UK Data Protection Impact Assessments: When and How to Run a DPIA
22 Aug, 2026Imagine you’re rolling out a new employee monitoring tool or launching a loyalty program that tracks customer behavior across devices. You’ve got the tech ready, but have you checked if it needs a formal risk check under UK law? If the answer is “maybe,” you need a Data Protection Impact Assessment, or DPIA. It’s not just bureaucratic red tape; it’s your first line of defense against fines from the Information Commissioner's Office (ICO) and reputational damage.
A DPIA is a structured process to identify and mitigate risks to individuals' privacy before you start processing personal data on a large scale. Under the UK General Data Protection Regulation (UK GDPR), it’s mandatory when processing is likely to result in a high risk to people’s rights and freedoms. Skip it, and you could face fines up to £20 million or 4% of global annual turnover, whichever is higher.
Key Takeaways
- When to run a DPIA: Mandatory for high-risk processing like systematic profiling, large-scale special category data, or new technologies with no precedent.
- The 4-step process: Describe the processing, assess necessity/proportionality, evaluate risks, and document mitigation measures.
- Who owns it: The Data Controller (you) is responsible, but the Data Protection Officer (DPO) should be consulted.
- Timeframe: No legal deadline, but best practice is to complete it before processing begins.
- Documentation: Keep records for at least 3 years; the ICO can request them during an investigation.
When Is a DPIA Actually Required?
Not every data project needs a full-blown impact assessment. The ICO provides a checklist to help you decide. If any of these apply, you’re in mandatory territory:
- Systematic and extensive profiling with legal or similarly significant effects (e.g., automated hiring decisions).
- Large-scale processing of special category data (health, biometrics, religious beliefs) or criminal offense data.
- Novel technology used in ways not previously seen (e.g., AI-driven facial recognition in retail).
- Combining datasets in unexpected ways that change the context of the data.
- Monitoring vulnerable subjects (children, elderly) on a public accessible area.
If none of these hit home, you might still choose to do a lightweight version as good governance. But legally, you’re only required to document the decision *not* to do one if you later get challenged by the ICO.
The Four-Step DPIA Process
Running a DPIA isn’t about filling out a single form. It’s a living document that evolves with your project. Here’s how to structure it:
1. Description of the Processing
Start with the basics. What are you doing? Who is involved? Be specific. Don’t just say “employee data.” Say “biometric attendance data for 500 staff using fingerprint scanners.” Include:
- Purpose of processing
- Data types collected
- Categories of data subjects
- Recipients of data (including third-party processors)
- Retention periods
2. Necessity and Proportionality
Ask yourself: Do we really need this? Could we achieve the same goal with less invasive methods? For example, if you want to secure office access, do you need facial recognition, or would RFID cards suffice? This step often reveals that the original plan was overkill.
3. Risk Assessment
This is the core. Identify where things could go wrong. Use a risk matrix that considers both likelihood and impact. Common risks include:
- Breach of confidentiality (data leak)
- Lack of transparency (people don’t know their data is being used)
- Inaccurate data leading to unfair decisions
- Function creep (using data for purposes beyond the original intent)
4. Mitigation Measures and Sign-off
For each high-risk item, define what you’ll do to fix it. Examples include encrypting data at rest, implementing pseudonymization, or adding human oversight to automated decisions. Get sign-off from key stakeholders: the DPO, IT security lead, and business owner.
DPIA vs. Privacy Notice: Don’t Confuse Them
Many businesses think a privacy notice covers all bases. It doesn’t. A privacy notice tells people *what* you’re doing with their data. A DPIA analyzes *how risky* that processing is and *how you’ll manage it*. Think of the privacy notice as the menu, and the DPIA as the kitchen inspection report. Both are essential, but they serve different functions.
| Feature | DPIA | Privacy Notice | ROPA |
|---|---|---|---|
| Purpose | Risk management | Transparency to data subjects | Accountability record |
| Timing | Before processing starts | At or before collection | Ongoing maintenance |
| Legal Trigger | High-risk processing | All personal data processing | All organizations with >250 employees (or always if high-risk) |
| Content Focus | Risks and mitigations | Purposes, rights, contacts | Catalog of all processing activities |
Common Pitfalls That Trip Up Businesses
Even experienced teams make mistakes here. Here are the top three I see:
- Treating it as a one-time event: If your system changes significantly (new vendor, new feature), update the DPIA. An outdated DPIA is worse than no DPIA because it shows negligence.
- Ignoring processor input: Your cloud provider knows where data lives better than you do. Involve them early. Article 28 of UK GDPR requires contracts with processors, but practical collaboration is key for accurate risk assessment.
- Vague language: Saying “we will protect data” means nothing. Specify: “Data will be encrypted using AES-256 and stored in UK-based servers.” Specificity is your friend in an ICO inquiry.
How Long Should a DPIA Take?
There’s no statutory deadline, but waiting until launch day is a recipe for disaster. For small projects, a focused DPIA can take 2-3 days. For complex, multi-stakeholder initiatives, budget 2-4 weeks. The goal is completion *before* processing begins. If you discover a show-stopper risk late in the game, you’ve saved yourself from a costly rollback or fine.
Frequently Asked Questions
Do I need a DPIA for every new app?
No. Only if the processing is high-risk. A simple contact list CRM usually doesn’t require one. However, if you add features like automated scoring or health tracking, re-evaluate. When in doubt, consult your DPO or the ICO’s guidance checklist.
What happens if the ICO finds a missing DPIA?
It depends on context. If the risk was low, they may issue a warning. If the risk was high and unmitigated, expect an enforcement notice and potential fines. They also consider whether you acted in good faith. Having a documented decision *not* to do a DPIA helps prove good faith.
Can I use a template for my DPIA?
Yes, and you should. The ICO offers a standard template that aligns with their expectations. Using it ensures you cover all necessary bases. Just avoid copy-pasting without customizing the risk sections to your specific context.
Does a DPIA replace a security audit?
No. A security audit looks at technical controls (firewalls, encryption). A DPIA looks at broader privacy risks, including fairness, transparency, and purpose limitation. They complement each other. Many companies run them in parallel for major launches.
How long must I keep the DPIA document?
Keep it for the duration of the processing activity plus at least 3 years after cessation. This aligns with the general accountability principle. If the project ends, archive it securely. You may need to produce it if the ICO investigates a complaint related to that period.