A DPIA, or Data Protection Impact Assessment, is a formal risk-assessment process that organisations must complete before undertaking certain types of personal data processing that are likely to result in high risk to individuals. It is a legal requirement under modern data protection frameworks, most notably the EU General Data Protection Regulation, and serves as a preventive tool rather than a retrospective audit. This guide covers the legal definition of a DPIA, when it is mandatory, what it must contain, how to conduct one in practice, and the consequences of non-compliance.
A DPIA is a documented process through which a data controller systematically evaluates the necessity, proportionality, and risk profile of a planned data processing activity. The term "data controller" refers to any entity - a company, public authority, or individual - that determines the purposes and means of processing personal data.
The legal foundation for the DPIA obligation in Europe is Article 35 of the General Data Protection Regulation (GDPR), which came into force across EU member states and has since influenced data protection legislation in the United Kingdom, Switzerland, Brazil, and numerous other jurisdictions. The GDPR does not treat a DPIA as optional guidance; it is a binding legal obligation for processing operations that meet defined risk thresholds.
At its core, a DPIA answers three questions: what data is being processed and why, what risks that processing creates for the rights and freedoms of natural persons, and what measures can reduce those risks to an acceptable level. The assessment must be completed before processing begins - not after a system is deployed or a product is launched.
A common mistake among organisations new to data protection compliance is treating a DPIA as a box-ticking exercise. In practice, supervisory authorities expect it to be a genuine, iterative analysis that shapes the design of the processing activity, not a document produced to justify a decision already made.
The GDPR mandates a DPIA when processing is "likely to result in a high risk" to individuals. This threshold is deliberately broad, and supervisory authorities across the EU have issued guidance to clarify which activities trigger the obligation.
Three categories of processing automatically require a DPIA under Article 35(3) of the GDPR:
Beyond these automatic triggers, the European Data Protection Board (EDPB) has identified additional criteria that, when two or more apply simultaneously, typically require a DPIA. These include the use of innovative technology, processing that prevents individuals from exercising a right or using a service, and processing involving vulnerable data subjects such as children or employees.
National supervisory authorities - such as the French CNIL, the German data protection authorities, and the UK Information Commissioner';s Office - have published their own lists of processing operations that always require a DPIA in their jurisdiction. Organisations operating across borders must check both the GDPR baseline and any jurisdiction-specific lists.
In practice, founders and compliance teams should apply a pre-screening test before any new processing project. If the answer to any of the EDPB';s nine criteria is affirmative, a DPIA is likely required. Many underestimate how broadly "large scale" is interpreted: processing the personal data of tens of thousands of individuals in the context of a core business activity will generally meet the threshold.
Article 35(7) of the GDPR sets out the minimum content of a valid DPIA. Supervisory authorities will assess compliance against these elements, and an incomplete DPIA carries the same legal risk as no DPIA at all.
A compliant DPIA must include:
Beyond these statutory requirements, best practice - and the guidance of the EDPB in its guidelines on DPIAs - calls for additional elements. These include a description of the data flows involved, the legal basis for processing, consultation records with the Data Protection Officer (DPO) where one has been appointed, and a record of the decision-making process.
The DPO plays a specific role here. Under Article 35(2) of the GDPR, the controller must seek the advice of the DPO when carrying out a DPIA, and must document that advice and whether it was followed. Ignoring the DPO';s recommendations without documented justification is a compliance risk that supervisory authorities take seriously.
A non-obvious requirement is the obligation to consult data subjects or their representatives where appropriate. This does not mean that every individual whose data is processed must be consulted, but where processing significantly affects a defined group - employees, customers, or users of a specific service - their views or those of their representatives should be sought and documented.
Conducting a DPIA is not a single event but a structured workflow that typically involves multiple internal stakeholders and, in some cases, external advisers. The process can be broken into four broad stages.
The first stage is scoping. The controller defines the processing activity in detail: what data is collected, from whom, for what purpose, how long it is retained, and who has access. This stage also identifies the legal basis for processing under Article 6 of the GDPR and, where special category data is involved, the additional condition under Article 9.
The second stage is necessity and proportionality assessment. The controller asks whether the processing achieves its stated purpose and whether a less intrusive method could achieve the same result. This is where data minimisation principles - processing only the data that is strictly necessary - are applied. Many organisations discover at this stage that they are collecting more data than they actually need.
The third stage is risk identification and assessment. Risks are assessed against two dimensions: the likelihood that a harm will occur and the severity of that harm if it does. Harms include physical, material, and non-material damage to individuals, such as discrimination, identity theft, financial loss, reputational damage, or loss of confidentiality of data protected by professional secrecy. The risk assessment should be documented in sufficient detail to demonstrate that it was conducted rigorously.
The fourth stage is risk mitigation and decision. For each identified risk, the controller identifies and implements measures to reduce it. These may include technical measures such as encryption, pseudonymisation, or access controls, and organisational measures such as staff training, data processing agreements, or contractual restrictions on data sharing. After mitigation, the residual risk is assessed. If residual risk remains high, the controller must consult the competent supervisory authority before proceeding - this is the prior consultation obligation under Article 36 of the GDPR.
If you are structuring a DPIA process for the first time or reviewing an existing one for adequacy, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Prior consultation is a distinct legal obligation that arises when a DPIA reveals that residual risk remains high after all mitigation measures have been applied. It is not a voluntary step; under Article 36 of the GDPR, the controller must consult the competent supervisory authority before commencing the processing.
The supervisory authority has up to eight weeks to respond, with a possible extension of a further six weeks in complex cases. During this period, the authority may provide written advice, impose conditions on the processing, or prohibit it entirely. The controller must not begin the processing until the consultation period has elapsed or the authority has responded.
In practice, prior consultation is relatively rare because most risks can be reduced to an acceptable level through well-designed mitigation measures. However, certain categories of processing - such as large-scale health data analytics, AI-driven profiling systems, or novel biometric identification technologies - frequently require it. Organisations that proceed without prior consultation when it is required face significant enforcement risk.
A practical scenario illustrates the point. A financial services company plans to deploy a machine learning model that uses transaction data to assess creditworthiness and make automated decisions with legal effects on applicants. This processing involves profiling, automated decision-making, and large-scale data use - three DPIA triggers. If the DPIA reveals that the model produces discriminatory outcomes that cannot be fully mitigated, the company must consult its national supervisory authority before launch.
A second scenario: a healthcare provider introduces a patient portal that processes special category health data and integrates with third-party analytics tools. The DPIA identifies risks related to unauthorised access and data sharing with processors in third countries. By implementing strong encryption, restricting third-party access, and using standard contractual clauses for international transfers, the provider reduces residual risk to an acceptable level and can proceed without prior consultation.
Non-compliance with the DPIA obligation is a directly enforceable breach of the GDPR. Supervisory authorities have the power to impose administrative fines of up to ten million euros or two percent of total worldwide annual turnover, whichever is higher, for failure to carry out a DPIA when required. This is the lower tier of GDPR fines; more serious violations can attract fines at double that level.
Beyond financial penalties, supervisory authorities can issue reprimands, impose temporary or permanent bans on processing, and require controllers to bring processing into compliance within a specified period. Reputational damage from a public enforcement decision can be significant, particularly for organisations that handle sensitive consumer data.
A common mistake is assuming that a DPIA conducted once is sufficient indefinitely. The GDPR requires controllers to review a DPIA when there is a change in the risk represented by the processing. This means that a system upgrade, a new data sharing arrangement, a change in the volume of data processed, or a change in the legal or technical context can all trigger the need to update or repeat the assessment.
Controllers that appoint a DPO should ensure that the DPO maintains a register of DPIAs and schedules periodic reviews. Organisations without a DPO should assign clear internal responsibility for DPIA maintenance. Many underestimate the ongoing nature of this obligation, treating the initial DPIA as a permanent compliance certificate rather than a living document.
What is the difference between a DPIA and a records of processing activities (ROPA)?
A ROPA is a comprehensive inventory of all processing activities carried out by a controller or processor, required under Article 30 of the GDPR. It documents what data is processed, by whom, for what purpose, and with what retention periods. A DPIA, by contrast, is a risk-specific assessment triggered only when processing is likely to result in high risk. The ROPA is a broader administrative record; the DPIA is a targeted risk management tool. In practice, the ROPA is often the starting point for identifying which processing activities require a DPIA, but the two documents serve different legal functions and must be maintained separately.
How long does a DPIA take to complete, and what does it cost?
The time required depends on the complexity of the processing activity. A straightforward DPIA for a single, well-defined processing operation can typically be completed in two to four weeks with adequate internal resources. Complex projects involving multiple data flows, novel technology, or cross-border transfers may take two to three months, particularly if prior consultation with a supervisory authority is required. Professional fees for external legal or privacy counsel to assist with a DPIA vary considerably depending on the scope and jurisdiction, but organisations should budget from the low thousands of euros for a standard assessment. Costs rise significantly if the DPIA reveals systemic compliance gaps that require remediation before processing can begin.
Does a DPIA apply outside the European Union?
The DPIA requirement originated in the GDPR and applies to any organisation processing the personal data of individuals located in the EU, regardless of where the organisation itself is established. Beyond the EU, several jurisdictions have introduced equivalent requirements. The UK GDPR, which mirrors the EU GDPR post-Brexit, contains an identical DPIA obligation. Brazil';s Lei Geral de Proteção de Dados (LGPD) includes a data impact assessment requirement, and various other national laws reference similar concepts. Organisations operating globally should assess their obligations under each applicable framework, as the triggers, content requirements, and supervisory authority involvement may differ in detail even where the underlying concept is the same.
A DPIA is a legally binding, risk-based process that sits at the centre of modern data protection compliance. It requires organisations to assess, document, and mitigate privacy risks before high-risk processing begins, and to consult supervisory authorities when residual risk cannot be reduced to an acceptable level. Failing to conduct a required DPIA exposes organisations to significant regulatory penalties and reputational risk.
VLO Law Firms advises international clients on data protection impact assessments and broader privacy compliance matters. We can assist with scoping DPIA obligations, drafting compliant assessments, advising on prior consultation procedures, and reviewing existing DPIA frameworks for adequacy. To request a consultation, contact: info@vlolawfirm.com