DPIA Tool — Free Data Protection Impact Assessment Template
A Data Protection Impact Assessment (DPIA) is required under UK GDPR Article 35 whenever processing is likely to result in a high risk to individuals' rights and freedoms. The ICO mandates DPIAs for large-scale processing of special category data, systematic monitoring of public areas, automated decision-making with legal effects, and several other processing types listed in their published screening criteria. This free interactive DPIA tool walks you through the five-step process recommended by the ICO: describe the processing, assess necessity and proportionality, identify risks to individuals, plan mitigating measures, and record the outcome. It flags special category data and children's data automatically, scores risks on a 4×4 likelihood-severity matrix, tracks inherent versus residual risk, and links directly to the GovernStack GDPR Fine Estimator and Data Breach Cost Calculator for quantifying your regulatory and financial exposure. All data stays in your browser — nothing is transmitted to any server.
Describe the processing
Based on the ICO's DPIA template and UK GDPR Article 35 requirements. Risk scoring uses a 4×4 likelihood-severity matrix. All data is stored in your browser only — nothing is sent to any server. Use Ctrl/Cmd+P to export as PDF.
What is a Data Protection Impact Assessment?
A DPIA is a structured process for systematically analysing how a proposed data processing activity will affect individuals' privacy and data protection rights. It is not a box-ticking exercise — it is a genuine risk assessment that forces the data controller to think through the consequences of processing before it begins, identify risks to individuals, and implement measures to reduce those risks to an acceptable level.
The concept originates from UK GDPR Article 35, which requires DPIAs for any processing that is "likely to result in a high risk to the rights and freedoms of natural persons." The ICO has published specific screening criteria that trigger a mandatory DPIA, including large-scale profiling, systematic monitoring, processing of children's data, and innovative use of new technologies such as AI.
How this tool maps to the ICO template
The ICO publishes a DPIA template that it recommends organisations follow. This tool implements the same five-stage structure: (1) describe the nature, scope, context, and purposes of the processing; (2) assess necessity, proportionality, and compliance measures; (3) identify and assess risks to individuals; (4) identify measures to mitigate those risks; and (5) record the outcome, including any conditions for proceeding and the review date. The tool automatically flags special category data and children's data when selected, as these trigger additional requirements under Articles 9 and 8 respectively.
Linking your DPIA to financial exposure
A DPIA is a compliance document — but the risks it identifies have real financial consequences. If the processing results in a data breach, the costs include incident response, notification, regulatory fines, and compensation claims. GovernStack provides tools to quantify each of these:
- The GDPR Fine Estimator models your maximum ICO fine exposure based on violation type, turnover, and enforcement factors
- The Data Breach Cost Calculator estimates total breach costs using IBM 2024 benchmarks across detection, response, notification, and lost business
- The Data Breach Compensation Calculator estimates what individuals might claim under UK GDPR Article 82
Used together, these tools build a complete picture: the DPIA identifies the risks, and the financial calculators quantify the cost of getting it wrong. This is a powerful combination for board-level reporting and budget justification for data protection controls.
For a comprehensive overview of UK GDPR compliance — covering all seven principles, data subject rights, breach notification, international transfers, and the full enforcement framework — see the UK GDPR Compliance Guide.