← Back to insights
PRIVACY RISK

When Should You Conduct a Data Protection Impact Assessment?

A practical screening approach for identifying high-risk processing and building privacy into projects before they go live.

Written by Lahiru Livera, Cybersecurity Advisor · Last reviewed: August 2026
Educational guidance only — not legal advice. The DPA has published draft impact-assessment regulations for consultation; confirm current legal requirements and guidance before relying on this article.

A DPIA is a decision-making tool

A Data Protection Impact Assessment, often called a DPIA, helps an organisation identify privacy risks before high-risk processing begins. It should not be treated as a form completed at the end of a project. Its value comes from influencing design, controls, approvals, and accountability early.

Start with privacy screening

Introduce a short privacy-screening questionnaire at project intake. It should ask what data is involved, who is affected, what technology is used, whether data is shared, where it is hosted, how long it is retained, and what harm could occur if something goes wrong.

INDICATOR 1

Sensitive or high-impact personal data

The activity involves health, biometric, financial, identity, children’s, employment, surveillance, or other information that could create significant harm if misused or exposed.

INDICATOR 2

Large-scale or systematic processing

The initiative processes data about many people, continuously monitors activity, or becomes central to a major service or decision-making process.

INDICATOR 3

New technology or novel use

The project introduces AI, biometrics, tracking, profiling, automated decision-making, advanced analytics, connected devices, or unfamiliar technology.

INDICATOR 4

Surveillance or monitoring

The initiative monitors people through CCTV, workplace tools, location tracking, behavioural analytics, network monitoring, or similar methods.

INDICATOR 5

Data sharing or cross-border complexity

The activity involves multiple controllers, processors, cloud environments, international transfers, or difficult-to-understand data flows.

INDICATOR 6

Potentially serious impact on individuals

The processing could affect access to services, employment, financial interests, safety, reputation, dignity, or other important interests.

What a practical DPIA should cover

  • • Description of the processing and its purpose
  • • Categories of people and data involved
  • • Necessity and proportionality considerations
  • • Data flows, systems, suppliers, and locations
  • • Privacy and security risks
  • • Mitigations, accountable owners, residual risks, and approvals
  • • Review triggers when the processing changes

Build privacy into delivery

Make privacy screening and DPIA decisions part of project governance, procurement, architecture review, change management, and go-live approval. This is more effective than attempting to retrofit controls after a system or service is already operational.

Privacy by design

Identify privacy risk before it becomes operational risk.

Explore advisory support for DPIA screening, privacy risk assessment, project governance, and implementation planning.

Explore advisory support →