Data protection impact assessments
A DPIA is not a form to file at the end. It is meant to happen before the processing starts, which is the part that makes it inconvenient and also the part that makes it useful.
What the law requires
Article 35 of the UK GDPR requires a data protection impact assessment where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of individuals. It must be carried out prior to the processing. The assessment must describe the processing and its purposes, assess necessity and proportionality, assess the risks, and set out the measures intended to address them. Where a DPIA indicates high residual risk and the controller cannot mitigate it, Article 36 requires prior consultation with the Information Commissioner. The Commissioner publishes a list of processing that always requires one.
Legislation referred to on this page: UK GDPR Article 35 · UK GDPR Article 36. Named so you can read the source. Nothing on this page is legal advice, and whether a duty applies to your organisation is a question for you and your adviser.
Who it applies to
- Any controller planning processing likely to result in high risk — commonly large-scale monitoring, special category data at scale, or new technology applied to people.
- Screening decisions matter as much as assessments: recording that you considered whether one was needed and concluded it was not is part of accountability.
- A DPIA should be reviewed when the processing changes, not treated as a one-off.
What you have to be able to show
The list an inspector, insurer or auditor actually works through.
- The screening decision, and the date it was made.
- The DPIA itself, where one was required, completed before processing began.
- The measures adopted to reduce risk, and evidence they were implemented.
- Consultation with the data protection officer where one is appointed.
- Any prior consultation with the Information Commissioner.
- Review when the processing changed.
How DutyHub records it
DutyHub does not carry out any of the work below. It records who did, when, and what they found.
Screening recorded either way
The "no DPIA needed" decision is a dated record with reasoning, which is the one organisations most often cannot produce.
Assessment before processing
The assessment is dated and the processing it covers is dated, so the order is visible rather than asserted.
Measures become actions
Each mitigation is an action with an owner, so "we said we would encrypt it" has an answer.
Start with what applies to you
Add your premises and answer a short set of questions about them. DutyHub works out which duties land on which building, and shows you the gaps before anybody else finds them.
Check your Martyn's Law tier — free See pricing