← All postsHow-to

Data protection impact assessment: when you need one and what it must show

A data protection impact assessment is required before high-risk processing starts, not after. The triggers, the sections, and what makes a DPIA defensible.

How-toD

A data protection impact assessment — a DPIA — is a written analysis of a proposed use of personal data: what you intend to do, why it is necessary, what could go wrong for the people whose data it is, and what you will do to reduce that. Under the GDPR and equivalent regimes it is mandatory before certain kinds of processing begin, and that timing is the part companies get wrong. A DPIA written after launch is not a DPIA; it is a description of a decision already taken.

When a data protection impact assessment is required

  • Systematic and extensive automated evaluation of people, including profiling, where decisions produce legal or similarly significant effects.
  • Large-scale processing of special category data — health, biometrics, beliefs, trade union membership — or criminal offence data.
  • Systematic monitoring of a publicly accessible area, which is where most CCTV and analytics deployments land.
  • New technologies applied to personal data, which is the clause that increasingly catches anything involving machine learning.
  • Combining datasets from different sources, or processing data about vulnerable people including children and employees.
  • Regulators publish their own lists of processing that always requires one — read yours rather than reasoning from the general criteria.

What the assessment has to contain

  1. A systematic description of the processing: what data, whose, from where, to whom, for how long, and by what means.
  2. The lawful basis, and for special category data the additional condition — stated, not implied.
  3. Necessity and proportionality: why this data and not less, and why this method rather than a less intrusive one. This section is where weak assessments are visibly weak.
  4. The risks to individuals, described as harms to them rather than as risks to you — distress, discrimination, financial loss, loss of control.
  5. The measures that reduce each risk, with residual risk stated honestly after mitigation.
  6. Consultation: with your data protection officer where you have one, and with the people affected or their representatives where practicable.
  7. A decision, signed and dated, and where high residual risk remains, prior consultation with the regulator before you proceed.

The point of the exercise is that it can change the plan. An assessment that concludes every proposal is acceptable with no modification has not been done properly, and that pattern is visible across a set of them. If nothing was ever narrowed, shortened, or dropped as a result, the process is decorative.

Keeping it useful after the launch

  • Review when the processing changes, not on a calendar — a new data source or a new purpose is a new assessment, not an amendment.
  • Link it to the information asset register so the systems it covers are identifiable later.
  • Record the residual risks somewhere they will be seen again, because those are what a regulator asks about after an incident.
  • Keep the version that was actually approved, alongside earlier drafts if they show how the design changed — evidence that the process bit.
  • Where a supplier is involved, the assessment and the standard contractual clauses cover different things and both are usually needed.

Where the assessment lives

Ettex Records holds each assessment as a dated record against the processing it covers, with the residual risks and the review trigger as fields rather than paragraphs buried on page nine. That matters because the question that arrives later is never "show me the DPIA" alone — it is "which of these did you accept, and who signed". Ettex does not assess risk, is not a data protection officer, and the thresholds differ by jurisdiction and by regulator guidance; check the rules that apply to you rather than the general description here.

Frequently asked

Do we need a DPIA for every new system?

No. It is required for high-risk processing, and a short screening note recording why a full assessment was not needed is the right output for everything else. That screening record is itself worth keeping.

Who signs it off?

Whoever can accept the residual risk on behalf of the organisation, having taken the data protection officer’s advice where one exists. If the officer disagreed, record the disagreement — overruling advice is permitted, hiding it is not.

Should we publish it?

There is usually no obligation, and most organisations publish a summary rather than the full document. Publishing something is a strong signal of confidence, and in public-sector contexts it is increasingly expected.

EP
Written by Elena P.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.