Data Protection Impact Assessment
Also called: DPIA. In some organizations, a privacy impact assessment or PIA.
Where it comes from: General Data Protection Regulation, Article 35. The UK equivalent applies under UK GDPR.
Mandatory since: May 2018, in both the EU and the UK.
Timing: completed before the processing begins.
When It Is Required
Required where processing is likely to result in a high risk to people.
Common triggers:
- Systematic and extensive evaluation of people, including profiling
- Large-scale processing of sensitive categories
- Systematic monitoring of a publicly accessible area
- Automated decisions with legal or similarly significant effects
- Large-scale processing generally
- Combining or matching data from several sources
- Data about vulnerable people, including employees
- Use of new or innovative technology
Rule of thumb: the more of these a deployment hits, the less room there is for judgment about whether one is needed.
If in doubt, do it. A completed assessment that turns out not to have been required costs you time. A missing one that was required is a finding.
What It Has to Cover
Four core elements, plus two consultation requirements.
1. A description of the processing
- What the tool does
- What data it processes
- Why you are doing it
- Who is involved — controller, processor, sub-processors
- How long data is kept
- Where data goes, including transfers
2. Necessity and proportionality
- Why this processing is necessary for the purpose
- Whether a less intrusive option would achieve it
- The lawful basis you are relying on
- The additional condition, if sensitive categories are involved
- How people exercise their rights
3. The risks to people
- What could go wrong for the individuals affected
- How likely it is
- How serious it would be
- Which groups are most exposed
4. The measures addressing those risks
- What safeguards are in place
- What you are changing as a result
- Residual risk after mitigation
- Who owns each measure
Plus: consultation
- Your data protection officer's advice, where one is appointed
- The views of the people affected, where appropriate
That second one is frequently skipped. Where it is not practical, record why.
Where the Information Probably Lives
| What you need | Where to look |
|---|---|
| What the tool does | Business lead; the approval request |
| Data categories | Business lead; IT |
| Purpose of processing | Business lead; the business justification |
| Systems it connects to | IT; the integration record |
| Sub-processors | Vendor trust page; the processing agreement |
| Retention periods — vendor | Vendor documentation; the contract |
| Retention periods — yours | Records management; the retention schedule |
| Transfers outside the EU or UK | The processing agreement; IT hosting records |
| Transfer safeguards | The processing agreement; legal |
| Lawful basis | Privacy team; prior assessments for similar processing |
| Condition for sensitive data | Privacy team; legal |
| How rights requests are handled | Privacy team; the rights request process |
| Existing security measures | Information security; the security review |
| Human review arrangements | Business lead; the process documentation |
| Named owner | The governance record; business lead |
| DPO advice | Your DPO — ask directly, and record the response |
| Views of affected people | Employee representatives, customer research, or a recorded reason why not |
Who Supplies What
You or the privacy function:
- The regulatory framing and structure
- Lawful basis and conditions
- Risk analysis
- Assembling the record
The business:
- What the tool does and why
- Who is affected
- What happens to the output
IT and security:
- Architecture, hosting, connections
- Security measures in place
Legal or counsel:
- Contested applicability questions
- Whether the assessment is sufficient
- Sign-off
Common Gaps
Watch for these — they are the ones that show up repeatedly.
- No date, or a date after processing started. The timing is part of the requirement.
- Necessity treated as a formality. "We need it because we decided to use it" is not an assessment of necessity.
- Risks described generically. "Data breach" is not a risk analysis. What happens to these people if this system fails?
- Measures listed as planned, never confirmed. A mitigation with no owner and no date is not a control.
- DPO consulted but the advice not recorded. The consultation is required. So is the record of it.
- No residual risk stated. After mitigation, what is left? Someone has to accept it, by name.
- Never revisited. An assessment from three years ago for a tool that has changed twice is a snapshot.
One Practical Note
A DPIA is not a form to be completed. It is a record that you examined the processing and reached conclusions.
An assessment that reaches no conclusions, identifies no risks, and prompts no changes has not been done — regardless of how many boxes are filled.
Statutory content requirements should be verified against the current text of the regulation before relying on this handout for a live assessment.
Sources
- General Data Protection Regulation, Regulation (EU) 2016/679 — Article 35, and Articles 35(2) and 35(9) for the consultation requirements
- UK General Data Protection Regulation and the Data Protection Act 2018
- Guidance on identifying high-risk processing is issued by the European Data Protection Board and, in the UK, by the Information Commissioner's Office
The content requirements summarized here are drawn from Article 35(7). Read the current text of the Article before relying on this handout for a live assessment. National supervisory authorities also publish lists of processing operations that do and do not require an assessment in their jurisdiction — check the list for each country in scope.
Use and reuse
Free to use, share, and adapt within your organization. Attribution appreciated, not required. No warranty of any kind — this is practitioner guidance, not legal advice, and sufficiency is determined by your counsel.
LegisGate · Regulatory Intelligence for AI Deployments · legisgate.com
Written by compliance and audit practitioners who spent decades on the other side of the table.
Version 1.0 · Current as of August 2026 · Verify time-sensitive claims against current sources before relying on them.