Skip to main content
v2026.11,772 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.2

Data Protection Impact Assessment (DPIA)

A documented assessment required under Article 35 of the GDPR where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, describing the processing, assessing necessity, proportionality, and risks, and identifying mitigating measures.

ByCASRAI Editorial Board
· Last updated 22 Aug 2026
Share this

Ask CASRAI · included with Regulatory Radar

Ask about Data Protection Impact Assessment (DPIA)

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    Before launching a wearable-sensor mental-health study that combines geolocation with mood reports, the research team completes a DPIA documenting pseudonymisation, encrypted storage, and a defined retention schedule.

  • Is an instance

    A university implementing a campus-wide CCTV analytics pilot conducts a DPIA, identifies residual high risk to staff and students, and consults the supervisory authority under Article 36.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A small-scale researcher survey collecting only name and email of voluntary participants for a single course evaluation typically does not meet Article 35 thresholds.

  • Not an instance

    Processing of fully anonymous statistical data does not require a DPIA under the GDPR.

Editorial commentary

A DPIA must be carried out prior to commencing processing and, at a minimum, must contain a systematic description of the envisaged operations and purposes, an assessment of necessity and proportionality in relation to the purposes, an assessment of risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks. Article 35(3) lists mandatory DPIA triggers including systematic and extensive evaluation of personal aspects based on automated processing, large-scale processing of special-category data, and systematic monitoring of publicly accessible areas. National supervisory authorities publish additional lists. Where residual high risk remains after mitigation, the controller must consult the supervisory authority under Article 36.

References

  • GDPR Regulation (EU) 2016/679 Article 35 Data protection impact assessment
  • Article 29 Working Party Guidelines on Data Protection Impact Assessment (WP248 rev.01)
  • UK Information Commissioner's Office Sample DPIA template and guidance

The DPIA process in practice

A DPIA is normally carried out as a structured sequence rather than a single document written in one pass:

  1. Screening — check whether the processing meets one of the Article 35(3) triggers, or any trigger published on a national supervisory authority’s own list (in the UK, the ICO publishes both a screening checklist and a DPIA template).
  2. Systematic description — document the nature, scope, context, and purposes of the processing.
  3. Necessity and proportionality assessment — justify why the processing is needed for the stated purpose and why less intrusive alternatives are not sufficient.
  4. Risk assessment — identify risks to the rights and freedoms of data subjects, not only to the organisation.
  5. Mitigating measures — set out the safeguards (pseudonymisation, encryption, access controls, retention limits) that reduce the identified risks.
  6. Sign-off and, where residual risk remains high, prior consultation with the data protection officer and, under Article 36, the supervisory authority before processing begins.

DPIAs in a research context

Institutional research ethics review and DPIA screening increasingly run alongside each other: a study can pass ethics review on scientific and consent grounds while still triggering a mandatory DPIA because of how it processes special category data or uses novel technology (e.g., large-scale sensor data, algorithmic profiling). Many institutions now build a DPIA screening question directly into the research data management plan approval workflow so that the assessment happens before data collection starts, not retrospectively.

References

  • GDPR Regulation (EU) 2016/679 Article 35 Data protection impact assessment
  • Article 29 Working Party Guidelines on Data Protection Impact Assessment (WP248 rev.01)
  • UK Information Commissioner’s Office Sample DPIA template and guidance

Also known as

DPIA · Privacy Impact Assessment · PIA

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Data Protection Impact Assessment (DPIA)"
      vocab-term-identifier="https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia",
  "name": "Data Protection Impact Assessment (DPIA)",
  "identifier": "https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia",
  "description": "A documented assessment required under Article 35 of the GDPR where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, describing the processing, assessing necessity, proportionality, and risks, and identifying mitigating measures.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia",
  "sameAs": [
    "DPIA",
    "Privacy Impact Assessment",
    "PIA"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-05-21T02:22:53",
  "dateModified": "2026-08-22T12:43:13",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.