Skip to main content
Category: Impact Assessments & Documentation

Innovative Use of Technology

Also known as: Technology Innovation, Innovative Technology
Simply put

Innovative use of technology generally refers to applying new or improved tools, systems, or processes in creative or purposeful ways to achieve better outcomes. The evidence available here treats the phrase as a broad, general-purpose concept rather than a defined legal term, with meanings that vary across educational, commercial, and technical contexts. Readers should note this term is not defined in the evidence provided as a data privacy or GDPR term of art.

Formal definition

Based on the available evidence, 'innovative use of technology' is used descriptively across multiple domains to mean the creation and application of new or improved technologies, tools, systems, and processes (see technology innovation), and in some legal-drafting usage denotes a process that has been tested but lacks an established history of full-scale use. The evidence does not supply a GDPR-specific or data protection definition; consequently, no privacy-law scope, legal basis, or article reference can be asserted here. Where this phrase appears in a data protection context (for example, in relation to whether processing involves 'innovative use or applying new technological or organisational solutions' as a factor relevant to assessing high risk), practitioners should verify the precise wording and effect against the current official regulatory text and guidance, as the evidence packet does not establish that boundary.

Why it matters

In data protection practice, the phrase "innovative use of technology" matters primarily because it can function as a risk signal rather than a self-contained legal term. Under the GDPR framework, whether processing involves the innovative use or application of new technological or organisational solutions is generally treated as one factor relevant to assessing whether processing is likely to result in a high risk to individuals, which in turn may trigger the requirement to carry out a Data Protection Impact Assessment. The evidence available here does not establish the precise wording or effect of that factor, so practitioners should verify it against the current official regulatory text and supervisory authority guidance before relying on it.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads generally need to recognise when a project's use of new or unproven technology may weigh toward a high-risk assessment and, subject to that assessment, a DPIA. Because this term is not defined in the evidence as a privacy term of art, they should map any internal use of the phrase to the precise wording in the current official GDPR text and their supervisory authority's guidance rather than to a generic dictionary meaning.
Compliance and Risk Teams
Compliance teams typically treat novelty and the absence of an established full-scale track record as triggers for closer scrutiny. In most cases this means building assessment steps into project intake so that innovative processing is flagged early, while avoiding the assumption that novelty alone is either automatically permitted or automatically high risk, the outcome depends on a context-specific assessment.
Engineers and Product Teams
Engineers and product teams applying new tools, systems, or processes should surface the novel or unproven aspects of a design to privacy and compliance colleagues early, since the innovative character of a technology can affect whether a formal risk assessment is required. The concept here is descriptive rather than a settled legal test, so technical teams should not self-certify compliance without input from the relevant governance function.
Lawyers and Legal Advisors
Legal advisors should note that "innovative use of technology" is used across domains and, in some legal drafting, carries a domain-specific meaning (for example, a tested process lacking an established history of full-scale use). Where the phrase appears in a data protection context, the precise wording, scope, and any article reference should be verified against the current official Regulation text and guidance, as the evidence provided does not establish that boundary.

Inside Innovative Use of Technology

Data Protection by Design and by Default
The obligation, generally associated with Article 25 GDPR, to embed data protection principles into the design of technological solutions from the outset and to ensure that, by default, only personal data necessary for each specific purpose is processed. This is central to deploying innovative technologies lawfully.
Data Protection Impact Assessment (DPIA)
A structured assessment, typically required under Article 35 GDPR where processing is likely to result in a high risk to individuals, which is often relevant when introducing novel or large-scale technologies. A DPIA is distinct from an Article 28 Data Processing Agreement and should be completed before high-risk processing begins.
Lawful Basis Selection
Identifying the appropriate Article 6 legal basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for the processing enabled by the technology. Consent is not a universal requirement, and special category data under Article 9 needs an additional condition.
Privacy-Enhancing Technologies (PETs)
Techniques such as pseudonymisation, encryption, and, where effective, anonymisation that can reduce risk. Genuinely anonymous data generally falls outside the scope of the GDPR, though whether a technique achieves anonymisation is subject to assessment and the threshold is contested among regulators.
Transparency and Individual Rights
Mechanisms to inform individuals about how innovative processing works and to give effect to their rights, which can be more challenging where technologies are complex, opaque, or automated. This includes considerations around automated decision-making and profiling.
International Data Transfer Considerations
Where a technology involves transfers outside the EEA, appropriate transfer tools (such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules) and, where needed, supplementary measures may be required. These mechanisms evolve and should be verified against current guidance.

Common questions

Answers to the questions practitioners most commonly ask about Innovative Use of Technology.

Does using innovative or new technology automatically require a Data Protection Impact Assessment?
Not automatically. Innovative use of technology is one of several factors that can indicate a processing operation is likely to result in a high risk to individuals' rights and freedoms, which is the threshold that triggers a Data Protection Impact Assessment. However, the presence of new technology alone does not compel a DPIA in every case; it must be assessed alongside other criteria and the overall risk profile. Supervisory authority guidance (notably from the European Data Protection Board, and equivalent guidance under the UK GDPR) typically treats innovative technology as one indicator among many, and some authorities publish lists of operations that mandate a DPIA. You should assess the specific processing against the applicable criteria rather than assume the requirement is triggered.
Is 'innovative use of technology' a term that carries its own separate legal definition in the GDPR?
It is not a standalone defined term in the operative articles in the way that, for example, 'personal data' or 'processing' are defined. The concept appears as one of the risk indicators associated with the obligation to carry out a Data Protection Impact Assessment and features in supervisory authority and European Data Protection Board guidance elaborating when high risk may arise. Because its meaning is shaped largely by guidance rather than a precise statutory definition, its scope can evolve and may be interpreted somewhat differently across regulators. Treat it as an assessment factor informed by guidance rather than a fixed legal category, and verify the current wording against the applicable official text and regulator guidance.
How should we decide whether a given technology counts as 'innovative' for risk-assessment purposes?
There is no exhaustive checklist, so the assessment is generally contextual. Consider whether the technology is novel in the way it processes personal data, whether its effects on individuals are well understood, and whether it introduces risks that established approaches would not. Consult the applicable supervisory authority's guidance and any published lists of high-risk operations, and document your reasoning. Because guidance evolves and regulators may diverge, record the basis for your determination and revisit it if the technology or its use changes.
At what stage of a project should we consider whether innovative technology raises data protection concerns?
Generally as early as possible, consistent with a data protection by design and by default approach. Assessing the technology before deployment allows you to determine whether a Data Protection Impact Assessment is required and to build in mitigations while design choices remain open. Leaving the assessment until after implementation typically reduces the options for reducing risk and may complicate demonstrating accountability.
If we conclude that innovative technology is being used, what documentation should we keep?
In most cases you should record the outcome of your screening assessment, including why the technology was or was not considered to raise high risk and whether a Data Protection Impact Assessment was carried out. Where a DPIA is conducted, retain the assessment itself, the identified risks, the mitigating measures, and any consultation with your data protection officer. Maintaining this documentation supports the accountability principle and helps evidence your decision-making to a supervisory authority. The precise expectations can vary, so check the applicable regulator's guidance.
Does the involvement of innovative technology change who is responsible for the assessment?
Not in itself. Responsibility for determining whether a Data Protection Impact Assessment is needed generally rests with the controller, which decides the purposes and means of the processing, regardless of whether the technology is novel. Where a processor supplies or operates the technology, the controller typically remains accountable for the assessment, though the processor is generally expected to assist as set out in their arrangements. Clarifying roles at the outset helps avoid conflating controller and processor responsibilities when new technology is provided by a third party.

Common misconceptions

Adopting an innovative technology always requires the individual's consent.
Consent is only one of six Article 6 lawful bases. Depending on context, contract, legitimate interests, public task, or another basis may be more appropriate. Special category data under Article 9 requires an additional condition on top of the Article 6 basis.
If data is put through a de-identification process, the GDPR no longer applies.
The GDPR generally ceases to apply only to genuinely anonymous data. Pseudonymised data typically remains personal data and stays in scope. Whether a technique achieves true anonymisation is subject to assessment and regulators can diverge on the threshold.
A DPIA and a Data Processing Agreement serve the same purpose when rolling out new technology.
These are distinct instruments. A DPIA (typically Article 35) assesses and mitigates risk to individuals before high-risk processing, while a Data Processing Agreement (Article 28) governs the controller-processor relationship contractually. Both may be needed but they are not interchangeable.

Best practices

Conduct a DPIA early in the design phase where the technology is likely to result in high risk, and revisit it as the solution evolves.
Document the chosen Article 6 lawful basis (and any Article 9 condition for special category data) before deployment rather than defaulting to consent.
Apply data protection by design and by default, incorporating privacy-enhancing techniques such as pseudonymisation or encryption where appropriate and proportionate.
Assess whether any de-identification genuinely achieves anonymisation before treating data as out of scope, noting that regulator positions can vary.
Map any international data flows and confirm an appropriate transfer tool and, where necessary, supplementary measures, verifying against the current official guidance.
Provide clear transparency information and workable mechanisms for individuals to exercise their rights, giving particular attention to automated or opaque processing.