Hatch resource banner image for How to complete a data protection impact assessment

How to complete a data protection impact assessment

A data protection impact assessment (DPIA) helps you identify and minimise privacy risks, ensuring your software is compliant with UK law and builds trust with your users.

Completing a data protection impact assessment (DPIA) is a legal requirement under UK GDPR for any project that involves high-risk data processing. This is essentially a risk assessment where you document how personal data moves through your software, what could go wrong, and the specific steps you are taking to keep that information safe.

When a DPIA is required

You must carry out a DPIA if your software involves any of the following:

  • Sensitive personal data: Processing health data, criminal records, or genetic information.
  • Large-scale monitoring: Tracking people in public areas or monitoring user behaviour on a massive scale.
  • Automated decision-making: Using algorithms to make decisions that have legal or significant effects on people.
  • New technology: Using innovative tech that might change how data is used in a way users wouldn't expect.

The seven steps of a DPIA

The Information Commissioner’s Office (ICO) provides a standard framework for conducting these assessments. Following these steps ensures you remain compliant:

  1. Identify the need: Briefly explain why you are doing the assessment and what the project aims to achieve.
  2. Describe the processing: Document how data is collected, stored, and used. Create a simple flow chart showing where the data goes and who has access to it.
  3. Consultation: Where appropriate, seek the views of your potential users or data protection experts. If you decide not to consult, you must document your reasoning.
  4. Assess necessity and proportionality: Confirm that the data you are collecting is actually necessary for your software to function. Is there a less intrusive way to achieve the same result?
  5. Identify and assess risks: List potential threats, such as data breaches, identity theft, or loss of control over personal information. Rank these based on their likelihood and the severity of the impact on the individual.
  6. Identify measures to mitigate risks: For every risk identified, list a technical or organisational solution. This might include data encryption, multi-factor authentication, or strict access controls.
  7. Sign off and record: Once you have identified how to manage the risks, record the outcome. If you find a high risk that you cannot mitigate, you must consult the ICO before you start processing the data.

Best practices for your assessment

Think of your DPIA as a 'live' document rather than a one-off box-ticking exercise. As your software evolves and you add new features, you should revisit the assessment to ensure your risk mitigations are still effective.

Keep your language simple and avoid overly technical jargon. The goal is to make it clear to anyone reading the document how you are protecting their rights.

Finally, always refer to the official templates and guidance on the ICO website. They provide detailed checklists that can help ensure you haven't missed any critical privacy considerations for your specific industry.

Created by hatch. • Updated on April 29, 2026