Handout · DPIAThe Handbook
§Handout

Data Protection Impact Assessment

Also called: DPIA. In some organizations, a privacy impact assessment or PIA.

Where it comes from: General Data Protection Regulation, Article 35. The UK equivalent applies under UK GDPR.

Mandatory since: May 2018, in both the EU and the UK.

Timing: completed before the processing begins.


When It Is Required

Required where processing is likely to result in a high risk to people.

Common triggers:

  • Systematic and extensive evaluation of people, including profiling
  • Large-scale processing of sensitive categories
  • Systematic monitoring of a publicly accessible area
  • Automated decisions with legal or similarly significant effects
  • Large-scale processing generally
  • Combining or matching data from several sources
  • Data about vulnerable people, including employees
  • Use of new or innovative technology

Rule of thumb: the more of these a deployment hits, the less room there is for judgment about whether one is needed.

If in doubt, do it. A completed assessment that turns out not to have been required costs you time. A missing one that was required is a finding.


What It Has to Cover

Four core elements, plus two consultation requirements.

1. A description of the processing

  • What the tool does
  • What data it processes
  • Why you are doing it
  • Who is involved — controller, processor, sub-processors
  • How long data is kept
  • Where data goes, including transfers

2. Necessity and proportionality

  • Why this processing is necessary for the purpose
  • Whether a less intrusive option would achieve it
  • The lawful basis you are relying on
  • The additional condition, if sensitive categories are involved
  • How people exercise their rights

3. The risks to people

  • What could go wrong for the individuals affected
  • How likely it is
  • How serious it would be
  • Which groups are most exposed

4. The measures addressing those risks

  • What safeguards are in place
  • What you are changing as a result
  • Residual risk after mitigation
  • Who owns each measure

Plus: consultation

  • Your data protection officer's advice, where one is appointed
  • The views of the people affected, where appropriate

That second one is frequently skipped. Where it is not practical, record why.


Where the Information Probably Lives

What you needWhere to look
What the tool doesBusiness lead; the approval request
Data categoriesBusiness lead; IT
Purpose of processingBusiness lead; the business justification
Systems it connects toIT; the integration record
Sub-processorsVendor trust page; the processing agreement
Retention periods — vendorVendor documentation; the contract
Retention periods — yoursRecords management; the retention schedule
Transfers outside the EU or UKThe processing agreement; IT hosting records
Transfer safeguardsThe processing agreement; legal
Lawful basisPrivacy team; prior assessments for similar processing
Condition for sensitive dataPrivacy team; legal
How rights requests are handledPrivacy team; the rights request process
Existing security measuresInformation security; the security review
Human review arrangementsBusiness lead; the process documentation
Named ownerThe governance record; business lead
DPO adviceYour DPO — ask directly, and record the response
Views of affected peopleEmployee representatives, customer research, or a recorded reason why not

Who Supplies What

You or the privacy function:

  • The regulatory framing and structure
  • Lawful basis and conditions
  • Risk analysis
  • Assembling the record

The business:

  • What the tool does and why
  • Who is affected
  • What happens to the output

IT and security:

  • Architecture, hosting, connections
  • Security measures in place

Legal or counsel:

  • Contested applicability questions
  • Whether the assessment is sufficient
  • Sign-off

Common Gaps

Watch for these — they are the ones that show up repeatedly.

  • No date, or a date after processing started. The timing is part of the requirement.
  • Necessity treated as a formality. "We need it because we decided to use it" is not an assessment of necessity.
  • Risks described generically. "Data breach" is not a risk analysis. What happens to these people if this system fails?
  • Measures listed as planned, never confirmed. A mitigation with no owner and no date is not a control.
  • DPO consulted but the advice not recorded. The consultation is required. So is the record of it.
  • No residual risk stated. After mitigation, what is left? Someone has to accept it, by name.
  • Never revisited. An assessment from three years ago for a tool that has changed twice is a snapshot.

One Practical Note

A DPIA is not a form to be completed. It is a record that you examined the processing and reached conclusions.

An assessment that reaches no conclusions, identifies no risks, and prompts no changes has not been done — regardless of how many boxes are filled.


Statutory content requirements should be verified against the current text of the regulation before relying on this handout for a live assessment.

Sources

  • General Data Protection Regulation, Regulation (EU) 2016/679 — Article 35, and Articles 35(2) and 35(9) for the consultation requirements
  • UK General Data Protection Regulation and the Data Protection Act 2018
  • Guidance on identifying high-risk processing is issued by the European Data Protection Board and, in the UK, by the Information Commissioner's Office

The content requirements summarized here are drawn from Article 35(7). Read the current text of the Article before relying on this handout for a live assessment. National supervisory authorities also publish lists of processing operations that do and do not require an assessment in their jurisdiction — check the list for each country in scope.


Use and reuse

Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.

LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com

Written by compliance and audit practitioners who spent decades on the other side of the table.

Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.

Contents
Talk to usWe're here to help
Data Protection Impact Assessment (DPIA) Guide | LegisGate