DPIA Full Form: Data Protection Impact Assessment

DPIA full form is Data Protection Impact Assessment. Learn when GDPR Article 35 requires a DPIA, the 9 EDPB criteria, what a DPIA must include and how to carry one out step by step.

DPIA Full Form: What Is a Data Protection Impact Assessment?

The full form of DPIA is Data Protection Impact Assessment. A DPIA is a process an organization carries out before starting a new processing activity to identify and reduce the risks it poses to people's privacy and rights. Article 35 of the GDPR makes a DPIA mandatory when processing is likely to result in a high risk to individuals, for example large-scale profiling, systematic monitoring or processing sensitive data.

DPIA and Related Terms

TermFull formMeaning
DPIAData Protection Impact AssessmentThe assessment required by Article 35 of the GDPR for high-risk processing.
PIAPrivacy Impact AssessmentA broader, older term for assessing privacy risks. Often used outside the EU and in the public sector.
TIATransfer Impact AssessmentAn assessment of the laws of a non-EEA country before transferring personal data there using SCCs.
LIALegitimate Interests AssessmentA test showing that legitimate interests is a valid lawful basis for a processing activity.
DPAData Protection AssessmentThe term used by several US state privacy laws for a similar risk assessment.

When Is a DPIA Required?

Under Article 35, you must carry out a DPIA before processing that is likely to result in a high risk to the rights and freedoms of individuals. The GDPR lists three cases where a DPIA is always required:

  1. A systematic and extensive evaluation of people based on automated processing, including profiling, that leads to decisions with legal or similarly significant effects
  2. Large-scale processing of special category data (such as health, biometric or genetic data) or data about criminal convictions
  3. Systematic monitoring of a publicly accessible area on a large scale, such as CCTV in public places

The nine EDPB criteria

The European Data Protection Board (EDPB) guidelines on DPIAs list nine criteria that indicate high risk. If your processing meets two or more, a DPIA is usually required:

  1. Evaluation or scoring, including profiling and predicting behaviour
  2. Automated decision-making with legal or similarly significant effects
  3. Systematic monitoring of individuals
  4. Sensitive data or data of a highly personal nature
  5. Data processed on a large scale
  6. Matching or combining datasets from different sources
  7. Data about vulnerable people, such as children, employees or patients
  8. Innovative use of technology, such as AI, facial recognition or connected devices
  9. Processing that prevents people from exercising a right or using a service or contract

National DPIA lists

Each supervisory authority publishes a list of processing types that require a DPIA in its country (Article 35(4)), and some also publish lists of processing that does not. Check the list of the authority where you operate, such as the CNIL in France, the ICO in the UK or the German data protection authorities.

Examples

Processing activityDPIA likely required?
Behavioural advertising that tracks users across websitesYes: large-scale monitoring, profiling and combined datasets
Credit scoring or automated loan decisionsYes: evaluation and automated decisions with significant effects
A health app processing medical dataYes: sensitive data, often on a large scale
Employee monitoring softwareYes: systematic monitoring of vulnerable data subjects
Facial recognition or other biometric identificationYes: sensitive data and innovative technology
AI systems trained on or making decisions about personal dataUsually yes: innovative technology, often with profiling
A newsletter sign-up formUsually no
A small shop's customer list for ordersUsually no

When a DPIA is not needed

  • The processing is unlikely to result in a high risk
  • A very similar processing activity has already been assessed in a DPIA
  • The processing is on the supervisory authority's list of exempt processing
  • The processing has a legal basis in EU or member state law, and a DPIA was already carried out when that law was adopted

If you decide a DPIA is not needed for processing that meets some of the criteria, document why.

What Must a DPIA Include?

Article 35(7) sets the minimum content of a DPIA:

  1. A systematic description of the processing and its purposes, including the legitimate interest pursued, where relevant
  2. An assessment of the necessity and proportionality of the processing in relation to its purposes
  3. An assessment of the risks to the rights and freedoms of individuals
  4. The measures planned to address those risks, including safeguards, security measures and mechanisms to protect personal data and demonstrate compliance

How to Carry Out a DPIA: Step by Step

  1. Identify the need. Screen new projects against the criteria above and your authority's list.
  2. Describe the processing. Set out the nature, scope, context and purposes: what data, whose data, where it comes from, who receives it, how long it is kept and which systems and vendors are involved.
  3. Consult. Seek the advice of your DPO, which is mandatory where you have one (Article 35(2)). Where appropriate, ask the people affected or their representatives, and involve IT, security, legal and your processors.
  4. Assess necessity and proportionality. Check the lawful basis, data minimisation, retention, transparency, how data subject rights are supported and how international transfers are covered.
  5. Identify and assess risks. Consider the likelihood and severity of harm to individuals, such as discrimination, identity theft, financial loss, loss of confidentiality or loss of control over their data.
  6. Identify measures to reduce risk. For example, collect less data, pseudonymise or encrypt it, shorten retention, add consent or opt-out controls, restrict access or choose different vendors.
  7. Sign off and record the outcome. Record which measures were approved, the residual risk, the DPO's advice and whether you followed it.
  8. Integrate the outcome into the project. Put the agreed measures into practice before processing starts.
  9. Keep it under review. Revisit the DPIA when the processing, the risks or the technology change (Article 35(11)).

Prior Consultation With the Supervisory Authority

If a DPIA shows that the processing would still result in a high risk and you cannot reduce it enough, you must consult your supervisory authority before starting the processing (Article 36). The authority has up to eight weeks to give written advice, which it can extend by six weeks for complex processing. It can also use its powers to limit or ban the processing.

What Happens If You Do Not Carry Out a DPIA?

Failing to carry out a required DPIA, carrying it out incorrectly, or failing to consult the supervisory authority when required falls under the lower tier of GDPR fines: up to €10 million or 2% of global annual turnover, whichever is higher. Regulators also often ask for DPIAs during investigations, and a missing DPIA makes it harder to show that other processing was lawful.

DPIA Requirements Under Other Privacy Laws

LawAssessmentSummary
UK GDPRDPIASame requirements as the EU GDPR. The ICO publishes a list of processing that requires a DPIA.
US state privacy lawsData protection assessmentLaws in states such as Virginia, Colorado, Connecticut and Texas require an assessment for targeted advertising, the sale of personal data, profiling and processing sensitive data.
California CCPA/CPRARisk assessmentRegulations require businesses to assess processing that presents a significant risk to consumers' privacy.
Brazil LGPDData protection impact report (RIPD)The regulator (ANPD) can require controllers to prepare one.
China PIPLPersonal information protection impact assessmentRequired before processing sensitive data, automated decision-making, entrusting or sharing data, publishing data and cross-border transfers.
India DPDP ActData protection impact assessmentRequired periodically for Significant Data Fiduciaries.

Learn more about US state privacy laws, Brazil's LGPD, China's PIPL and India's DPDP Act.

DPIAs for Cookies, Tracking and Advertising

Websites and apps that use behavioural advertising, cross-site tracking, audience matching or large-scale analytics often meet several of the EDPB criteria: monitoring, profiling, large scale and combined datasets. A DPIA for this kind of processing typically looks at:

  • Which cookies, pixels and SDKs are used, and which vendors receive data
  • Whether valid consent is collected before tags fire
  • How long identifiers and data are kept
  • Whether data is transferred outside the EEA
  • How users can withdraw consent and exercise their rights

How UniConsent Supports Your DPIA

For website and app tracking, UniConsent gives you the evidence and controls a DPIA needs:

  • The cookie scanner lists every cookie and tracker on your site, with categories and durations, for the description of processing
  • The consent banner blocks non-essential cookies and tags until visitors agree, which is a key risk-reducing measure
  • Consent records prove when and how each visitor consented
  • IAB TCF v2.3 and Google Consent Mode v2 pass consent signals to vendors, and the vendor list shows which vendors receive data
  • The Privacy Portal lets people submit access, deletion and other rights requests

Frequently Asked Questions

What is the full form of DPIA?

DPIA stands for Data Protection Impact Assessment, the process required by Article 35 of the GDPR to identify and reduce the privacy risks of high-risk processing.

When is a DPIA mandatory?

A DPIA is mandatory before processing that is likely to result in a high risk to individuals, including large-scale profiling with significant effects, large-scale processing of sensitive data and large-scale monitoring of public areas. Processing that meets two or more of the EDPB criteria usually needs one.

Who is responsible for carrying out a DPIA?

The controller is responsible. It must seek the advice of its DPO, if it has one, and processors must help where needed. The work is often done by the project owner together with privacy, security and legal teams.

Do I have to publish my DPIA?

No. The GDPR does not require you to publish a DPIA, but you must be able to show it to the supervisory authority. Publishing a summary can help build trust.

What is the difference between a DPIA and a PIA?

A DPIA is the specific assessment required by the GDPR, with minimum content set by Article 35. A PIA, or privacy impact assessment, is a broader term used in other laws and frameworks.

What if the DPIA shows a high risk that cannot be reduced?

You must consult your supervisory authority before starting the processing. The authority has up to eight weeks, extendable by six, to give written advice, and it can limit or ban the processing.

Further Reading

UniConsent Consent Manager for GDPR Compliance

  • Cookies scan and disclosing
  • JavaScript tags blocking and cookies blocking
  • Google Consent Mode v2 support
  • Certified IAB CMP
  • One-tag Implementation
  • Multiple languages support
  • Easy self-serve solution
  • Learn more from GDPR Compliance Guide

Microsoft certified CMP - UniConsent CMPIAB certified CMP - UniConsent CMPIAB TCF V2 certified CMP - UniConsent CMPIAB TCF Canada certified consent manager - UniConsent CMPGoogle-certified CMP Gold tire - UniConsent CMPGoogle-certified CMP partner

Comply With Global Privacy Regulations

Trusted by 5000+ of global publishers and marketers
  • sej
  • football365
  • sharethrough
  • districtm
  • pf1
  • tower cast

Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc

Sign up