A DPIA is mandatory under the GDPR and UK GDPR where processing is likely to result in high risk. The assessment is only useful if it happens before the decision is made — not after the contract is signed.
A PIA or DPIA is a structured assessment of a processing activity, carried out before it goes live, to identify the risks it creates for individuals and confirm what controls are needed to bring those risks to an acceptable level.
Under the GDPR and UK GDPR a DPIA is mandatory where processing is likely to result in high risk, including large scale monitoring, special category data, and automated decision making with legal or similarly significant effects. Several US state laws now impose comparable assessment obligations.
Any company launching new products, deploying new technology, or processing sensitive data at scale needs both the assessments themselves and a framework that determines when one is triggered and who signs it off.
Either a specific processing activity has stalled because no one can assess or approve it, or an audit, regulatory finding, or customer diligence exercise has established that assessments should have been carried out and were not.
Companies also come to this when a new deployment is imminent — most often AI or a new vendor platform — and the business needs the assessment completed before launch rather than a framework in the abstract.
A scoping call to confirm the processing activities in scope, the jurisdictions engaged, and whether the need is for a framework, specific assessments, or both.
Develop the risk framework, defining the risk criteria, scoring methodology, thresholds for what constitutes high risk, mitigation expectations, and residual risk acceptance and escalation routes.
Draft the assessment policy, setting out when a PIA or DPIA is triggered, who is responsible for initiating it, the approval path, and how outcomes are recorded and revisited.
Interview the stakeholders behind the processing activity — typically product, IT, infosec, procurement, and the business owner — and review contracts, data flows, and technical documentation.
Conduct the PIA or DPIA, documenting the processing, assessing necessity and proportionality, identifying risks to individuals, and recording controls, residual risk, and sign off.
Circulate for stakeholder review, finalise, train the teams expected to run assessments going forward, and hand over the SOP and templates for ongoing use.
The most common failure is timing. Assessments get completed after the decision has been made and the contract signed, so they document risk rather than reduce it.
Where there is no framework, the trigger is left to individual judgment, and high risk processing goes unassessed while low risk activity is over documented. Scoring is applied inconsistently between assessors, which makes the outputs impossible to compare or prioritize.
Risk is also framed as risk to the company rather than risk to individuals, which is the wrong test and does not hold up under regulatory scrutiny. Finally, mitigations are recorded and never implemented, because nothing in the process assigns ownership or checks completion.
A consumer services business with vendor-heavy processing needed its personal data processing assessed, both for the activities it carried out directly and for the vendors processing on its behalf. I built the risk framework and assessment policy, defining what triggers a PIA, who owns it, and how residual risk is escalated and accepted, then conducted the assessments across the processing activities and vendor relationships in scope.
The business came out of it with a documented view of where its risk sat and a repeatable route to assess new processing rather than deciding case by case.
Under the GDPR and UK GDPR a DPIA is mandatory where processing is likely to result in high risk, including large scale monitoring, special category data, and automated decision making with legal or similarly significant effects. Several US state laws now impose comparable assessment obligations.
Assessments completed after the decision has been made and the contract signed document risk rather than reduce it. The assessment is only useful when it happens before the processing goes live.
A framework build produces the risk criteria, scoring methodology, high risk thresholds, assessment policy, triggers, approval path, templates, and the SOP — the repeatable infrastructure for running assessments going forward. An individual assessment applies that infrastructure to a specific processing activity. Building the framework typically runs four to eight weeks as a fixed fee project; individual assessments are generally two to four weeks each.
Framework builds typically run four to eight weeks as a fixed fee project. Individual assessments are generally two to four weeks each. The right shape is usually obvious once we have scoped the work on a call.
A short note about your situation is plenty. Replies come from rasha.hisham@appliedprivacyconsulting.com.
We use Google Analytics 4 to understand how this site is used and to measure our advertising. These set cookies on your device. Nothing loads until you choose. How we handle your data.