When Is a Data Protection Impact Assessment Required?

A Data Protection Impact Assessment, or DPIA, is mandatory under UK GDPR whenever a new processing activity is likely to result in a high risk to individuals. The ICO's guidance on DPIAs sets out specific types of processing that will almost always trigger this requirement, including systematic and extensive profiling with significant effects, large scale processing of special category data, and systematic monitoring of a publicly accessible area on a large scale. For most businesses, the question is not whether a DPIA might be relevant in theory, but whether a specific new project or tool falls within one of these recognised high-risk categories.

In practice, the most common trigger for businesses today is AI. If you are introducing a tool that profiles employees or customers, makes or significantly influences decisions affecting people such as recruitment, performance management, or credit decisions, or processes biometric or other sensitive data, a DPIA is very likely to be required before that tool goes live. The assessment should describe what the processing involves and why it is needed, evaluate whether it is necessary and proportionate, identify the specific risks it creates for individuals, and set out the measures you will put in place to address those risks.

The assessment needs to happen before deployment, not afterwards, since its purpose is to catch problems before they cause harm rather than respond to them once they have already occurred. If your DPIA identifies risks that you cannot adequately reduce, you are required to consult the ICO before proceeding. Failing to carry out a DPIA when one is legally required is itself a breach of UK GDPR, separate from any issues with the underlying processing, so if you are introducing any new AI tool, monitoring system, or large scale data project, it is worth checking early whether this requirement applies to you.

Next
Next

What Is The 72-Hour Rule Under GDPR?