Data Protection Impact Assessment
A structured process, required for processing likely to result in a high risk to individuals, that identifies and helps minimise the data protection risks of a project before it goes ahead. Commonly abbreviated to DPIA.
Independent editorial summary — not the official statute text. Read the official version on legislation.gov.uk.
ICO guidance frames the DPIA as a practical risk-management tool rather than a paperwork exercise: 'A DPIA is a process designed to help you systematically analyse, identify and minimise the data protection risks of a project or plan.' It does not have to eliminate every risk, but it does have to help the organisation judge whether the remaining level of risk is acceptable given what the project is trying to achieve.
Carrying one out is not always optional. The guidance is direct about the consequences of skipping it where it is required: 'Conducting a DPIA is a legal requirement for any type of processing, including certain specified types of processing that are likely to result in a high risk to the rights and freedoms of individuals.' The stakes for getting this wrong are significant — the same guidance warns that 'Under UK GDPR, failure to carry out a DPIA when required may leave you open to enforcement action, including a fine of up to £8.7 million, or 2% global annual turnover if higher.'
Related terms
Official sources
This explanation is drawn from the official sources below; every substantive statement is verified against them. For advice on a specific matter, see our find help page.