Quick answerA Data Protection Impact Assessment (DPIA) is a structured review of a processing activity to identify privacy risks to individuals and decide how to mitigate them. GDPR Article 35 requires a DPIA whenever processing is likely to result in a high risk to rights and freedoms – typically including large-scale processing of special-category data, systematic monitoring of public areas, and most new AI use cases involving personal data.
Definition and legal basis
A DPIA is a documented assessment of how a processing activity could affect the rights and freedoms of natural persons, with mitigations recorded against each identified risk. Under Article 35 of the EU and UK GDPR, a DPIA is mandatory wherever processing is ‘likely to result in a high risk’. Similar requirements exist under POPIA (South Africa), DPDPA (India), LGPD (Brazil) and most modern privacy regimes – usually under different names (Privacy Impact Assessment, PIA, or DPIA).
When is a DPIA required?
Regulators publish lists of processing types that always require a DPIA. Common triggers include:
- Systematic, extensive evaluation of personal aspects (profiling, automated decisions with legal effect)
- Large-scale processing of special-category or criminal-conviction data
- Systematic monitoring of publicly accessible areas (CCTV, ANPR)
- Processing children’s data on a commercial scale
- Combining datasets from multiple sources
- Using new technologies – including most uses of generative AI on personal data
- International transfers to jurisdictions without adequacy decisions
What a DPIA must contain
Article 35(7) lists the minimum content:
- A systematic description of the processing operations and purposes
- An assessment of necessity and proportionality
- An assessment of risks to data subjects’ rights and freedoms
- The measures envisaged to address those risks – including safeguards and security measures
- Records of consultation with the DPO, data subjects (where appropriate) and the regulator (where high residual risk remains)
The DPIA process
Trigger
A new processing activity is proposed – or an existing one is materially changed. The privacy team confirms whether a DPIA is required.
Scope
The processing is described systematically: what data, what purposes, what systems, what third parties, what retention.
Risk assessment
Each risk to data subjects is identified, scored for likelihood and severity, and mapped to mitigations.
Sign-off
The DPO reviews and the accountable business owner signs off. Where high residual risk remains, the regulator is consulted under Article 36.
Review
The DPIA is reviewed on a schedule and whenever the processing materially changes.
DPIA vs TIA vs LIA
DPIAs are often confused with two adjacent assessments. A Transfer Impact Assessment (TIA) is focused specifically on international transfers and the destination country’s legal framework – required after Schrems II for many GDPR transfers. A Legitimate Interests Assessment (LIA) is a balancing test required when relying on Article 6(1)(f) as a lawful basis. A DPIA may incorporate either, but they are not interchangeable.
Common pitfalls
- Conducting DPIAs after deployment instead of by design
- Treating it as a documentation exercise rather than a risk decision
- Missing the consultation requirement when high residual risk remains
- Failing to update the DPIA when the processing materially changes
- Not linking the DPIA back to the ROPA, data map and applicable privacy notices
How PrivIQ supports DPIAs
PrivIQ ships DPIA templates pre-aligned to Article 35 – drawing scope information from the underlying data map and ROPA so teams don’t restart from scratch each time. AI assistance drafts assessment questions, risk descriptions and remediation tasks; humans approve. Outcomes link back to the ROPA, applicable privacy notices and processor records, so a regulator-facing audit pack can be produced on demand.
- A DPIA is mandatory under GDPR Article 35 whenever processing is likely to result in high risk – including most AI use cases involving personal data.
- It must contain a description, necessity check, risk assessment, mitigations and sign-off – not just a free-form review.
- DPIAs done after deployment are documentation exercises; DPIAs done by design are risk decisions.
- Where high residual risk remains, prior consultation with the regulator under Article 36 is required.
PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.
More on Privacy Compliance.
Is a DPIA the same as a PIA?
They are closely related and the terms are often used interchangeably. ‘DPIA’ is the GDPR-specific term; ‘Privacy Impact Assessment’ (PIA) is broader and predates GDPR. Outside the EU, regulators may use PIA, Privacy Risk Assessment or Data Protection Assessment – the substance is similar.
Who signs off a DPIA?
The accountable business owner signs off on the processing; the Data Protection Officer (or equivalent) advises and reviews. The regulator is consulted under Article 36 only when high residual risk remains after mitigations.
Do I need to consult the regulator?
Only where, after applying mitigations, the residual risk to data subjects remains high. In practice this is rare – most DPIAs end with risks reduced below the consultation threshold.
How often should I review a DPIA?
At minimum, on a defined cycle (annually is typical) and whenever the processing materially changes – new data sources, new recipients, new technologies (including new AI components), or changes in scope.
Does every AI use case need a DPIA?
Not strictly – but most uses of AI on personal data trigger DPIA criteria (new technology, systematic evaluation, large-scale processing). Regulators across the EU, UK and South Africa have signalled that AI deployments should be treated as high-risk by default unless clearly justified otherwise.