The guide, in plain English
DPIA: What It Is, When You Need One, and How We Help
A Data Protection Impact Assessment, or DPIA, is a documented way of finding and reducing the data protection risks of a project before it goes live. This guide explains what a DPIA is, when the UK GDPR makes one mandatory, and how to run one. There is a free template to work through yourself, and a fixed-fee service for when you would rather we ran it.
The definition
What a DPIA actually is
A DPIA is not a form for its own sake. It is a structured way of thinking through a piece of processing before you commit to it: what personal data it involves, whether you genuinely need all of it, what could go wrong for the people whose data it is, and what you will do to keep that risk low.
Done properly, it is the single clearest piece of evidence that your organisation took privacy seriously before it acted, which is exactly what the UK GDPR's accountability principle asks of you.
A DPIA sets out
- A description of the processing: what data, whose data, and why
- An assessment of whether the processing is necessary and proportionate
- The risks the processing poses to the people whose data it is
- The measures you will put in place to reduce those risks
- A record of the decision, so you can evidence it later
Article 35
When do you need a DPIA?
There are three ways a project lands in DPIA territory: the law requires it, the ICO's list catches it, or it is simply the sensible thing to do. Most new systems and suppliers touch at least one.
When the law requires it
Article 35 of the UK GDPR makes a DPIA mandatory where processing is likely to result in a high risk to people's rights and freedoms. It names three cases in particular: large-scale automated profiling with legal or similarly significant effects, large-scale processing of special category or criminal offence data, and systematic monitoring of a public place on a large scale.
When the ICO's list catches it
The ICO sets out ten types of processing that are likely to require a DPIA, including the use of innovative technology, tracking people's location or behaviour, matching or combining datasets, processing biometric or genetic data, and processing that concerns children or other vulnerable people. If your project touches any of them, a DPIA is the safe assumption.
When it is simply good practice
Even where none of the triggers strictly apply, a DPIA is the cleanest way to show you have thought about privacy before launching a new system, product or supplier. It is the practical form the UK GDPR's accountability principle takes: evidence that you considered the risk before the processing began, not after a complaint.
Two ways forward
Run it yourself, or have us run it
For a straightforward project, a good template is all you need. For anything high risk or contested, an impartial specialist gives you a DPIA that stands up to scrutiny.
Do it yourself
Free DPIA template
Free
plain-English, ready to work through
A DPIA template covering the screening questions, the risk assessment and the sign-off record, written so a non-specialist can follow it. Available from our resources page or on request.
Get the templateFor high-risk processing
Have us run it
We run your DPIA
From £1,450
indicative fixed fee, banded by size
A data protection consultant runs the assessment end to end: screening, the risk analysis, the measures to reduce risk and a defensible written record. Impartial, evidenced and ready to show a regulator, an insurer or a customer.
Talk to a consultantQuick answers
DPIA questions, answered
What does DPIA stand for?
Data Protection Impact Assessment. It is a documented process for identifying and reducing the data protection risks of a project before it goes ahead. The name comes straight from Article 35 of the UK GDPR, which is where the legal requirement to carry one out sits.
When is a DPIA legally required?
Whenever processing is likely to result in a high risk to individuals. Article 35 sets out three clear cases: large-scale automated profiling with significant effects, large-scale processing of special category or criminal data, and large-scale systematic monitoring of a public area. On top of that, the ICO publishes a list of ten further types of processing that are likely to require one. If you are unsure, the cautious and usually correct answer is to do a short screening assessment and record the outcome.
Who should carry out the DPIA?
It is the responsibility of the organisation acting as data controller. In practice a project or compliance lead runs it, drawing on the people who understand the processing. Where your organisation has a data protection officer, Article 35 requires you to seek their advice. Where you do not, or where the processing is complex, bringing in an external specialist to run the assessment gives you an impartial, defensible record.
What happens if the DPIA finds a high risk you cannot reduce?
If, after taking every reasonable measure, a residual high risk remains, Article 36 requires you to consult the ICO before you start the processing. In most projects it does not come to that: the value of a DPIA is that it surfaces the risk early enough to design it out, so the processing proceeds with the controls already in place.
Do you have a DPIA template we can use?
Yes. We publish a plain-English DPIA template you can work through yourself, covering the screening questions, the risk assessment and the sign-off record. It is available from our resources page or on request. Where the processing is high risk or contested, we can also run the DPIA for you as a fixed-fee piece of work.
Now you know what it is
Need a DPIA done properly?
A free 45 minute call with a data protection consultant confirms whether your project needs a DPIA, what running one involves and the fixed fee if you would like us to run it for you.