DPIA full form is Data Protection Impact Assessment. Learn when GDPR Article 35 requires a DPIA, the 9 EDPB criteria, what a DPIA must include and how to carry one out step by step.
The full form of DPIA is Data Protection Impact Assessment. A DPIA is a process an organization carries out before starting a new processing activity to identify and reduce the risks it poses to people's privacy and rights. Article 35 of the GDPR makes a DPIA mandatory when processing is likely to result in a high risk to individuals, for example large-scale profiling, systematic monitoring or processing sensitive data.
| Term | Full form | Meaning |
|---|---|---|
| DPIA | Data Protection Impact Assessment | The assessment required by Article 35 of the GDPR for high-risk processing. |
| PIA | Privacy Impact Assessment | A broader, older term for assessing privacy risks. Often used outside the EU and in the public sector. |
| TIA | Transfer Impact Assessment | An assessment of the laws of a non-EEA country before transferring personal data there using SCCs. |
| LIA | Legitimate Interests Assessment | A test showing that legitimate interests is a valid lawful basis for a processing activity. |
| DPA | Data Protection Assessment | The term used by several US state privacy laws for a similar risk assessment. |
Under Article 35, you must carry out a DPIA before processing that is likely to result in a high risk to the rights and freedoms of individuals. The GDPR lists three cases where a DPIA is always required:
The European Data Protection Board (EDPB) guidelines on DPIAs list nine criteria that indicate high risk. If your processing meets two or more, a DPIA is usually required:
Each supervisory authority publishes a list of processing types that require a DPIA in its country (Article 35(4)), and some also publish lists of processing that does not. Check the list of the authority where you operate, such as the CNIL in France, the ICO in the UK or the German data protection authorities.
| Processing activity | DPIA likely required? |
|---|---|
| Behavioural advertising that tracks users across websites | Yes: large-scale monitoring, profiling and combined datasets |
| Credit scoring or automated loan decisions | Yes: evaluation and automated decisions with significant effects |
| A health app processing medical data | Yes: sensitive data, often on a large scale |
| Employee monitoring software | Yes: systematic monitoring of vulnerable data subjects |
| Facial recognition or other biometric identification | Yes: sensitive data and innovative technology |
| AI systems trained on or making decisions about personal data | Usually yes: innovative technology, often with profiling |
| A newsletter sign-up form | Usually no |
| A small shop's customer list for orders | Usually no |
If you decide a DPIA is not needed for processing that meets some of the criteria, document why.
Article 35(7) sets the minimum content of a DPIA:
If a DPIA shows that the processing would still result in a high risk and you cannot reduce it enough, you must consult your supervisory authority before starting the processing (Article 36). The authority has up to eight weeks to give written advice, which it can extend by six weeks for complex processing. It can also use its powers to limit or ban the processing.
Failing to carry out a required DPIA, carrying it out incorrectly, or failing to consult the supervisory authority when required falls under the lower tier of GDPR fines: up to €10 million or 2% of global annual turnover, whichever is higher. Regulators also often ask for DPIAs during investigations, and a missing DPIA makes it harder to show that other processing was lawful.
| Law | Assessment | Summary |
|---|---|---|
| UK GDPR | DPIA | Same requirements as the EU GDPR. The ICO publishes a list of processing that requires a DPIA. |
| US state privacy laws | Data protection assessment | Laws in states such as Virginia, Colorado, Connecticut and Texas require an assessment for targeted advertising, the sale of personal data, profiling and processing sensitive data. |
| California CCPA/CPRA | Risk assessment | Regulations require businesses to assess processing that presents a significant risk to consumers' privacy. |
| Brazil LGPD | Data protection impact report (RIPD) | The regulator (ANPD) can require controllers to prepare one. |
| China PIPL | Personal information protection impact assessment | Required before processing sensitive data, automated decision-making, entrusting or sharing data, publishing data and cross-border transfers. |
| India DPDP Act | Data protection impact assessment | Required periodically for Significant Data Fiduciaries. |
Learn more about US state privacy laws, Brazil's LGPD, China's PIPL and India's DPDP Act.
Websites and apps that use behavioural advertising, cross-site tracking, audience matching or large-scale analytics often meet several of the EDPB criteria: monitoring, profiling, large scale and combined datasets. A DPIA for this kind of processing typically looks at:
For website and app tracking, UniConsent gives you the evidence and controls a DPIA needs:
DPIA stands for Data Protection Impact Assessment, the process required by Article 35 of the GDPR to identify and reduce the privacy risks of high-risk processing.
A DPIA is mandatory before processing that is likely to result in a high risk to individuals, including large-scale profiling with significant effects, large-scale processing of sensitive data and large-scale monitoring of public areas. Processing that meets two or more of the EDPB criteria usually needs one.
The controller is responsible. It must seek the advice of its DPO, if it has one, and processors must help where needed. The work is often done by the project owner together with privacy, security and legal teams.
No. The GDPR does not require you to publish a DPIA, but you must be able to show it to the supervisory authority. Publishing a summary can help build trust.
A DPIA is the specific assessment required by the GDPR, with minimum content set by Article 35. A PIA, or privacy impact assessment, is a broader term used in other laws and frameworks.
You must consult your supervisory authority before starting the processing. The authority has up to eight weeks, extendable by six, to give written advice, and it can limit or ban the processing.
Get started to make your website and application compliant for EU GDPR, US CPRA, CA PIPEDA etc
Sign up