What is a DPIA? A guide to Data Protection Impact Assessments

A Data Protection Impact Assessment is a structured review of a processing activity that identifies privacy risks to individuals and decides how to mitigate them. GDPR requires one for high-risk processing – including most uses of AI on personal data.
Quick answer

A Data Protection Impact Assessment (DPIA) is a structured review of a processing activity to identify privacy risks to individuals and decide how to mitigate them. GDPR Article 35 requires a DPIA whenever processing is likely to result in a high risk to rights and freedoms – typically including large-scale processing of special-category data, systematic monitoring of public areas, and most new AI use cases involving personal data.

Definition and legal basis

A DPIA is a documented assessment of how a processing activity could affect the rights and freedoms of natural persons, with mitigations recorded against each identified risk. Under Article 35 of the EU and UK GDPR, a DPIA is mandatory wherever processing is ‘likely to result in a high risk’. Similar requirements exist under POPIA (South Africa), DPDPA (India), LGPD (Brazil) and most modern privacy regimes – usually under different names (Privacy Impact Assessment, PIA, or DPIA).

When is a DPIA required?

Regulators publish lists of processing types that always require a DPIA. Common triggers include:

  • Systematic, extensive evaluation of personal aspects (profiling, automated decisions with legal effect)
  • Large-scale processing of special-category or criminal-conviction data
  • Systematic monitoring of publicly accessible areas (CCTV, ANPR)
  • Processing children’s data on a commercial scale
  • Combining datasets from multiple sources
  • Using new technologies – including most uses of generative AI on personal data
  • International transfers to jurisdictions without adequacy decisions

What a DPIA must contain

Article 35(7) lists the minimum content:

  • A systematic description of the processing operations and purposes
  • An assessment of necessity and proportionality
  • An assessment of risks to data subjects’ rights and freedoms
  • The measures envisaged to address those risks – including safeguards and security measures
  • Records of consultation with the DPO, data subjects (where appropriate) and the regulator (where high residual risk remains)

The DPIA process

Trigger

A new processing activity is proposed – or an existing one is materially changed. The privacy team confirms whether a DPIA is required.

Scope

The processing is described systematically: what data, what purposes, what systems, what third parties, what retention.

Risk assessment

Each risk to data subjects is identified, scored for likelihood and severity, and mapped to mitigations.

Sign-off

The DPO reviews and the accountable business owner signs off. Where high residual risk remains, the regulator is consulted under Article 36.

Review

The DPIA is reviewed on a schedule and whenever the processing materially changes.

DPIA vs TIA vs LIA

DPIAs are often confused with two adjacent assessments. A Transfer Impact Assessment (TIA) is focused specifically on international transfers and the destination country’s legal framework – required after Schrems II for many GDPR transfers. A Legitimate Interests Assessment (LIA) is a balancing test required when relying on Article 6(1)(f) as a lawful basis. A DPIA may incorporate either, but they are not interchangeable.

Common pitfalls

  • Conducting DPIAs after deployment instead of by design
  • Treating it as a documentation exercise rather than a risk decision
  • Missing the consultation requirement when high residual risk remains
  • Failing to update the DPIA when the processing materially changes
  • Not linking the DPIA back to the ROPA, data map and applicable privacy notices

How PrivIQ supports DPIAs

PrivIQ ships DPIA templates pre-aligned to Article 35 – drawing scope information from the underlying data map and ROPA so teams don’t restart from scratch each time. AI assistance drafts assessment questions, risk descriptions and remediation tasks; humans approve. Outcomes link back to the ROPA, applicable privacy notices and processor records, so a regulator-facing audit pack can be produced on demand.

Key takeaways
  • A DPIA is mandatory under GDPR Article 35 whenever processing is likely to result in high risk – including most AI use cases involving personal data.
  • It must contain a description, necessity check, risk assessment, mitigations and sign-off – not just a free-form review.
  • DPIAs done after deployment are documentation exercises; DPIAs done by design are risk decisions.
  • Where high residual risk remains, prior consultation with the regulator under Article 36 is required.
PrivIQ

PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.

Frequently asked questions

More on Privacy Compliance.

Is a DPIA the same as a PIA?

They are closely related and the terms are often used interchangeably. ‘DPIA’ is the GDPR-specific term; ‘Privacy Impact Assessment’ (PIA) is broader and predates GDPR. Outside the EU, regulators may use PIA, Privacy Risk Assessment or Data Protection Assessment – the substance is similar.

Who signs off a DPIA?

The accountable business owner signs off on the processing; the Data Protection Officer (or equivalent) advises and reviews. The regulator is consulted under Article 36 only when high residual risk remains after mitigations.

Do I need to consult the regulator?

Only where, after applying mitigations, the residual risk to data subjects remains high. In practice this is rare – most DPIAs end with risks reduced below the consultation threshold.

How often should I review a DPIA?

At minimum, on a defined cycle (annually is typical) and whenever the processing materially changes – new data sources, new recipients, new technologies (including new AI components), or changes in scope.

Does every AI use case need a DPIA?

Not strictly – but most uses of AI on personal data trigger DPIA criteria (new technology, systematic evaluation, large-scale processing). Regulators across the EU, UK and South Africa have signalled that AI deployments should be treated as high-risk by default unless clearly justified otherwise.

Put this into practice.

Book a meeting, watch a self-guided walkthrough or take the free assessment to see where your programme stands.