PIAs and DPIAs

Structured risk assessments, built to reduce risk before processing goes live

A DPIA is mandatory under the GDPR and UK GDPR where processing is likely to result in high risk. The assessment is only useful if it happens before the decision is made — not after the contract is signed.

What a PIA or DPIA is and who needs one

A PIA or DPIA is a structured assessment of a processing activity, carried out before it goes live, to identify the risks it creates for individuals and confirm what controls are needed to bring those risks to an acceptable level.

Under the GDPR and UK GDPR a DPIA is mandatory where processing is likely to result in high risk, including large scale monitoring, special category data, and automated decision making with legal or similarly significant effects. Several US state laws now impose comparable assessment obligations.

Any company launching new products, deploying new technology, or processing sensitive data at scale needs both the assessments themselves and a framework that determines when one is triggered and who signs it off.

When organizations come to this

Either a specific processing activity has stalled because no one can assess or approve it, or an audit, regulatory finding, or customer diligence exercise has established that assessments should have been carried out and were not.

Companies also come to this when a new deployment is imminent — most often AI or a new vendor platform — and the business needs the assessment completed before launch rather than a framework in the abstract.

How the work runs

  1. 01

    Scoping

    A scoping call to confirm the processing activities in scope, the jurisdictions engaged, and whether the need is for a framework, specific assessments, or both.

  2. 02

    Risk framework

    Develop the risk framework, defining the risk criteria, scoring methodology, thresholds for what constitutes high risk, mitigation expectations, and residual risk acceptance and escalation routes.

  3. 03

    Assessment policy

    Draft the assessment policy, setting out when a PIA or DPIA is triggered, who is responsible for initiating it, the approval path, and how outcomes are recorded and revisited.

  4. 04

    Stakeholder interviews and documentation review

    Interview the stakeholders behind the processing activity — typically product, IT, infosec, procurement, and the business owner — and review contracts, data flows, and technical documentation.

  5. 05

    Conduct the assessment

    Conduct the PIA or DPIA, documenting the processing, assessing necessity and proportionality, identifying risks to individuals, and recording controls, residual risk, and sign off.

  6. 06

    Review, training, and handover

    Circulate for stakeholder review, finalise, train the teams expected to run assessments going forward, and hand over the SOP and templates for ongoing use.

Pricing

Framework, policy, and templates
Fixed fee Typically four to eight weeks.
Individual assessments
Per assessment or day rate ($2,000/day) Generally two to four weeks each depending on complexity and stakeholder availability.
Assessments at volume
Retainer from $4,500/mo Where assessments are needed at volume, they sit more efficiently within a retainer.

What goes wrong with assessments

The most common failure is timing. Assessments get completed after the decision has been made and the contract signed, so they document risk rather than reduce it.

Where there is no framework, the trigger is left to individual judgment, and high risk processing goes unassessed while low risk activity is over documented. Scoring is applied inconsistently between assessors, which makes the outputs impossible to compare or prioritize.

Risk is also framed as risk to the company rather than risk to individuals, which is the wrong test and does not hold up under regulatory scrutiny. Finally, mitigations are recorded and never implemented, because nothing in the process assigns ownership or checks completion.

What is included and what is not

Included

  • Risk framework with defined criteria, scoring methodology, and high risk thresholds
  • PIA and DPIA policy, including triggers, ownership, approval path, and escalation
  • Assessment templates and supporting guidance
  • Completed PIAs or DPIAs for the processing activities in scope
  • Stakeholder interviews and review of contracts, data flows, and documentation
  • Consultation requirements, including where prior consultation with a regulator is indicated
  • Training for teams running assessments
  • SOP for maintaining and revisiting assessments

Not included

  • Technical implementation of the controls or mitigations identified
  • Security testing, penetration testing, or technical validation
  • Ongoing assessment of new processing — available under retainer
  • Legal representation before a regulator

How this has worked in practice

A consumer services business with vendor-heavy processing needed its personal data processing assessed, both for the activities it carried out directly and for the vendors processing on its behalf. I built the risk framework and assessment policy, defining what triggers a PIA, who owns it, and how residual risk is escalated and accepted, then conducted the assessments across the processing activities and vendor relationships in scope.

The business came out of it with a documented view of where its risk sat and a repeatable route to assess new processing rather than deciding case by case.

Questions

When is a DPIA legally required?

Under the GDPR and UK GDPR a DPIA is mandatory where processing is likely to result in high risk, including large scale monitoring, special category data, and automated decision making with legal or similarly significant effects. Several US state laws now impose comparable assessment obligations.

Why does timing matter so much?

Assessments completed after the decision has been made and the contract signed document risk rather than reduce it. The assessment is only useful when it happens before the processing goes live.

What is the difference between a framework build and an individual assessment?

A framework build produces the risk criteria, scoring methodology, high risk thresholds, assessment policy, triggers, approval path, templates, and the SOP — the repeatable infrastructure for running assessments going forward. An individual assessment applies that infrastructure to a specific processing activity. Building the framework typically runs four to eight weeks as a fixed fee project; individual assessments are generally two to four weeks each.

Our services

Ready to scope the assessment?

Get in touch

Framework builds typically run four to eight weeks as a fixed fee project. Individual assessments are generally two to four weeks each. The right shape is usually obvious once we have scoped the work on a call.

Write to us

Prefer email? Start here.

A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.