Data Protection Impact Assessment (DPIA): A Simple Guide
A Data Protection Impact Assessment (DPIA) is a structured way to spot and reduce privacy risks before you start a project that uses personal data in a risky way. UK GDPR makes one mandatory for high-risk processing. This guide explains when you need a DPIA and walks you through a simple, small-business version step by step.
What a DPIA is
A Data Protection Impact Assessment, or DPIA, is a structured way to think through the privacy risks of a project before you start it — and then reduce them. It is essentially a planning tool: you describe what you want to do with people’s data, ask what could go wrong for those people, and decide how to make it safer.
Under UK GDPR, a DPIA is not just good practice. For certain higher-risk activities it is a legal requirement. The good news is that a DPIA does not have to be a heavy, bureaucratic document. For a small business, a clear one- or two-page assessment done honestly is worth far more than a thick report nobody reads.
This guide explains when you actually need a DPIA and how to complete a simple one, step by step.
When a DPIA is required
You must carry out a DPIA when your processing is likely to result in a high risk to people’s rights and freedoms. UK GDPR specifically names three situations:
- Systematic and extensive automated decision-making that has legal or similarly significant effects on people — such as automated profiling that decides whether someone gets a service.
- Large-scale processing of special category data — health, ethnicity, religious beliefs, criminal offence data and similar — or of data relating to criminal convictions.
- Large-scale, systematic monitoring of a publicly accessible area — for example, extensive CCTV or tracking.
The ICO adds further triggers where a DPIA is expected, including:
- Using innovative or new technology in a way people may not expect.
- Combining or matching datasets from different sources.
- Processing data about vulnerable people, such as children or patients.
- Tracking people’s location or behaviour.
- Processing that could deny people access to a service or opportunity.
If your project ticks two or more of these, treat a DPIA as necessary. If you are genuinely unsure, doing one anyway is the safer and simpler choice.
Do a quick screening check first
Most projects do not need a full DPIA, so start with a short screening check. For any new system, product or way of using data, ask:
- Am I using any of the high-risk types of processing above?
- Am I handling special category data, or data about children or vulnerable people?
- Am I using new technology, or using data in a way people would not expect?
- Could this decision affect someone’s access to money, services or opportunities?
If the answer to all of these is a clear ‘no’, record that you checked and move on. If any answer is ‘yes’ or ‘maybe’, carry out a DPIA.
A clear one- or two-page assessment done honestly is worth far more than a thick report nobody reads.
How to do a simple DPIA, step by step
A workable small-business DPIA has seven parts. You can write it in a single document.
1. Describe the processing
Set out plainly what you plan to do. What data will you collect, from whom, and how? Where will it be stored, who will have access, and how long will you keep it? Explain the purpose in a sentence or two. Clarity here makes every later step easier.
2. Explain why you need it
State the benefit — to your business, your customers, or both — and confirm your lawful basis for the processing. If you cannot articulate a clear purpose and lawful basis, that is a warning sign in itself.
3. Consider the people affected
Whose data is it, and what would they expect? Where it is proportionate, ask them or their representatives for their views. Even a quick, informal check of ‘would our customers be comfortable with this?’ is valuable.
4. Identify the risks
Think about what could go wrong for the individuals, not just for you. Common risks include:
- Data being lost, stolen, or accessed by the wrong people.
- Data being used for something people did not expect.
- Keeping data longer than needed, or collecting more than necessary.
- People being unable to exercise their rights, such as access or deletion.
For each risk, note how likely it is and how serious the impact would be.
5. Decide how to reduce each risk
This is the heart of the DPIA. For every risk, write down a practical control. For example:
- Collect less data, or delete it sooner.
- Restrict who can see it, and turn on multi-factor authentication.
- Encrypt sensitive files and keep reliable backups.
- Train staff so they know how to handle the data safely.
- Anonymise or pseudonymise data where you can.
Good security controls do a lot of the heavy lifting here, which is why the practical side of a DPIA overlaps closely with everyday cyber-security.
6. Record the outcome and sign it off
Summarise the remaining risk after your controls are in place: is it now low, medium, or still high? Have the person responsible for the project approve it. If you have a Data Protection Officer, they should advise before sign-off.
7. Consult the ICO if a high risk remains
If, after doing everything reasonable, a high risk still remains, you must consult the ICO before you go ahead. This is uncommon for small businesses — in most cases your controls will bring the risk down to an acceptable level — but it is an important legal safeguard.
Keep it alive
A DPIA is not a one-off form to file and forget. If the project changes — new data, new technology, a new supplier — revisit it. Keep the document with your other data protection records so you can show the ICO, or a customer, that you thought carefully before acting. That evidence of good faith is exactly what regulators want to see, and it fits neatly alongside the wider habits covered in our GDPR basics for UK small business.
Getting help
Much of a DPIA comes down to sensible IT and security decisions: who can access what, how data is stored, and how you would recover from a mistake. That is exactly the ground DACROS covers for small businesses across Leeds and Yorkshire. If you have a new project on the horizon and want a second pair of eyes on the risks, get in touch — we will keep it clear, honest and free of jargon.
Frequently asked questions
Does every small business need a DPIA?
No. A DPIA is only legally required when your processing is likely to result in a high risk to people's rights and freedoms — for example, large-scale use of health data, systematic monitoring, or new technology used in a novel way. Many small businesses will rarely need a full DPIA, but doing a quick screening check for any new project is good practice.
When exactly is a DPIA mandatory?
UK GDPR requires one for high-risk processing. That clearly includes systematic and extensive automated decisions with significant effects, large-scale processing of special category data, and large-scale systematic monitoring of a public area. The ICO also lists further situations, such as combining datasets, using innovative technology, or processing data about vulnerable people.
Who should carry out the DPIA?
Whoever owns the project should lead it, with input from anyone who understands the data and the technology involved. If you have a Data Protection Officer, they should advise. For a small business, this is often the owner or manager working through a simple template rather than a formal committee.
What happens if the DPIA finds a high risk we cannot reduce?
If, after doing everything reasonable, a high risk remains, you must consult the ICO before you start the processing. This is uncommon for small businesses, but it is an important safeguard. In most cases you will find practical ways to bring the risk down to an acceptable level and proceed.
Dacros — led by Jordan Gilbert
Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.
Related guides
IT and Cyber Security for Charities and Non-Profits in the UK
A plain-English guide to IT and cyber security for UK charities: protecting donor and beneficiary data, controlling volunteer access, and Cyber Essentials on a tight budget.
Read → GuideIT & Cyber Security for Solicitors and Law Firms: A Plain-English Guide
A practical guide to IT security for UK law firms: client confidentiality, SRA-aligned controls, secure email and documents, DMARC, backups and staying compliant.
Read → GuideIT Support for Recruitment Agencies in the UK
A plain-English guide to IT and cyber security for UK recruitment agencies: protecting candidate data, securing your CRM/ATS, mobile working and stopping placement invoice fraud.
Read →Want this handled for you?
Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.