Glossary | GDPR & Data Privacy
Data Protection Impact Assessment (DPIA)
What is a Data Protection Impact Assessment (DPIA)?
A Data Protection Impact Assessment (DPIA) is a process carried out by a Data Controller to identify, assess, and address the privacy risks associated with a new or significantly changed data processing activity. Under Regulation (EU) 2016/679 (GDPR), a DPIA is mandatory where processing is likely to result in a high risk to the rights and freedoms of individuals.
Why It Matters
A DPIA is not simply a compliance formality — it is a structured risk management tool that helps organisations identify and mitigate privacy risks before they materialise. Carrying out a DPIA early in the design of a new processing activity allows problems to be addressed at a stage when changes are still practical and cost-effective.
Where a DPIA is required and not carried out, the organisation is in breach of the GDPR, regardless of whether any harm actually occurs. Supervisory authorities may treat the failure to conduct a required DPIA as evidence of a broader failure of accountability, increasing the likelihood and severity of enforcement action.
For organisations introducing new technologies, processing sensitive data, or conducting large-scale monitoring of individuals, understanding when and how to carry out a DPIA is a key part of GDPR compliance.

Key Requirements
When Is a DPIA Required?
A DPIA is mandatory when processing is likely to result in a high risk, particularly where:
- Large-scale processing of special categories of personal data is involved
- Systematic and extensive profiling or automated decision-making takes place
- Large-scale systematic monitoring of a publicly accessible area is conducted
This requirement applies under:
- Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), Article 35
Supervisory authorities may also publish lists of processing activities for which a DPIA is always required or never required in their jurisdiction. Controllers should consult the relevant national guidance alongside the GDPR’s own criteria.
What a DPIA Must Include
Under the GDPR, a DPIA must contain at minimum:
- A systematic description of the processing activity and its purposes
- An assessment of the necessity and proportionality of the processing
- An assessment of the risks to the rights and freedoms of data subjects
- The measures envisaged to address those risks, including safeguards and security measures
The Role of the DPO in a DPIA
Where a Data Protection Officer has been appointed, the controller is required to seek the DPO’s advice when carrying out a DPIA. The DPO’s involvement does not transfer responsibility for the assessment to the DPO — accountability remains with the controller — but their expertise is an important input into the process.
Where the DPIA identifies a high residual risk that cannot be mitigated, the controller must consult the relevant supervisory authority before proceeding with the processing activity.
Frequently Asked Questions
No. A DPIA is required where processing is likely to result in a high risk to individuals. For lower-risk activities, a DPIA may not be mandatory, though documenting the decision not to carry one out is considered good practice.
The Data Controller is responsible for ensuring a DPIA is carried out. Where a DPO has been appointed, their advice must be sought. Processors may also be required to assist with information and assessments relevant to their processing activities.
Where a high residual risk remains after mitigation measures have been considered, the controller must consult the supervisory authority prior to commencing the processing. The authority may then advise, impose conditions, or prohibit the processing.
Need GDPR Representative Services?
Euverify provides EU Representative services for organisations outside the European Union that are subject to the GDPR. Our team supports regulatory communication, documentation, and ongoing compliance management.
Related Terms
Further Reading