What is a DPIA? A UK GDPR guide for SaaS teams

A Data Protection Impact Assessment is the UK GDPR's structured way of asking: before we build this, have we thought about the risks to people?

A Data Protection Impact Assessment, a DPIA, is a structured risk assessment required under Article 35 of the UK GDPR whenever a processing activity is likely to result in a high risk to the rights and freedoms of individuals. It is the regulator's preferred way of pushing privacy thinking upstream, into product design, rather than treating it as a paperwork exercise after launch.

A data protection solicitor can help work with your product or engineering team to consider if a DPIA is required. Many teams avoid conduct impact assessments except in cases of mandatory high risk. However conducting a holistic impact assessment at the outset of a product can flag critical risks ahead of time and help guide the build. 

When a DPIA is mandatory

UK GDPR makes a DPIA mandatory for processing that is likely to result in high risk. The ICO publishes a list of activities that always require one, including large-scale processing of special-category data, systematic monitoring of publicly accessible areas, using new technologies in a novel way, profiling with legal or significant effects, and combining datasets in ways individuals would not expect.

In a technology context, common triggers include: - launching an AI feature that processes customer content; - launching digital health applications; - introducing behavioural analytics or session replay; - deploying biometric authentication; or - building a data-sharing integration with a new third party.

What a DPIA contains

A DPIA must describe the processing (what data, whose data, why, how long, who has access), assess whether the processing is necessary and proportionate to the purpose, identify the risks to individuals, and set out the measures you will take to reduce those risks.

DPIAs should be undertaken with a genuine assessment of the risk and not be considered a box-ticking exercise. In the event of an investigation, the ICO (as data protection regulator) may request review of the impact assessments that were carried out prior to processing.

How to run one without slowing the team down

The most effective DPIAs are short, with input from product teams or the person building the feature, with legal or privacy input rather than entirely drafted by a solicitor.

For AI features specifically, the DPIA should address training data, inference data, human oversight, and any automated decisions with legal or significant effects.

When to involve the ICO

If your DPIA identifies a high residual risk that you cannot mitigate, UK GDPR requires you to consult the ICO before starting the processing. In practice this is rare, most risks can be reduced through design changes, contractual safeguards or user controls, but if mitigation is not possible it is the requirement.

Getting help

Hythe Legal advises AI and software companies on UK GDPR, including DPIA templates and reviews as part of ongoing privacy advisory. If you are preparing for enterprise procurement or launching an AI feature and want the DPIA done properly, do get in touch.

Get in touch