GovernStack
🛡️Cybersecurity

DPIA Tool — Free Data Protection Impact Assessment Template

A Data Protection Impact Assessment (DPIA) is required under UK GDPR Article 35 whenever processing is likely to result in a high risk to individuals' rights and freedoms. The ICO mandates DPIAs for large-scale processing of special category data, systematic monitoring of public areas, automated decision-making with legal effects, and several other processing types listed in their published screening criteria. This free interactive DPIA tool walks you through the five-step process recommended by the ICO: describe the processing, assess necessity and proportionality, identify risks to individuals, plan mitigating measures, and record the outcome. It flags special category data and children's data automatically, scores risks on a 4×4 likelihood-severity matrix, tracks inherent versus residual risk, and links directly to the GovernStack GDPR Fine Estimator and Data Breach Cost Calculator for quantifying your regulatory and financial exposure. All data stays in your browser — nothing is transmitted to any server.

Describe the processing

Based on the ICO's DPIA template and UK GDPR Article 35 requirements. Risk scoring uses a 4×4 likelihood-severity matrix. All data is stored in your browser only — nothing is sent to any server. Use Ctrl/Cmd+P to export as PDF.

What is a Data Protection Impact Assessment?

A DPIA is a structured process for systematically analysing how a proposed data processing activity will affect individuals' privacy and data protection rights. It is not a box-ticking exercise — it is a genuine risk assessment that forces the data controller to think through the consequences of processing before it begins, identify risks to individuals, and implement measures to reduce those risks to an acceptable level.

The concept originates from UK GDPR Article 35, which requires DPIAs for any processing that is "likely to result in a high risk to the rights and freedoms of natural persons." The ICO has published specific screening criteria that trigger a mandatory DPIA, including large-scale profiling, systematic monitoring, processing of children's data, and innovative use of new technologies such as AI.

How this tool maps to the ICO template

The ICO publishes a DPIA template that it recommends organisations follow. This tool implements the same five-stage structure: (1) describe the nature, scope, context, and purposes of the processing; (2) assess necessity, proportionality, and compliance measures; (3) identify and assess risks to individuals; (4) identify measures to mitigate those risks; and (5) record the outcome, including any conditions for proceeding and the review date. The tool automatically flags special category data and children's data when selected, as these trigger additional requirements under Articles 9 and 8 respectively.

Linking your DPIA to financial exposure

A DPIA is a compliance document — but the risks it identifies have real financial consequences. If the processing results in a data breach, the costs include incident response, notification, regulatory fines, and compensation claims. GovernStack provides tools to quantify each of these:

Used together, these tools build a complete picture: the DPIA identifies the risks, and the financial calculators quantify the cost of getting it wrong. This is a powerful combination for board-level reporting and budget justification for data protection controls.

For a comprehensive overview of UK GDPR compliance — covering all seven principles, data subject rights, breach notification, international transfers, and the full enforcement framework — see the UK GDPR Compliance Guide.

Frequently Asked Questions

When is a DPIA required under UK GDPR?

UK GDPR Article 35 requires a DPIA before processing that is "likely to result in a high risk to the rights and freedoms of natural persons." The ICO has published a list of processing operations that always require a DPIA, including: large-scale processing of special category data, systematic monitoring of publicly accessible areas, automated decision-making with significant effects, innovative use of new technologies, and processing that prevents individuals from exercising their rights.

What happens if I do not conduct a required DPIA?

Failure to carry out a DPIA when required is itself a breach of UK GDPR and can result in enforcement action by the ICO. The ICO can issue fines of up to £8.7 million or 2% of global annual turnover for procedural failures, including failure to conduct or consult on a DPIA. Beyond fines, a missing DPIA is a significant audit finding in ISO 27001 assessments and may invalidate cyber insurance claims.

Do I need to consult the ICO before proceeding?

Under UK GDPR Article 36, you must consult the ICO before processing if the DPIA indicates that the processing would result in a high risk that you cannot mitigate. In practice, this means if your residual risk scores remain high after implementing all reasonable safeguards, you should submit a prior consultation request to the ICO before starting the processing.

Who should be involved in a DPIA?

The data controller is responsible for conducting the DPIA, but it should involve input from: the Data Protection Officer (if appointed), the project or processing team, IT security, legal or compliance, and — where appropriate — the views of the data subjects or their representatives. The DPO must be consulted but does not carry out the DPIA themselves.

How often should a DPIA be reviewed?

DPIAs should be reviewed and updated whenever the processing changes in a way that could affect the risk profile — for example, new data categories, new recipients, changes in technology, or security incidents. Even without changes, an annual review is considered good practice and is expected by most certification auditors.

Is this tool suitable for ISO 27001 compliance?

Yes. ISO 27001:2022 control A.5.34 (Privacy and protection of PII) references the need for privacy impact assessments. The output of this tool — covering processing description, lawful basis, risk assessment, mitigations, and documented outcome — is consistent with what ISO 27001 auditors expect to see as evidence of a structured privacy risk assessment process.

Related Tools