InternalRef\"\u003e4\u003c/span\u003e presents the priority levels received based on expert feedback in Round 3, along with explanations of how these priority assessments influenced our suggestions to enhance the DPIA framework. Regarding the definition of \u0026lsquo;Essential\u0026rsquo; and \u0026lsquo;High Priority\u0026rsquo;, the former refers to DPIA components that are critical for the effective functioning of the DPIA framework. On the other hand, the latter (\u0026lsquo;High Priority\u0026rsquo;), indicates DPIA components that are important for improving the efficiency, transparency, and practical application of the DPIA framework.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab6\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e4: Prioritisation of DPIA Framework Components Based on Expert Feedback\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"3\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eDPIA Framework Component\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003ePriority Level Based on Expert Feedback\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eHow Feedback Can Influence Suggestions\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eConditions\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e42% High Priority, 0% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eConditions were not prioritised as essential, indicating a need for further clarification of scenarios for initiating DPIAs.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eGuidelines\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e42% High Priority, 17% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eHigh priority and essential; experts emphasised the need for detailed guidelines to improve transparency and stakeholder engagement.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eKnowledge Base\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e25% High Priority, 33% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eExperts prioritised the knowledge base to support practical applications in BDA with case studies and best practices.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eMethod\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e33% High Priority, 33% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eThe method received strong consensus; experts stressed its importance in structuring DPIA processes, particularly in complex BDA contexts.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003ePolicy\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e17% High Priority, 0% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eWhile deemed important, policy changes were not ranked as essential, suggesting it may need further refinement or specificity.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003ePrinciples\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e50% High Priority, 8% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003ePrinciples were recognised as important, but received lower essential prioritisation, reflecting their supportive role in the DPIA process.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eSoftware Tools\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e17% High Priority, 0% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eSoftware tools were ranked lower in priority, indicating that while useful, they may not be critical in all contexts.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eTemplates\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003e50% High Priority, 17% Essential\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c3\"\u003e \u003cp\u003eTemplates were viewed as highly important for standardising the DPIA process and were ranked as essential by some experts.\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e \u003cp\u003eGuided by the prioritization results, experts were provided with suggestions for each of the established PTPs. For example,\u003csup\u003e6\u003c/sup\u003e regarding PTP (1) \u0026lsquo;unclear data controllership\u0026rsquo;, we proposed further developing the components based on the tiered, layered, and staged consent model (Bunnik et al., \u003cspan citationid=\"CR6\" class=\"CitationRef\"\u003e2013\u003c/span\u003e). This approach would enhance the understanding and completeness of consent for BDA operations in line with established guidelines, addressing the complexity of managing such consent and ultimately creating a new standardised template or consent management platform as a software support tool. Another example relates to the \u0026lsquo;knowledge base\u0026rsquo; and \u0026lsquo;method\u0026rsquo; components, where the need for dynamic, case-based learning resources was emphasised, particularly to tackle the challenges of de-identification and algorithmic transparency identified in PTPs (2) and (4). This feedback directly influenced the decision to prioritise the expansion of the \u0026lsquo;knowledge base\u0026rsquo; as the top-ranked component.\u003c/p\u003e \u003cp\u003eOur key findings regarding our suggestions to enhance the DPIA framework are:\u003c/p\u003e \u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003ePTP (1) \u0026lsquo;unclear data controllership\u0026rsquo;: Responses reflected varied opinions on the effectiveness of current data controllership mechanisms within data protection law. Concerns were raised about the complexity of the consent model, particularly regarding BDA, and the need for improvements in guidelines. Some experts noted specific gaps in data protection laws and the impracticality of the consent model, citing challenges in obtaining \u0026lsquo;informed consent\u0026rsquo; due to its complexity. The clarity of roles in data controllership emerged as a significant concern, with some experts highlighting organisations\u0026rsquo; struggles in this area. Additionally, there were calls for refining regulations to better account for emerging technologies like ChatGPT and deepfakes, although reservations about potential category overlaps under the EU AI Act\u0026rsquo;s layered approach were also expressed.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e PTP (2) \u0026lsquo;identification of individuals from derived data\u0026rsquo;: Experts emphasised the need for more concrete guidelines, especially concerning the anonymisation and de-identification of data. While acknowledging the challenges inherent in these processes \u0026ndash; particularly in BDA contexts \u0026ndash; there was a clear sentiment that de-identification does not equate to complete anonymisation. Some experts expressed scepticism about the real-world significance of re-identification risks, suggesting they might be more theoretical than practical. There were positive views on the DPIA incorporating more specific elements, with suggestions to combine aspects of ISO standards and consider the proposed EU AI Act. However, a call for clarity on risk assessment types distinguishing between privacy and personal data protection risks was made. Given the vast amounts of personal data available online, there is a recognised need for effective de-identification measures. Nevertheless, concerns persist about the feasibility of achieving complete anonymisation, particularly from the perspective of regulatory bodies.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePTP (3) \u0026lsquo;discrimination issues affecting moral or material personal matters\u0026rsquo;: Responses generally supported the incorporation of an ethical and social impact assessment framework for BDA, emphasising the importance of understanding the consequences for vulnerable populations and promoting diversity and inclusion. Experts acknowledged the risks posed by human involvement in algorithm design and provided additional references to ensure fair AI. However, challenges in ensuring fairness in AI beyond algorithmic considerations were noted.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePTP (4) \u0026lsquo;lack of transparency\u0026rsquo;: Experts unanimously agreed on the importance of transparency in BDA. One expert pointed out that transparency can sometimes appear illusory, particularly within the context of data protection law. While regulators prioritise transparency, it was noted that data subjects may not place the same emphasis on it. Differentiating between various roles within organisations \u0026ndash; such as managers, data analysts, and model users \u0026ndash; underscored the critical need for transparency across these functions. The inherent challenges in achieving genuine transparency in BDA and AI were highlighted, with specific concerns raised about \u0026lsquo;black box\u0026rsquo; algorithms. Reference was made to the work of Barredo Arrieta et al. (\u003cspan citationid=\"CR3\" class=\"CitationRef\"\u003e2020\u003c/span\u003e), which underscores the broader literature on fair AI, focusing primarily on algorithmic intricacies. Although the majority of experts agreed that the proposed solution represents a step in the right direction, there was consensus that further research is necessary to effectively implement transparency in AI. Additionally, the acknowledgement of systemic risks in BDA suggests that solutions may only provide limited relief. In summary, while transparency is considered crucial, its practical implementation within BDA and AI remains a multifaceted challenge that may require more nuanced approaches beyond merely opening the \u0026lsquo;black box\u0026rsquo;.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003ePTP (5) \u0026lsquo;increased scope leading to further processing incompatible with the initial purpose\u0026rsquo;: Experts voiced concerns regarding excessive regulation and the potential proliferation of analyses and frameworks while also recognising the necessity for improvement. One expert highlighted the risks associated with additional frameworks and requirements, which could overwhelm the process and potentially divert attention from actual data analysis. Another expert expressed scepticism about the efficacy of these principles for data subjects, citing a specific opinion on purpose limitation (WP29, \u003cspan citationid=\"CR38\" class=\"CitationRef\"\u003e2013\u003c/span\u003e) that has not yet been endorsed. There was a suggestion to consider \u0026lsquo;purpose limitation\u0026rsquo; as a principle to address these concerns, along with a recommendation to examine relevant Court of Justice of the European Union cases. In summary, while there was consensus on the importance of minimising data collection and processing solely for legitimate purposes, questions remain regarding the practicality of conducting multiple complementary assessments.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e The responses from the Delphi study primarily emphasised the importance of addressing societal and ethical concerns in BDA. Many experts supported the idea of providing clear guidance, with some mentioning the fairness, accountability, and transparency framework, as well as the systematic description in the DPIA. A distinction was made between the scope of the DPIA and broader societal concerns, noting that the primary focus of the DPIA is on individual rights as defined in the Charter of Fundamental Rights of the European Union. Including other societal issues could potentially transform the DPIA into an integrated impact assessment. While some respondents recognised the value of addressing these broader concerns, others pointed out challenges in assessing certain societal impacts, such as quantifying the stress or anxiety experienced by individuals affected by identity theft. Two experts either expressed general agreement or admitted unfamiliarity with the topic.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e \u003cp\u003eIn terms of expert panel participation, we received responses from 10 participants in the third round. The decrease in participation can primarily be attributed to time constraints faced by the experts, many of whom requested deadline extensions. As the study progressed and the questions became more detailed, some experts felt unable to respond to these in-depth queries due to a perceived lack of relevant expertise or because they believed they did not possess the appropriate knowledge to address them. Although the number of experts decreased from 14 to 10, we accounted for this reduction when interpreting the consensus. Delphi studies often experience attrition, and a smaller number of experts in later rounds may impact the stability of consensus (Diamond et al., \u003cspan citationid=\"CR9\" class=\"CitationRef\"\u003e2014\u003c/span\u003e; Trevelyan \u0026amp; Robinson, \u003cspan citationid=\"CR35\" class=\"CitationRef\"\u003e2015\u003c/span\u003e). However, it is generally accepted in Delphi studies that as long as the group remains sufficiently diverse and expert participation is consistent, the final consensus remains valid. In our case, the remaining experts still represented key areas of expertise, and their feedback was consistent with earlier rounds, indicating that the smaller group did not significantly skew the results.\u003c/p\u003e \u003cp\u003eWe were not informed of other reasons for reduced participation that have been documented in the relevant literature, such as feedback frustration (Skulmoski et al., \u003cspan citationid=\"CR33\" class=\"CitationRef\"\u003e2007\u003c/span\u003e), lack of incentive (Keeney et al., \u003cspan citationid=\"CR26\" class=\"CitationRef\"\u003e2011\u003c/span\u003e), technical issues (Brady, \u003cspan citationid=\"CR5\" class=\"CitationRef\"\u003e2015\u003c/span\u003e), and loss of anonymity (Linstone \u0026amp; Turoff, \u003cspan citationid=\"CR28\" class=\"CitationRef\"\u003e2002\u003c/span\u003e).\u003c/p\u003e \u003c/div\u003e \u003c/div\u003e \u003cdiv id=\"Sec13\" class=\"Section2\"\u003e \u003ch2\u003e4.4 Interviews with Experts\u003c/h2\u003e \u003cp\u003eFollowing the Delphi study, a targeted group of experts participated in semi-structured interviews, focusing on areas where consensus was not achieved. Specifically, these interviews explored topics related to PTP, such as data controllership, stakeholder involvement, and transparency, which were identified in the Delphi study as needing further examination. In other words, the interviews concentrated on areas where experts raised concerns or expressed divergent views in the Delphi rounds. This qualitative approach aimed to gain deeper insights and pinpoint specific elements of the DPIA requiring enhancement to adequately assess the PTPs. Consequently, the interviews consistently focused on improving the effectiveness of the DPIA for BDA operations.\u003c/p\u003e \u003cp\u003eNine experts, representing all key disciplines relevant to our study \u0026ndash; such as AI, data protection law, BDA, cybersecurity and governance \u0026ndash; took part in the interviews, which were conducted and analysed individually. Saturation of key insights or core ideas was reached after these interviews, leading to the decision to conclude this phase of data collection without soliciting additional interviews. Importantly, each interview began with a questionnaire and was followed by a one-on-one conversation for specific clarification, making the interviews semi-structured.\u003c/p\u003e \u003cp\u003eBelow, we present the convergence and divergence of the experts\u0026rsquo; opinions for each question, along with a synthesis of the discussions leaning towards conclusions for each. By linking the interview findings to the components of the DPIA framework, we aimed to provide a more detailed understanding of how these components can be improved or extended to address the identified PTP risks.\u003c/p\u003e \u003c/div\u003e\n\u003ch3\u003e1) Procedural Indeterminacy and BDA Complexity\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts acknowledge the complexities and challenges inherent in procedural uncertainty within BDA contexts. They agree that navigating the DPIA process can be difficult due to the intricate and often evolving nature of BDA projects. There is a consensus that the DPIA process, when applied to BDA, would benefit from enhanced guidance, support tools, and resources tailored to address BDA\u0026rsquo;s unique complexities and the associated risk factors linked to the PTPs. While flexibility within the fundamental DPIA structure is valued, experts believe that procedural uncertainty is a key concern for practitioners. Consequently, the answers to this question highlight the need for clearer and more accessible guidance to help users effectively manage and mitigate these complexities.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eWhile two experts regarded procedural indeterminacy as a less significant issue, the majority proposed specific solutions. These include guidelines, repositories, and checklists \u0026ndash; such as the AI-HLEG\u0026rsquo;s Ethics Checklist for Trustworthy AI (EC, \u003cspan citationid=\"CR10\" class=\"CitationRef\"\u003e2019\u003c/span\u003e) \u0026ndash; which provide practical advice and tangible real-world examples. This indicates a preference for a structured approach to mitigate uncertainties within the DPIA process. Experts also emphasised the need for a comprehensive list of potential harms, advocating for a more risk-centric approach. Adapting models like FAIR (Factor Analysis of Information Risk) (Freund \u0026amp; Jones, \u003cspan citationid=\"CR14\" class=\"CitationRef\"\u003e2014\u003c/span\u003e) and ISACA\u0026rsquo;s RiskIT framework (ISACA, \u003cspan citationid=\"CR23\" class=\"CitationRef\"\u003e2020\u003c/span\u003e) for BDA risk quantification could further reduce ambiguity.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eThe consensus favours enhancing DPIA guidance for practitioners. Whether through simplified guides, case studies, or clear risk listings, the goal is to make the DPIA process less intimidating and easier to follow. While there is some debate about how to address \u0026lsquo;indeterminacy\u0026rsquo; directly, all experts emphasise the necessity of providing clearer resources to help practitioners understand the inherent complexities of BDA projects. These enhancements would primarily enrich the DPIA knowledge base, guidelines, and templates.\u003c/p\u003e \u003c/p\u003e\n\u003ch3\u003e2) Enhancing Guidelines for BDA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003e Experts strongly agree on the need for enhanced DPIA guidelines specific to BDA. This reflects a common belief that the distinctive complexities of BDA require customised guidance, particularly focused on conducting thorough risk assessments tailored to BDA scenarios. Such enhancements are essential to ensure a robust and efficient DPIA process in this domain.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003e A comprehensive risk identification process is crucial for developing enhanced DPIA guidelines. BDA-specific guidelines should consider the unique aspects of BDA projects, emphasising the vital role of risk assessment. Additionally, they should clearly outline the responsibilities of data controllers and processors to ensure compliance with BDA initiatives.\u003c/p\u003e \u003c/p\u003e \u003cp\u003eUnderstanding data flows is another key element for improved DPIA guidance. This involves thoroughly mapping data processes and establishing authoritative oversight bodies. One expert proposed creating a \u0026lsquo;BDA Body of Knowledge\u0026rsquo; to facilitate understanding of the entire data lifecycle within the DPIA framework. Furthermore, taking inspiration from the AI Act\u0026rsquo;s emphasis on human rights impact assessments (FRA, \u003cspan citationid=\"CR13\" class=\"CitationRef\"\u003e2021\u003c/span\u003e), guidelines should extend beyond data protection to address broader risks to fundamental rights arising from BDA technologies.\u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003e Experts concur on the necessity to refine DPIA guidelines specifically for BDA projects, ensuring they align with European data protection legislation and the emerging AI Act. While the proposed strategies vary (see diverse suggestions), there is a strong consensus that enhanced BDA-specific guidance is essential for effectively navigating the complexities of this domain. These guidelines would ensure that DPIAs are not only compliant but also effective in identifying and mitigating the unique risks associated with big data, as highlighted by the PTPs.\u003c/p\u003e \u003c/p\u003e\n\u003ch3\u003e3) Expanding the Knowledge Base for DPIA in BDA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts widely recognise the importance of expanding the knowledge base that supports the DPIA process in the context of BDA. This expansion involves developing resources, case studies, and examples tailored to the complexities of BDA, enabling practitioners to conduct more informed and effective assessments.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eExperts propose creating a publicly available database containing relevant BDA case studies, including both successful and unsuccessful DPIA examples. Such a database would provide valuable insights and lessons for upcoming projects, fostering knowledge sharing and best practices within the DPIA community. Furthermore, there is a broader need for comprehensive guidance that integrates various perspectives (e.g., legal, ethical, technical, operational) while emphasising thorough risk assessment within BDA.\u003c/p\u003e \u003c/p\u003e \u003cp\u003eEstablishing a multi-stakeholder task force to develop BDA use cases for DPIA could lead to the creation of a code of conduct. Additionally, organising periodic forums by authoritative bodies, such as the European Data Protection Board, could facilitate knowledge exchange among stakeholders. These initiatives would significantly enhance the DPIA knowledge base for BDA.\u003c/p\u003e \u003cp\u003e \u003cb\u003eConclusive Insights\u003c/b\u003e: Experts strongly agree on the necessity of enhancing the knowledge base for conducting DPIAs within BDA contexts. Although specific suggestions may vary, the consensus is clear: comprehensive and accessible resources are crucial. Such resources would enable practitioners to conduct customised and effective DPIAs, considering the diverse range of risks encompassed by the PTPs and the constantly evolving data analytics landscape.\u003c/p\u003e\n\u003ch3\u003e4) DPIA Methodological Adaptations for BDA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts unanimously agree that the fundamental DPIA methodology outlined in Article 35 of the GDPR should remain unchanged. However, they emphasise the need for a robust BDA-specific knowledge base, which would include detailed guidelines, sector-specific risk scenarios, and practical use cases tailored to the DPIA process. This focus on practical resources aims to better equip practitioners to manage DPIAs in the context of BDA projects. Additionally, experts advocate for a shift from mere compliance to a more practical approach to risk assessment, grounded in a broader ethical impact assessment framework.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eWhile experts recognise the limitations of the current DPIA framework for BDA, they advise against making drastic changes. Instead, they propose methodological adaptations to address the PTPs. These improvements include\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003eSeeking input from a variety of stakeholders to gain a broader perspective on risks.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eCreating customised tools, such as checklists and guidance, tailored to specific domains.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eBroadening the scope beyond GDPR to encompass ethical and societal consequences.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003eConsidering integration with frameworks such as the FRIA outlined in the AI Act.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003cp\u003eThis strategy aims to create thorough DPIAs that not only comply with the law but also address the unique ethical and impact-related aspects of BDA projects.\u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eExperts provide clear guidance on effectively conducting DPIAs in BDA contexts. They stress the importance of establishing a comprehensive knowledge base that includes BDA-specific guidelines, risk assessment tools, and practical examples. Prioritising the identification of contextually relevant risks and offering practical solutions is crucial. Furthermore, experts recommend that DPIAs adhere to a holistic impact assessment model that considers ethical and societal considerations alongside legal requirements. Given the evolving regulatory environment, aligning with emerging frameworks like the AI Act is essential. This tailored approach ensures that existing DPIA methodologies can adapt to the specific needs of BDA, promoting both legal compliance and ethical best practices in this dynamic field.\u003c/p\u003e \u003c/p\u003e\n\u003ch3\u003e5) Balancing Rigour and Flexibility in DPIA for BDA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts agree that achieving a balance between rigour and flexibility is essential for conducting effective DPIAs within BDA contexts. The GDPR\u0026rsquo;s accountability principle empowers data controllers to tailor DPIAs to meet diverse needs and risks. While there is no universal approach, experts emphasise that both rigour and flexibility are crucial components of an effective DPIA strategy in the BDA domain.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eExperts propose several strategies to achieve this balance, including the implementation of a \u0026lsquo;four-eyes\u0026rsquo; review/approval principle for the DPIA before launching BDA processing within the organisation. These strategies encompass\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eStakeholder Consultation\u003c/b\u003e: Seeking input from a broad range of perspectives to inform the DPIA process.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eScaled Assessments\u003c/b\u003e: Introducing preliminary or \u0026lsquo;light touch\u0026rsquo; evaluations based on assessed risk levels.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eTool Support\u003c/b\u003e: Utilising tools like certification schemes (e.g., Europrivacy) for tailored BDA analysis.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003ePrinciple-Driven\u003c/b\u003e: Establishing clear principles and evaluation criteria for conducting DPIAs.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eRisk-Focused\u003c/b\u003e: Advocating for a less rigid, outcome-driven approach centred on risk management rather than purely on documentation.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003cp\u003eThese diverse strategies illustrate the potential for tailoring DPIAs to BDA projects while maintaining both rigour and flexibility.\u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eAchieving a balance between rigour and flexibility in BDA DPIAs necessitates a nuanced approach. Organisations should prioritise the adoption of BDA-specific risk assessment tools and guidelines, adjusting the intensity of DPIAs according to the specific context. To promote adaptability without compromising data protection, it is crucial to cultivate a privacy-by-design mindset. This involves moving beyond a mere \u0026lsquo;checklist\u0026rsquo; mentality, embracing continuous risk assessment practices, and integrating DPIA principles throughout the development lifecycles of BDA projects. By adopting these strategies, organisations can effectively manage risks while remaining agile and compliant in the dynamic BDA landscape.\u003c/p\u003e \u003c/p\u003e\n\u003ch3\u003e6) Incorporating Diverse Stakeholder Perspectives in a BDA DPIA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts agree that while the DPIA primarily functions as an internal risk assessment tool for data controllers, there is significant value in incorporating diverse stakeholder perspectives. This can include data subjects, data controllers, processors, privacy experts, legal advisors, and regulatory authorities.\u003csup\u003e7\u003c/sup\u003e However, the need for a comprehensive definition of stakeholders is emphasised.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eTo involve stakeholders from varied backgrounds, experts suggest conducting surveys, interviews, and focus groups led by the DPIA assessor. Some propose pilot projects that include post-DPIA stakeholder engagement monitoring, while others recommend structural changes such as mandatory stakeholder lists, analysis requirements, or reinterpreting Article 35(9) to standardise consultation practices. Additionally, experts advocate for expanding the stakeholder definition to encompass those indirectly affected by BDA processing.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eIncorporating stakeholder perspectives in BDA DPIAs necessitates careful consideration of the project\u0026rsquo;s nature, risk level, and potential impacts on specific groups. Organisations would benefit from sector-specific guidance on identifying key stakeholders and methods for their inclusion. Importantly, while stakeholder input is valuable, it should not overshadow the data controller\u0026rsquo;s primary responsibility for conducting a thorough DPIA.\u003c/p\u003e \u003c/p\u003e\n\u003ch3\u003e7) Addressing Ethical and Societal Concerns in a BDA DPIA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExpert feedback highlights the critical importance of addressing the ethical and societal concerns unique to BDA. While the GDPR provides a foundational framework, the potential for broader harm posed by BDA necessitates a DPIA process that transcends mere legal compliance. A robust DPIA methodology must thoroughly engage with both regulatory requirements and the ethical and societal questions raised by BDA projects.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eExperts propose various approaches for integrating ethical and societal considerations into BDA DPIAs\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eChecklists\u003c/b\u003e: Covering aspects such as data governance, bias mitigation, and alignment with broader objectives like the UN Sustainable Development Goals (SDGs).\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eResponsible AI Inspiration\u003c/b\u003e: Prioritising principles such as non-discrimination, protection of freedoms, and upholding human dignity.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eBeyond \u0026lsquo;Ethics\u0026rsquo;\u003c/b\u003e: Emphasising measurable social values and the prevention of harm.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eManaging Scope\u003c/b\u003e: Some experts caution against extending DPIAs too broadly, suggesting the need for separate frameworks to conduct in-depth ethical analyses alongside DPIAs.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003cp\u003eThese diverse perspectives underscore the necessity of a balanced approach that integrates ethical and societal considerations without compromising the core functions of DPIAs.\u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eExperts emphasise the importance of incorporating ethical and societal evaluations into BDA DPIAs. The focus should be on recognising actual harms such as discrimination, fairness issues, and social inequalities. Organisations can refer to responsible AI principles and fundamental rights frameworks (such as the AI Act) and possibly align with broader goals like the UN SDGs.\u003c/p\u003e \u003c/p\u003e \u003cp\u003eTo maintain the efficiency of DPIAs, a systematic approach is essential. This may require integrating ethical considerations proportionally with concurrent, thorough assessments for high-risk BDA projects. Such a holistic strategy aims to ensure responsible BDA execution that upholds individual rights and enhances societal welfare.\u003c/p\u003e\n\u003ch3\u003e8) Enhancing Transparency and Accountability in a BDA DPIA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts strongly agree on the importance of transparency and accountability in BDA DPIAs. They emphasise the need for proactive communication with stakeholders, including public outreach about the project, its impacts, and how stakeholders can provide input. Furthermore, experts stress the importance of demonstrating accountability through documented risk assessments, well-defined mitigation plans, and clearly stated ownership at all stages of BDA implementation.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eExperts propose a multifaceted approach to enhance transparency and accountability in BDA DPIAs. Key strategies include\u003c/p\u003e \u003c/p\u003e \u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003ePublic or Internal (Data Protection) Notices\u003c/b\u003e: Providing stakeholders with information about the project\u0026rsquo;s purpose, potential impact, and avenues for feedback.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eMeticulous Risk Analysis\u003c/b\u003e: Conducting thorough assessments of the risks associated with BDA projects and developing actionable mitigation plans.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eSpecialised Guidelines\u003c/b\u003e: Developing BDA-specific tools and guidelines, potentially in collaboration with a dedicated task force, to promote transparency and accountability.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eSupervisory Authority Role\u003c/b\u003e: Engaging supervisory authorities in awareness campaigns and promoting best practices to enhance transparency and accountability.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eAI Act Inspiration\u003c/b\u003e: Drawing inspiration from principles outlined in the AI Act, such as those related to data quality and bias, and incorporating them into BDA DPIA documentation.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e \u003cp\u003eThis comprehensive approach aims to strengthen trust and responsibility within the BDA landscape.\u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eThe consensus highlights the critical importance of improving transparency and accountability in a DPIA process tailored to BDA. This necessitates a proactive approach, with organisations openly engaging with stakeholders, providing clear project explanations, and actively soliciting feedback. To implement these principles, it is essential to thoroughly document assessments, risks, and mitigations, and clearly define ownership for oversight. Crafting BDA-specific guidelines and tools, as well as involving supervisory authorities in promoting best practices, are crucial for fostering a culture of trust within the BDA domain. Transparency and accountability go beyond mere compliance; they exemplify responsible BDA usage for the benefit of individuals and society. These principles are essential for ensuring that BDA technologies are developed and deployed responsibly, respecting privacy, upholding ethical standards, and contributing positively to society.\u003c/p\u003e \u003c/p\u003e\n\u003ch3\u003e9) Future-proofing the DPIA process for BDA\u003c/h3\u003e\n\u003cp\u003e \u003cstrong\u003eConsensus Overview\u003c/strong\u003e \u003cp\u003eExperts emphasise the need for the DPIA to evolve into a flexible framework that can adapt to the rapid advancements and innovations in BDA. They recognise that AI serves a dual purpose in BDA DPIAs, acting both as a tool for conducting assessments and as a key component of the assessment itself. While a complete overhaul may not be necessary at this stage, the DPIA must continuously develop to remain relevant in the changing landscape of BDA technologies and associated risks. Future-proofing involves anticipating challenges, incorporating adaptability into assessment procedures, and regularly updating the framework to address new risks and opportunities, thereby ensuring privacy and data security.\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cstrong\u003eDiverse Suggestions\u003c/strong\u003e \u003cp\u003eExperts propose several strategies to future-proof DPIAs for BDA\u003c/p\u003e \u003c/p\u003e \u003cp\u003e \u003cul\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eUpdate Risk Catalogues\u003c/b\u003e: Stay informed about emerging BDA risks.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eExpand Impact Assessments\u003c/b\u003e: Incorporate societal values alongside data protection considerations.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eDevelop Sector-Specific Use Cases\u003c/b\u003e: Provide tailored guidance for key BDA industries.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eRequire Expertise\u003c/b\u003e: Ensure that DPIA practitioners possess the necessary knowledge in both privacy and BDA.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eFocus on Explainability\u003c/b\u003e: Mandate clear reasoning within BDA systems to enhance transparency.\u003c/p\u003e \u003c/li\u003e \u003cli\u003e \u003cp\u003e \u003cb\u003eRegular Reviews\u003c/b\u003e: Continuously update DPIAs in response to technological advancements and evolving data usage.\u003c/p\u003e \u003c/li\u003e \u003c/ul\u003e \u003c/p\u003e \u003cp\u003eThese actions aim to ensure the relevance of DPIAs amidst the rapid innovation occurring in the BDA field.\u003c/p\u003e \u003cp\u003e \u003cstrong\u003eConclusive Insights\u003c/strong\u003e \u003cp\u003eExperts emphasise the critical importance of future-proofing DPIAs to keep pace with the ever-changing nature of BDA. This necessitates a shift towards a flexible, adaptable approach within organisations. Recognising the dual role of AI \u0026ndash; both as a tool for conducting DPIAs and as a subject of assessment \u0026ndash; is essential. Guidelines, resources, and risk catalogues must be consistently updated to align with emerging BDA technologies and their associated risks. Regular reviews of DPIAs, triggered by changes in technology or data usage, will help maintain their relevance. Furthermore, emphasising overarching principles of risk, ethics, and societal considerations will establish a stronger foundation for DPIAs to effectively address emerging challenges in the dynamic BDA landscape.\u003c/p\u003e \u003c/p\u003e \u003cp\u003eTable\u0026nbsp;\u003cspan refid=\"Tab7\" class=\"InternalRef\"\u003e4\u003c/span\u003e\u0026ndash;5 summarises the consensus levels for the questions discussed by the experts regarding the necessary improvements and adaptations for DPIAs in the context of BDA. Although there is no universally accepted standard for categorising percentage ranges in consensus levels (Hasson, \u003cspan citationid=\"CR19\" class=\"CitationRef\"\u003e2000\u003c/span\u003e), we classified \u0026lsquo;unanimous agreement\u0026rsquo; as 100% agreement, \u0026lsquo;strong consensus\u0026rsquo; for agreement above 75%, and \u0026lsquo;moderate consensus\u0026rsquo; for the range of 50\u0026ndash;74% agreement, based on the responses gathered during the interviews. This breakdown clarifies areas where expert opinions were closely aligned and where a greater diversity of perspectives emerged.\u003c/p\u003e \u003cp\u003e \u003cdiv class=\"gridtable\"\u003e\u003ctable float=\"Yes\" id=\"Tab7\" border=\"1\"\u003e \u003ccaption language=\"En\"\u003e \u003cdiv class=\"CaptionNumber\"\u003eTable 4\u003c/div\u003e \u003cdiv class=\"CaptionContent\"\u003e \u003cp\u003e5: Summary of Consensus Levels Across Questions\u003c/p\u003e \u003c/div\u003e \u003c/caption\u003e \u003ccolgroup cols=\"3\"\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c1\" colnum=\"1\"\u003e\u003c/div\u003e \u003cdiv align=\"left\" class=\"colspec\" colname=\"c2\" colnum=\"2\"\u003e\u003c/div\u003e \u003cdiv align=\"char\" char=\".\" class=\"colspec\" colname=\"c3\" colnum=\"3\"\u003e\u003c/div\u003e \u003cthead\u003e \u003ctr\u003e \u003cth align=\"left\" colname=\"c1\"\u003e \u003cp\u003eQuestion\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c2\"\u003e \u003cp\u003eConsensus Level\u003c/p\u003e \u003c/th\u003e \u003cth align=\"left\" colname=\"c3\"\u003e \u003cp\u003eAgreement (%)\u003c/p\u003e \u003c/th\u003e \u003c/tr\u003e \u003c/thead\u003e \u003ctbody\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eProcedural Indeterminacy in BDA DPIAs\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eModerate Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e60\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eEnhancing Guidelines for BDA\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e70\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eExpanding the Knowledge Base\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e80\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eMethodological Adaptations for BDA DPIAs\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eModerate Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e50\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eBalancing Rigour and Flexibility\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eUnanimous Agreement\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e100\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eIncorporating Stakeholder Perspectives\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eMixed Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e50\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eAddressing Ethical and Societal Implications\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e75\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eEnhancing Transparency and Accountability\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e80\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003ctr\u003e \u003ctd align=\"left\" colname=\"c1\"\u003e \u003cp\u003eFuture-Proofing DPIA for BDA\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"left\" colname=\"c2\"\u003e \u003cp\u003eStrong Consensus\u003c/p\u003e \u003c/td\u003e \u003ctd align=\"char\" char=\".\" colname=\"c3\"\u003e \u003cp\u003e85\u003c/p\u003e \u003c/td\u003e \u003c/tr\u003e \u003c/tbody\u003e \u003c/colgroup\u003e \u003c/table\u003e\u003c/div\u003e \u003c/p\u003e\n\u003cp\u003e[4] As of February 2024, Google Bard has been renamed Gemini.\u0026nbsp;\u003c/p\u003e\n\u003cp\u003e[5] PTP (2) and (3) are not included in this graph as they received strong consensus in the first round and were therefore not subject to further evaluation in round 2.\u003c/p\u003e\n\u003cp\u003e[6] For additional details on the remaining PTPs, please refer to the information provided in the third questionnaire, available at: https://github.com/georggr/bda-dpia-research-data\u003c/p\u003e\n\u003cp\u003e[7] This typically refers to the prior checks and consultations with Supervisory Authorities, especially when the results of the DPIA indicate high residual data protection risks. \u0026nbsp;\u003c/p\u003e"},{"header":"5 Lessons Learned and Recommendations for Improving the DPIA Framework for BDA","content":"\u003cp\u003eThis section translates the findings from the Delphi study and expert interviews into practical recommendations for adapting the DPIA framework to the BDA context, specifically addressing the PTPs validated in the Delphi study. We begin by summarising key lessons learned, highlighting crucial insights about the complexities of BDA, its nuanced privacy risks, and the shortcomings of the current DPIA framework. Based on this analysis, we provide specific recommendations for developing a more robust DPIA methodology tailored to BDA. Finally, we explore how the DPIA framework can be adjusted to incorporate these improvements, ensuring compliance with both legal and ethical aspects of BDA implementation. By implementing these insights and recommendations, the DPIA framework can better tackle the challenges and opportunities presented by BDA. This will not only strengthen data privacy and protection within BDA but also promote its sustainable and ethical use for innovation and development.\u003c/p\u003e \u003cdiv id=\"Sec24\" class=\"Section2\"\u003e \u003ch2\u003e5.1 Lessons Learned\u003c/h2\u003e \u003cp\u003eOur study uncovered several complexities in BDA, highlighted data protection risks, and revealed limitations in the current DPIA framework, which are outlined below:\u003c/p\u003e \u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eComplexity of BDA\u003c/b\u003e: The integration of BDA into various sectors creates a complex landscape that poses significant challenges for personal data protection and privacy. BDA\u0026rsquo;s capacity to process vast volumes of data at high speeds introduces unique risks, underscoring the need for a DPIA framework that effectively addresses these complexities.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003ePrivacy and Data Protection Risks\u003c/b\u003e: The research identified specific PTPs that represent BDA-specific risks, including issues related to data controllership, identification from derived data, discrimination, transparency, and stakeholder involvement. The varying levels of consensus on these PTPs across the Delphi study rounds indicate the nuanced understanding required for effective mitigation.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eCurrent DPIA Limitations\u003c/b\u003e: The Delphi study and expert interviews revealed that the existing DPIA framework may not fully capture the intricacies and risks associated with BDA. This includes gaps in addressing the full scope of BDA-specific risks, procedural ambiguity, and the evolving nature of data protection laws.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eExpert Consensus on Improvement Needs\u003c/b\u003e: There is strong consensus among experts regarding the need to enhance the DPIA framework to increase its relevance for BDA. Recommendations include clearer guidelines, expanded knowledge bases, methodological adaptations, and a balance between rigour and flexibility.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec25\" class=\"Section2\"\u003e \u003ch2\u003e5.2 Recommendations for Improving the DPIA Framework\u003c/h2\u003e \u003cp\u003eBased on our understanding of the challenges and limitations identified, we propose the following recommendations:\u003c/p\u003e \u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eEnhanced Guidelines and Clearer Procedures\u003c/b\u003e: Develop specific DPIA guidelines for BDA that provide clearer, actionable steps for identifying and mitigating risks. Include detailed risk assessment criteria and processes tailored to the unique challenges of BDA, as outlined in the PTPs.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eExpanded Knowledge Base\u003c/b\u003e: Create a comprehensive knowledge base that includes case studies, best practices, and lessons learned specific to BDA. This resource should be easily accessible and routinely updated to reflect the latest developments in BDA technologies and data protection regulations.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eMethodological Adaptations\u003c/b\u003e: Modify the DPIA methodology to incorporate BDA-specific data privacy and protection considerations, such as those introduced by sophisticated algorithms and advanced computational techniques. Provide tools and frameworks to facilitate thorough assessments of PTPs, focusing on issues related to discrimination and transparency.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eIncorporating Stakeholder Perspectives\u003c/b\u003e: Adopt a more inclusive approach by engaging a broader range of stakeholders in the DPIA process. Involve data subjects, data analysts, and external experts, including public authorities, particularly in cases indicating high residual data protection risks, to gather diverse perspectives on PTPs.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eBalancing Rigour and Flexibility\u003c/b\u003e: Achieve a balance between rigour and flexibility in the DPIA process to accommodate the dynamic nature of BDA projects. This should involve scalable assessments based on the level of risk and the complexity of data processing activities.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eEthical and Societal Considerations\u003c/b\u003e: Broaden the scope of the DPIA to encompass the ethical and societal implications of BDA projects. Conduct holistic impact assessments that extend beyond legal compliance to evaluate effects on fundamental rights and societal values.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eContinuous Improvement and Future-Proofing\u003c/b\u003e: Establish a mechanism for ongoing review and enhancement of the DPIA framework in response to emerging BDA technologies and evolving data protection laws. Ensure regular updates to guidelines, templates, and the knowledge base to maintain the effectiveness and relevance of the DPIA.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec26\" class=\"Section2\"\u003e \u003ch2\u003e5.3 Changing the Conceptual Model of the DPIA Framework to Incorporate Experts\u0026rsquo; Recommendations\u003c/h2\u003e \u003cp\u003eGiven the conceptual model of the DPIA framework and insights from the Delphi study and expert interviews, the components outlined below need adjustment to ensure the DPIA framework is usable and effective in a BDA context. Enhancing these components will enable organisations and regulatory bodies to effectively address the PTPs, ensuring that DPIA procedures align with legal requirements and broader ethical considerations, thereby fostering confidence and responsibility in data-centric innovation.\u003c/p\u003e \u003cp\u003eApart from stating the recommendations, we also clarify their motivation by tracing back to the relevant findings and insights obtained in the Delphi study and the expert interviews.\u003c/p\u003e \u003cp\u003e\u003cul\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003ePolicy Enhancement\u003c/b\u003e: Update policies to explicitly include considerations for BDA, ensuring they effectively address the PTPs. Integrate revised data protection policies that reflect the latest legal and ethical standards related to BDA. \u003cb\u003eMotivation\u003c/b\u003e: The Delphi study and expert interviews highlighted the need for clearer policies that specifically address the unique risks posed by BDA. This modification aligns with expert feedback recommending clearer regulatory guidance on using BDA in DPIAs.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eConditions Refinement\u003c/b\u003e: Clearly define conditions or scenarios specific to BDA projects that necessitate a DPIA. This may involve identifying new or advanced analytics techniques that pose a higher probability of impacting data privacy and security. Incorporate conditions that consider the scale, complexity, and sensitivity of data processed by BDA technologies. \u003cb\u003eMotivation\u003c/b\u003e: Experts noted the challenges of applying current conditions to the diverse and evolving nature of BDA. This modification responds to their recommendations, ensuring that the conditions are not overly prescriptive while effectively guiding risk assessments in BDA contexts.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003ePrinciples Expansion\u003c/b\u003e: Introduce or expand existing principles particularly relevant to BDA, such as data minimisation, purpose limitation, and transparency in algorithmic decision-making processes. Strengthen principles related to fairness and non-discrimination, acknowledging BDA\u0026rsquo;s potential to exacerbate biases. \u003cb\u003eMotivation\u003c/b\u003e: Experts called for a broader inclusion of ethical and societal considerations in BDA, emphasising the need for principles that extend beyond privacy and data protection to include fairness, transparency, and accountability. This modification integrates these additional principles to ensure that the DPIA framework accommodates the ethical complexities identified during the interviews and the Delphi study.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eMethod Adaptation\u003c/b\u003e: Develop methodologies tailored to the intricacies of BDA, including guidelines for evaluating the impact of AI and machine learning models on privacy and data protection. Incorporate methodologies for dynamic and continuous risk assessment to accommodate the iterative nature of BDA projects. \u003cb\u003eMotivation\u003c/b\u003e: Expert feedback consistently highlighted the need to adapt the DPIA method to account for specific risks associated with BDA. This modification ensures the method remains flexible enough to handle diverse BDA applications while maintaining rigour in the assessment of data protection risks.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eAids and Templates Update\u003c/b\u003e: Create or revise aids and templates specifically designed for BDA projects, including risk assessment tools, consent forms, and impact assessment templates that address the unique aspects of BDA. Develop BDA-specific checklists and flowcharts to facilitate structured DPIA processes for data controllers. \u003cb\u003eMotivation\u003c/b\u003e: Experts recommended developing practical tools, such as templates and aids, to assist organisations in conducting effective DPIAs in BDA contexts. This modification addresses the procedural gaps identified during the Delphi study and interviews, ensuring that the DPIA process is user-friendly and comprehensive.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eKnowledge Base Expansion\u003c/b\u003e: Substantially expand the knowledge base to include case studies, best practices, and lessons learned from BDA projects, highlighting both successes and challenges in safeguarding personal data. Incorporate insights from recent BDA advancements, including the use of emerging technologies and compliance with new data protection regulations. \u003cb\u003eMotivation\u003c/b\u003e: The Delphi study and expert interviews consistently underscored the need to expand the knowledge base to support organisations conducting DPIAs for BDA. This modification implements that recommendation by creating a dynamic knowledge base populated with sector-specific guidelines, case studies, and best practices that evolve with new developments in the field, providing practitioners with essential resources to stay informed and compliant.\u003c/p\u003e\u003c/li\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eGuidelines Clarification\u003c/b\u003e: Provide comprehensive guidelines for conducting DPIAs for BDA projects, offering clear instructions for addressing the PTPs. Include guidance on involving stakeholders, including data subjects, in the DPIA process for BDA projects to enhance transparency and accountability. \u003cb\u003eMotivation\u003c/b\u003e: Experts expressed the need for clearer and more specific guidelines tailored to the unique challenges of BDA, balancing procedural flexibility in DPIAs with structured guidance and practical tools to effectively manage the complexities inherent in BDA. This modification addresses these concerns by offering detailed instructions on conducting DPIAs in BDA contexts, particularly regarding data controllership, stakeholder involvement, and transparency.\u003c/p\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/p\u003e \u003cp\u003eIn this context, our redefined DPIA conceptual model, as illustrated in Fig.\u0026nbsp;\u003cspan refid=\"Fig8\" class=\"InternalRef\"\u003e5\u003c/span\u003e\u0026thinsp;\u0026minus;\u0026thinsp;1, incorporates four additional elements,\u003csup\u003e8\u003c/sup\u003e each directly linked to existing concepts to ensure seamless integration. These new elements aim to enhance the DPIA framework by effectively addressing the complexities, ethical considerations, stakeholder input, and practical needs arising from BDA implementation:\u003c/p\u003e \u003cp\u003e\u003col\u003e\u003cspan\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eEthical AI Guidelines (Linked to DPIA Principles)\u003c/b\u003e: This element underscores the fundamental importance of ethical considerations within the DPIA, expanding existing principles to advocate for responsible AI practices from the outset.\u003c/p\u003e\u003c/li\u003e\u003c/span\u003e\u003cspan\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eBDA Risk Matrix (Linked to DPIA Method)\u003c/b\u003e: This matrix offers a structured understanding of BDA-specific risks. Its integration directly informs risk assessments within the DPIA, guiding mitigation strategies and shaping the overall approach.\u003c/p\u003e\u003c/li\u003e\u003c/span\u003e\u003cspan\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003eStakeholder Engagement Framework (Linked to DPIA Method)\u003c/b\u003e: This framework establishes clear mechanisms and procedures for involving stakeholders throughout the DPIA process. Its connection emphasises a more dynamic and interactive approach, enhancing transparency and accountability.\u003c/p\u003e\u003c/li\u003e\u003c/span\u003e\u003cspan\u003e\u003cli\u003e\u003cp\u003e\u003cb\u003ePrivacy Engineering Tools (Linked to Aids and Templates)\u003c/b\u003e: These tools facilitate the implementation of technical solutions for data protection. This link bridges the gap between principles and practice, ensuring that tools are easily accessible and integrated into DPIA documentation.\u003c/p\u003e\u003c/li\u003e\u003c/span\u003e\u003c/ol\u003e\u003c/p\u003e \u003cp\u003e \u003c/p\u003e \u003c/div\u003e\u003cp\u003e[8] The newly introduced concepts are highlighted in light blue for better visual distinction. Dotted lines show their direct connections to existing concepts within the DPIA conceptual model.\u003c/p\u003e"},{"header":"6 Research Contribution and Limitations","content":"\u003cp\u003eThis paper offers a comprehensive analysis of the challenges and considerations for enhancing the DPIA in the context of BDA. By leveraging an in-depth Delphi study comprising three rounds, alongside individual interviews with experts from various fields, our research underscores the necessity for an advanced DPIA approach capable of effectively managing the unique risks and complexities associated with BDA technologies. In our study, these risks are encapsulated as PTPs. The findings have enriched both academic understanding and practical implementations, particularly in designing a DPIA framework for large-scale data projects. The following subsections summarise our research contributions and limitations.\u003c/p\u003e \u003cdiv id=\"Sec28\" class=\"Section2\"\u003e \u003ch2\u003e6.1 Research Contributions\u003c/h2\u003e \u003cp\u003eOur study thoroughly explores the challenge of making the DPIA more relevant and effective within the BDA context. To address this, we conducted a Delphi study complemented by expert interviews to analyse diverse perspectives, emphasising the need for a more advanced DPIA framework to manage specific BDA risks, encapsulated in our nine PTPs.\u003c/p\u003e \u003cp\u003eOur research contributions extend those of the conference papers (i.e., (Georgiadis \u0026amp; Poels, \u003cspan citationid=\"CR15\" class=\"CitationRef\"\u003e2022a\u003c/span\u003e, \u003cspan citationid=\"CR17\" class=\"CitationRef\"\u003e2023a\u003c/span\u003e, \u003cspan citationid=\"CR18\" class=\"CitationRef\"\u003e2023b\u003c/span\u003e)) that presented results from individual Delphi study rounds with the emphasis on expert validation of the PTPs that were synthesized from our systematic literature review (Georgiadis \u0026amp; Poels, \u003cspan citationid=\"CR16\" class=\"CitationRef\"\u003e2022b\u003c/span\u003e). In this paper, our research extends beyond mere analysis, providing additional insights and recommendations that were not covered in earlier publications. We not only rigorously validate the nine PTPs across the three Delphi study rounds but building on these insights and the findings from subsequent expert interviews, we offer practical suggestions for practitioners and policymakers, advocating for clearer DPIA guidelines, robust knowledge bases, and methodologies specifically adjusted to the complexities of BDA. Importantly, we propose actionable adjustments to the DPIA framework itself to ensure effective identification and mitigation of the PTPs. Our refined conceptual model lays the groundwork for extending the current DPIA framework, making it more robust and relevant for BDA environments.\u003c/p\u003e \u003c/div\u003e \u003cdiv id=\"Sec29\" class=\"Section2\"\u003e \u003ch2\u003e6.2 Limitations\u003c/h2\u003e \u003cp\u003eWhile this study provides valuable insights into improving the DPIA framework for BDA scenarios, it is important to acknowledge its limitations. Although our Delphi panel was diverse, it may not fully capture the breadth of perspectives within the BDA and data privacy fields. Given the constant evolution of technology, it is essential to periodically review our research results to maintain the relevance of the identified key points and expert recommendations. Furthermore, as our research focuses on the GDPR framework for personal data protection and data privacy, further investigation is needed to assess its applicability in different legal and cultural contexts. Implementing the suggested enhancements to the DPIA may encounter challenges such as limited resources or varying levels of organisational support. To address these obstacles, future studies could adopt action research methodologies to bridge the gap between DPIA improvements and their real-world implementation. This approach could involve developing tailored guidelines and tools for various BDA settings, followed by collecting and analysing their impact to inform further improvements.\u003c/p\u003e \u003c/div\u003e"},{"header":"7 Future Research Directions","content":"\u003cp\u003eTo ensure that our proposed DPIA framework remains practical and effective, we recommend a multifaceted research roadmap. This roadmap should focus on the continuous revision and potential expansion of the PTPs to address emerging BDA-specific privacy and data protection risks. It is crucial to explore ways to develop and enrich the DPIA\u0026rsquo;s knowledge base, aligning it with BDA technologies, as well as strategies for improving and automating risk assessments, some of which may relate to complex cybersecurity issues.\u003c/p\u003e \u003cp\u003e It is also important to investigate how to address ethical and societal considerations related to BDA within the DPIA by creating useful tools and guidelines for practitioners. Developing strategies to foster a culture of data privacy within organisations through continuous training and awareness programmes is essential. Additionally, conducting studies across industries and jurisdictions can help further tailor our proposed DPIA framework. Exploring methods to incorporate AI-driven enhancements for risk identification and assessment would significantly streamline the DPIA implementation process and reduce the overall effort required, especially considering the inherent complexity and occasional opacity of the underlying BDA processing activities. Within this scope, we can also investigate means of integrating models like FAIR and ISACA\u0026rsquo;s RiskIT framework.\u003c/p\u003e \u003cp\u003eThe ultimate goal of these future research initiatives is to further enhance the DPIA framework, ensuring it remains relevant and useful in light of technological advancements and legislative changes. By doing so, we aim to provide organisations with an easily adaptable tool to address data privacy and protection challenges within the rapidly evolving BDA landscape.\u003c/p\u003e"},{"header":"8 Conclusion and Outlook","content":"\u003cp\u003eOur study on DPIAs in BDA settings highlights the connection between technological advancements and the safeguarding of privacy and personal data protection. Based on a Delphi study followed by expert interviews, it underscores the need for a DPIA framework that goes beyond mere legal compliance to address the unique challenges posed by BDA.\u003c/p\u003e \u003cp\u003eTo answer our research question \u0026ndash; \u003cem\u003eWhat changes or improvements should be considered to enhance the DPIA to make it more relevant for use in BDA contexts where personal data is processed?\u003c/em\u003e \u0026ndash; we thoroughly analysed nine PTPs that capture BDA-related privacy and data protection risks. These risks correspond to key challenges, such as ambiguous data controllership, which emphasises the need for transparency and stakeholder involvement. A significant contribution of this study lies in the analysis and validation of these risks, enhancing our understanding of how BDA intersects with data privacy and protection concern. While our research has limitations, it provides recommendations for enhancing the existing DPIA process. These include suggestions for BDA-specific guidelines, an expanded knowledge base, and methodological adjustments to navigate the complexities of BDA. Incorporating Ethical AI Guidelines and a BDA Risk Matrix into the DPIA framework represents a substantial step towards robust data protection in the realm of big data. These recommendations serve as a foundation for ongoing discussion and development, promoting an approach that safeguards personal data within BDA initiatives. As BDA continues to expand across industries, having a forward-looking or \u0026lsquo;future-proof\u0026rsquo; DPIA framework is essential. This framework must anticipate both existing and emerging challenges to uphold data protection as a fundamental principle of digital environments \u0026ndash; \u0026lsquo;by design and by default\u0026rsquo;. The rapid pace of technological advancement underscores the importance of researching and adjusting privacy protocols. The limitations identified in this study, particularly regarding expertise and practical application, highlight areas that warrant further investigation. Engaging a diverse range of stakeholders \u0026ndash; including technologists, policymakers, the general public, and public authorities in specific cases \u0026ndash; is crucial for developing a DPIA framework that effectively balances data protection concerns with various perspectives.\u003c/p\u003e \u003cp\u003eIn conclusion, this study addresses our research question while advancing understanding of how to enhance the DPIA within the BDA context. By connecting technological advancements with data protection, the suggested recommendations foster an environment where big data can be responsibly utilised, ensuring that innovation and privacy are closely linked.\u003c/p\u003e"},{"header":"Declarations","content":"\u003cul\u003e\n \u003cli\u003e\u003cstrong\u003eEthics approval and consent to participate:\u0026nbsp;\u003c/strong\u003eInformed consent was obtained from all individual participants included in the study\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eConsent for publication:\u0026nbsp;\u003c/strong\u003eBoth authors have read and approved the final version of the manuscript and consent to its submission for publication in \u003cem\u003eInformation Systems Frontiers\u003c/em\u003e.\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eAvailability of data and material:\u0026nbsp;\u003c/strong\u003eThe datasets generated and analysed in the described research are publicly \u0026nbsp;available in the GitHub repository at https://github.com/georggr/bda-dpia-research-data\u003cstrong\u003e.\u003c/strong\u003e\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eCompeting interests:\u0026nbsp;\u003c/strong\u003eThe authors declare that they have no conflict of interest\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eFunding:\u003c/strong\u003e This research received no external funding\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eAuthors\u0026rsquo; contributions:\u0026nbsp;\u003c/strong\u003eGeorgios Georgiadis was responsible in conducting the study and drafting, analysing the manuscript. Geert Poels contributed significantly by reviewing, revising and improving the manuscript for intellectual content. Both authors read and approved the final version of the manuscript.\u003c/li\u003e\n \u003cli\u003e\u003cstrong\u003eAcknowledgments:\u003c/strong\u003e Not applicable\u003c/li\u003e\n\u003c/ul\u003e"},{"header":"References","content":"\u003col\u003e\u003cli\u003e\u003cspan\u003eAmmon K (2023) \u003cem\u003eGenerative AI, Bias, Hallucinations and GDPR\u003c/em\u003e. Fieldfisher. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://www.fieldfisher.com/en/insights/generative-ai-bias-hallucinations-and-gdpr\u003c/span\u003e\u003cspan address=\"https://www.fieldfisher.com/en/insights/generative-ai-bias-hallucinations-and-gdpr\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBaker J, Lovell K, Harris N (2006) How expert are the experts? An exploration of the concept of \u0026lsquo;expert\u0026rsquo; within Delphi panel techniques. Nurse Res 14(1):59\u0026ndash;70. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.7748/nr2006.10.14.1.59.c6010\u003c/span\u003e\u003cspan address=\"10.7748/nr2006.10.14.1.59.c6010\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBarredo Arrieta A, D\u0026iacute;az-Rodr\u0026iacute;guez N, Del Ser J, Bennetot A, Tabik S, Barbado A, Garcia S, Gil-Lopez S, Molina D, Benjamins R, Chatila R, Herrera F (2020) Explainable Artificial Intelligence (XAI): Concepts, taxonomies, opportunities and challenges toward responsible AI. Inform Fusion 58:82\u0026ndash;115. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1016/j.inffus.2019.12.012\u003c/span\u003e\u003cspan address=\"10.1016/j.inffus.2019.12.012\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBeiderbeck D, Frevel N, von der Gracht HA, Schmidt SL, Schweitzer VM (2021) Preparing, conducting, and analyzing Delphi surveys: Cross-disciplinary practices, new directions, and advancements. \u003cem\u003eMethodsX\u003c/em\u003e, \u003cem\u003e8\u003c/em\u003e, 101401. https://doi.org/10/gmpjvv\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBrady SR (2015) Utilizing and Adapting the Delphi Method for Use in Qualitative Research. Int J Qualitative Methods 14(5):160940691562138. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1177/1609406915621381\u003c/span\u003e\u003cspan address=\"10.1177/1609406915621381\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eBunnik EM, Janssens ACJW, Schermer MHN (2013) A tiered-layered-staged model for informed consent in personal genome testing. Eur J Hum Genet 21(6):596\u0026ndash;601. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1038/ejhg.2012.237\u003c/span\u003e\u003cspan address=\"10.1038/ejhg.2012.237\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eChen C, Storey (2012) Business Intelligence and Analytics: From Big Data to Big Impact. MIS Q 36(4):1165. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.2307/41703503\u003c/span\u003e\u003cspan address=\"10.2307/41703503\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eClarke R (2017) \u003cem\u003eThe Distinction between a PIA and a Data Protection Impact Assessment (DPIA) under the EU GDPR\u003c/em\u003e. Roger Clarke\u0026rsquo;s Web-Site. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttp://www.rogerclarke.com/DV/PIAvsDPIA.html\u003c/span\u003e\u003cspan address=\"http://www.rogerclarke.com/DV/PIAvsDPIA.html\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eDiamond IR, Grant RC, Feldman BM, Pencharz PB, Ling SC, Moore AM, Wales PW (2014) Defining consensus: A systematic review recommends methodologic criteria for reporting of Delphi studies. J Clin Epidemiol 67(4):401\u0026ndash;409. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1016/j.jclinepi.2013.12.002\u003c/span\u003e\u003cspan address=\"10.1016/j.jclinepi.2013.12.002\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEC (2019) \u003cem\u003eEthics Guidelines for Trustworthy AI\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai\u003c/span\u003e\u003cspan address=\"https://digital-strategy.ec.europa.eu/en/library/ethics-guidelines-trustworthy-ai\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eEU (2016) \u003cem\u003eRegulation (EU) 2016/679 of the European parliament and of the council\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://eur-lex.europa.eu/eli/reg/2016/679/oj\u003c/span\u003e\u003cspan address=\"https://eur-lex.europa.eu/eli/reg/2016/679/oj\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eF\u0026ouml;rster B, von der Gracht H (2014) Assessing Delphi panel composition for strategic foresight\u0026mdash;A comparison of panels based on company-internal and external participants. Technol Forecast Soc Chang 84:215\u0026ndash;229. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1016/j.techfore.2013.07.012\u003c/span\u003e\u003cspan address=\"10.1016/j.techfore.2013.07.012\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eFRA (2021) \u003cem\u003eGetting the future right. Artificial intelligence and fundamental rights\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://fra.europa.eu/en/about-fra\u003c/span\u003e\u003cspan address=\"https://fra.europa.eu/en/about-fra\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eFreund J, Jones J (2014) Measuring and managing information risk: A FAIR approach. Butterworth-Heinemann\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eGeorgiadis G, Poels G, Big Data Analytics (2022a) Delphi Study to Identify Criteria for the Systematic Assessment of Data Protection Risks in the Context of. \u003cem\u003e2022 IEEE Eighth International Conference on Big Data Computing Service and Applications (BigDataService)\u003c/em\u003e, 177\u0026ndash;178. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1109/BigDataService55688.2022.00037\u003c/span\u003e\u003cspan address=\"10.1109/BigDataService55688.2022.00037\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eGeorgiadis G, Poels G (2022b) Towards a privacy impact assessment methodology to support the requirements of the general data protection regulation in a big data analytics context: A systematic literature review. Comput Law Secur Rev 44. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1016/j.clsr.2021.105640\u003c/span\u003e\u003cspan address=\"10.1016/j.clsr.2021.105640\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eGeorgiadis G, Poels G (2023a) A Methodology for the Assessment of the Impact of Data Protection Risks in the Context of Big Data Analytics: A Delphi Study. In S. Schiffner, S. Ziegler, \u0026amp; M. Jensen (Eds.), \u003cem\u003ePrivacy Symposium 2023\u003c/em\u003e (pp. 1\u0026ndash;15). Springer International Publishing\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eGeorgiadis G, Poels G, General Data Protection Regulation (2023b) Towards Establishing a Comprehensive Privacy Impact Assessment Methodology for Big Data Analytics in Compliance with the. \u003cem\u003eInternational Conference on Information Systems (2023) Special Interest Group on Big Data Proceedings\u003c/em\u003e. ICIS 2023, Hyderabad, India. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://aisel.aisnet.org/sigbd2023\u003c/span\u003e\u003cspan address=\"https://aisel.aisnet.org/sigbd2023\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHasson F (2000) \u003cem\u003eResearch guidelines for the Delphi survey technique\u003c/em\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHordri N, Samar A, Yuhaniz S, Shamsuddin S (2017) A systematic literature review on features of deep learning in big data analytics. Int J Adv Soft Comput Its Appl, \u003cem\u003e9\u003c/em\u003e(1)\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eHsu CC, Sandford BA (2007) The Delphi technique: Making sense of consensus. Practical Assess Res Evaluation 12(10):1\u0026ndash;8\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eIBM (2023) \u003cem\u003eCost of a Data Breach Report 2023\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://www.ibm.com/reports/data-breach\u003c/span\u003e\u003cspan address=\"https://www.ibm.com/reports/data-breach\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eISACA (2020) \u003cem\u003eISACA\u0026rsquo;s Risk IT Framework Offers a Structured Methodology for Enterprises to Manage Information and Technology Risk\u003c/em\u003e. ISACA. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://www.isaca.org/about-us/newsroom/press-releases/2020/isacas-risk-it-framework-offers-a-structured-methodology\u003c/span\u003e\u003cspan address=\"https://www.isaca.org/about-us/newsroom/press-releases/2020/isacas-risk-it-framework-offers-a-structured-methodology\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eIvanova Y (2020) The Data Protection Impact Assessment as a Tool to Enforce Non-discriminatory AI. In: Antunes L, Naldi M, Italiano GF, Rannenberg K, Drogkaris P (eds) 8th Annual Privacy Forum, APF 2020. Springer International Publishing, pp 3\u0026ndash;24\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eJain P, Gyanchandani M, Khare N (2016) Big data privacy: A technological perspective and review. J Big Data 3(1):25. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1186/s40537-016-0059-y\u003c/span\u003e\u003cspan address=\"10.1186/s40537-016-0059-y\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKeeney S, Hasson F, Mckenna H (2011) The Delphi Technique in Nursing and Health Research. Wiley-Blackwell\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eKloza D, van Dijk N, Casiraghi S, Vazquez Maymir S, Roda S, Tanas A, Konstantinou I (2018) Data protection impact assessments in the European Union: Designing an appraisal method towards a more robust protection of individuals. \u003cem\u003eD.Pia.Lab Policy Brief, VUB\u003c/em\u003e, \u003cem\u003e2\u003c/em\u003e, 4\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eLinstone HA, Turoff M (2002) The Delphi Method: Techniques and Applications. Addison-Wesley Educational Publishers Inc\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eMullen PM (2003) Delphi: Myths and reality. J Health Organ Manag 17(1):37\u0026ndash;52. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1108/14777260310469319\u003c/span\u003e\u003cspan address=\"10.1108/14777260310469319\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eOkoli C, Pawlowski SD (2004) The Delphi method as a research tool: An example, design considerations and applications. Inform Manage 42(1):15\u0026ndash;29. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1016/j.im.2003.11.002\u003c/span\u003e\u003cspan address=\"10.1016/j.im.2003.11.002\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003ePardau S (2018) The California Consumer Privacy Act: Towards a European-style privacy regime in the United States? J Technol Law Policy 23(1):68\u0026ndash;114\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003ePetter S, Straub D, Rai A (2007) Specifying formative constructs in information systems research. MIS Q 623\u0026ndash;656. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.2307/25148814\u003c/span\u003e\u003cspan address=\"10.2307/25148814\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eSkulmoski GJ, Hartman FT, Krahn J (2007) The Delphi method for graduate research. J Inform Technol Education: Res 6(1):1\u0026ndash;21\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eTene O, Polonetsky J (2012) Big Data for All: Privacy and User Control in the Age of Analytics. Northwest J Technol Intellect Property 11:xxvii\u0026ndash;274\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eTrevelyan EG, Robinson N (2015) Delphi methodology in health research: How to do it? Eur J Integr Med 7(4):423\u0026ndash;428. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1016/j.eujim.2015.07.002\u003c/span\u003e\u003cspan address=\"10.1016/j.eujim.2015.07.002\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eVan Looy A, Poels G, Snoeck M (2017) Evaluating business process maturity models. J Association Inform Syst 18(6):461\u0026ndash;486\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eVenkatesh V, Brown SA, Bala H (2013) Bridging the Qualitative-Quantitative Divide: Guidelines for Conducting Mixed Methods Research in Information Systems. MIS Q 37(1):21\u0026ndash;54. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.25300/MISQ/2013/37.1.02\u003c/span\u003e\u003cspan address=\"10.25300/MISQ/2013/37.1.02\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eWP29 (2013) \u003cem\u003eOpinion 03/2013 on purpose limitation\u003c/em\u003e. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2013/wp203_en.pdf\u003c/span\u003e\u003cspan address=\"https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2013/wp203_en.pdf\" targettype=\"URL\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eWright D (2013) Making Privacy Impact Assessment More Effective. Inform Soc 29(5):307\u0026ndash;315. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1080/01972243.2013.825687\u003c/span\u003e\u003cspan address=\"10.1080/01972243.2013.825687\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e \u003cli\u003e\u003cspan\u003eZeng J, Glaister KW (2018) Value creation from big data: Looking inside the black box. Strategic Organ 16(2):105\u0026ndash;140. \u003cspan class=\"ExternalRef\"\u003e\u003cspan class=\"RefSource\"\u003ehttps://doi.org/10.1177/1476127017697510\u003c/span\u003e\u003cspan address=\"10.1177/1476127017697510\" targettype=\"DOI\" class=\"RefTarget\"\u003e\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003c/li\u003e\u003c/ol\u003e"}],"fulltextSource":"","fullText":"","funders":[],"hasAdminPriorityOnWorkflow":false,"hasManuscriptDocX":true,"hasOptedInToPreprint":true,"hasPassedJournalQc":"","hasAnyPriority":true,"hideJournal":true,"highlight":"","institution":"Ghent University","isAcceptedByJournal":false,"isAuthorSuppliedPdf":false,"isDeskRejected":"","isHiddenFromSearch":false,"isInQc":false,"isInWorkflow":false,"isPdf":false,"isPdfUpToDate":true,"isWithdrawnOrRetracted":false,"journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true},"keywords":"Big data, data protection, Delphi study, directive, General Data Protection Regulation, governance, information security, privacy, privacy impact assessment","lastPublishedDoi":"10.21203/rs.3.rs-5821174/v1","lastPublishedDoiUrl":"https://doi.org/10.21203/rs.3.rs-5821174/v1","license":{"name":"CC BY 4.0","url":"https://creativecommons.org/licenses/by/4.0/"},"manuscriptAbstract":"\u003cp\u003eIn today\u0026rsquo;s digital landscape, as big data analytics (BDA) gain increasing significance, it is vital to have robust strategies for safeguarding privacy and data protection. This paper focuses on improving data protection impact assessments (DPIAs) in the context of BDA, aligning them with the principles of the General Data Protection Regulation (GDPR). Through a study that combines a Delphi approach with individual expert interviews, we have validated nine critical privacy touch points (PTPs) for adapting DPIA methodology to BDA environments. These PTPs, identified in our previous research, address key privacy and data protection issues in BDA, including consent nuances, definitions of data control, and challenges such as re-identification and discrimination. The result is a framework tailored to the unique landscape of BDA technologies.\u003c/p\u003e \u003cp\u003eThis research stands out by thoroughly analysing and validating these nine PTPs and offering actionable recommendations to enhance the existing DPIA framework. With the anticipated growth of artificial intelligence and large language models, BDA will continue to attract attention. Our research therefore contributes both academically and practically by supporting the evolution of thorough DPIA practices while providing guidance for policymakers, businesses, and privacy advocates.\u003c/p\u003e","manuscriptTitle":"Establishing a Comprehensive Data Protection Impact Assessment Methodology for Big Data Analytics in Compliance with the General Data Protection Regulation","msid":"","msnumber":"","nonDraftVersions":[{"code":1,"date":"2025-01-15 08:06:07","doi":"10.21203/rs.3.rs-5821174/v1","editorialEvents":[{"type":"communityComments","content":0}],"status":"published","journal":{"display":true,"email":"
[email protected]","identity":"researchsquare","isNatureJournal":false,"hasQc":true,"allowDirectSubmit":true,"externalIdentity":"","sideBox":"","snPcode":"","submissionUrl":"/submission","title":"Research Square","twitterHandle":"researchsquare","acdcEnabled":true,"dfaEnabled":false,"editorialSystem":"","reportingPortfolio":"","inReviewEnabled":false,"inReviewRevisionsEnabled":true}}],"origin":"","ownerIdentity":"cfb38323-8796-49f3-842b-587acac83797","owner":[],"postedDate":"January 15th, 2025","published":true,"recentEditorialEvents":[],"rejectedJournal":[],"revision":"","amendment":"","status":"posted","subjectAreas":[{"id":42800505,"name":"Artificial Intelligence and Machine Learning"},{"id":42800506,"name":"Management"}],"tags":[],"updatedAt":"2025-05-21T13:23:26+00:00","versionOfRecord":[],"versionCreatedAt":"2025-01-15 08:06:07","video":"","vorDoi":"","vorDoiUrl":"","workflowStages":[]},"version":"v1","identity":"rs-5821174","journalConfig":"researchsquare"},"__N_SSP":true},"page":"/article/[identity]/[[...version]]","query":{"redirect":"/article/rs-5821174","identity":"rs-5821174","version":["v1"]},"buildId":"8U1c8b4HqxoKbykW_rLl7","isFallback":false,"isExperimentalCompile":false,"dynamicIds":[84888],"gssp":true,"scriptLoader":[]}
Text is read by the "Ask this paper" AI Q&A widget below.
Extraction quality varies by source — PMC NXML preserves structure
cleanly, OA-HTML may include some navigation residue, and OA-PDF can
have broken hyphenation. The publisher copy
(via DOI)
is the canonical version.