A Data Protection Impact Assessment, or DPIA, is the structured process GDPR Article 35 requires for identifying, evaluating, and reducing the privacy risks of a processing activity before it begins. It documents what data you process, why, the risks to individuals, and the safeguards that bring those risks down.
What a DPIA is and why it matters
The DPIA is one of the clearest expressions of the GDPR principle of accountability. Rather than waiting for harm to occur, the controller assesses risk in advance and builds mitigations into the design of the processing. This is data protection by design and by default in practice. A DPIA is not a one-off form; it is a living record that you revisit whenever the nature, scope, context, or purposes of the processing change materially.
Regulators treat the DPIA as evidence that an organisation understood its own risk. A thin or generic assessment signals the opposite. Our GDPR implementation guide walks through where the DPIA fits alongside your record of processing activities and your legal basis analysis.
When is a DPIA mandatory?
Article 35(1) requires a DPIA whenever processing is likely to result in a high risk to the rights and freedoms of individuals, particularly when using new technologies. Article 35(3) then names three cases where a DPIA is always required.
- Systematic and extensive automated profiling that produces legal or similarly significant effects on individuals, including automated decision-making
- Large-scale processing of special category data under Article 9, or of criminal conviction and offence data under Article 10
- Systematic monitoring of a publicly accessible area on a large scale, such as widespread CCTV or location tracking
- New technologies, biometric matching, or vulnerable data subjects such as children or employees, where supervisory authority screening lists apply
Each national supervisory authority also publishes lists of processing operations that always trigger a DPIA, so you should check the list for every jurisdiction in which you operate. When in doubt, running a short screening assessment is far cheaper than defending a missing one.
Getting this wrong is expensive. Failing to carry out a required DPIA can attract fines of up to EUR 10 million or 2 percent of worldwide annual turnover under Article 83(4). The most serious GDPR breaches, such as unlawful processing, sit in the higher tier of up to EUR 20 million or 4 percent of global turnover.
The DPIA process step by step
A defensible DPIA follows a repeatable sequence. Skipping steps is where most enforcement findings originate. A 2025 DLA Piper survey noted that 41 percent of organisations cited in DPIA-related enforcement notices were flagged for risk assessments that were too generic, so the detail in each step matters.
- Screen the processing to confirm whether a DPIA is required before any processing starts
- Describe the processing: the data flows, purposes, categories of data, recipients, retention, and any international transfers
- Assess necessity and proportionality against the stated purpose and legal basis
- Consult stakeholders, including data subjects or their representatives where appropriate
- Identify and score the risks to individuals, then define mitigations and evaluate the residual risk
- Record the DPO advice, the decision to proceed, and the review date
What the DPIA must contain
Article 35(7) sets the minimum content. A compliant DPIA must include a systematic description of the processing and its purposes; an assessment of the necessity and proportionality of the processing in relation to those purposes; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks, including safeguards and security measures. Generic risk registers copied between projects do not satisfy this requirement.
The role of the DPO and prior consultation
Where a Data Protection Officer has been designated, Article 35(2) requires the controller to seek the DPO advice when carrying out the DPIA. The DPO does not own the processing, but advises on methodology, challenges optimistic risk scoring, and monitors that agreed mitigations are actually implemented.
If, after applying every planned mitigation, the residual risk remains high, Article 36 requires the controller to consult the supervisory authority before starting the processing. The controller submits the DPIA together with details of responsibilities, purposes, means, safeguards, and DPO contact details. The authority must respond within eight weeks, extendable by six weeks for complex cases, and the processing cannot begin until that consultation concludes.
DPIAs, ISO 27701, and the NIST Privacy Framework
The DPIA does not exist in isolation. ISO/IEC 27701 extends ISO/IEC 27001 into a certifiable privacy information management system and maps directly to Article 35, giving you a repeatable governance structure for assessing and treating privacy risk. The NIST Privacy Framework takes a risk-management lens through its Identify, Govern, Control, Communicate, and Protect functions, which align closely with the description, risk, and mitigation stages of a DPIA.
Organisations that already run an ISMS often find the DPIA slots neatly into their existing risk methodology. Treating the DPIA as part of your broader management system, rather than a standalone legal chore, is what turns it from a compliance cost into a genuine control on privacy risk.