Skip to main content
v2026.11,858 entries · CC-BY 4.0
Dictionary termTrack DProposedv2026.2

Data Protection Impact Assessment (DPIA)

A documented assessment required under Article 35 of the GDPR where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, describing the processing, assessing necessity, proportionality, and risks, and identifying mitigating measures.

ByCASRAI Editorial Board
· Last updated 5 Sept 2026
Share this

Ask CASRAI · free to try

Ask about Data Protection Impact Assessment (DPIA)

Ask your first 2 questions free below. Subscribers get 150 a day for $29 a month.

An AI assistant specialized in research administration. It cites the sources behind every answer, labels web answers and says when it can't answer.

Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.

Works on this site and inside Claude, Cursor and the AI tools you already use.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Examples

Worked examples

  • Is an instance

    Before launching a wearable-sensor mental-health study that combines geolocation with mood reports, the research team completes a DPIA documenting pseudonymisation, encrypted storage, and a defined retention schedule.

  • Is an instance

    A university implementing a campus-wide CCTV analytics pilot conducts a DPIA, identifies residual high risk to staff and students, and consults the supervisory authority under Article 36.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A small-scale researcher survey collecting only name and email of voluntary participants for a single course evaluation typically does not meet Article 35 thresholds.

  • Not an instance

    Processing of fully anonymous statistical data does not require a DPIA under the GDPR.

Editorial commentary

A DPIA must be carried out prior to commencing processing and, at a minimum, must contain a systematic description of the envisaged operations and purposes, an assessment of necessity and proportionality in relation to the purposes, an assessment of risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks. Article 35(3) lists mandatory DPIA triggers including systematic and extensive evaluation of personal aspects based on automated processing, large-scale processing of special-category data, and systematic monitoring of publicly accessible areas. National supervisory authorities publish additional lists. Where residual high risk remains after mitigation, the controller must consult the supervisory authority under Article 36.

References

  • GDPR Regulation (EU) 2016/679 Article 35 Data protection impact assessment
  • Article 29 Working Party Guidelines on Data Protection Impact Assessment (WP248 rev.01)
  • UK Information Commissioner's Office Sample DPIA template and guidance

The DPIA process in practice

A DPIA is normally carried out as a structured sequence rather than a single document written in one pass:

  1. Screening — check whether the processing meets one of the Article 35(3) triggers, or any trigger published on a national supervisory authority’s own list (in the UK, the ICO publishes both a screening checklist and a DPIA template).
  2. Systematic description — document the nature, scope, context, and purposes of the processing.
  3. Necessity and proportionality assessment — justify why the processing is needed for the stated purpose and why less intrusive alternatives are not sufficient.
  4. Risk assessment — identify risks to the rights and freedoms of data subjects, not only to the organisation.
  5. Mitigating measures — set out the safeguards (pseudonymisation, encryption, access controls, retention limits) that reduce the identified risks.
  6. Sign-off and, where residual risk remains high, prior consultation with the data protection officer and, under Article 36, the supervisory authority before processing begins.

DPIAs in a research context

Institutional research ethics review and DPIA screening increasingly run alongside each other: a study can pass ethics review on scientific and consent grounds while still triggering a mandatory DPIA because of how it processes special category data or uses novel technology (e.g., large-scale sensor data, algorithmic profiling). Many institutions now build a DPIA screening question directly into the research data management plan approval workflow so that the assessment happens before data collection starts, not retrospectively.

References

  • GDPR Regulation (EU) 2016/679 Article 35 Data protection impact assessment
  • Article 29 Working Party Guidelines on Data Protection Impact Assessment (WP248 rev.01)
  • UK Information Commissioner’s Office Sample DPIA template and guidance

Also known as

DPIA · Privacy Impact Assessment · PIA

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="Data Protection Impact Assessment (DPIA)"
      vocab-term-identifier="https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia",
  "name": "Data Protection Impact Assessment (DPIA)",
  "identifier": "https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia",
  "description": "A documented assessment required under Article 35 of the GDPR where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, describing the processing, assessing necessity, proportionality, and risks, and identifying mitigating measures.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/data-protection-impact-assessment-dpia",
  "alternateName": [
    "DPIA",
    "Privacy Impact Assessment",
    "PIA"
  ],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "author": {
    "@id": "https://casrai.org/#editorial-team"
  },
  "datePublished": "2026-05-21T02:22:53",
  "dateModified": "2026-09-05T17:31:59",
  "inLanguage": "en-GB",
  "isAccessibleForFree": true
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Ask CASRAI · Regulatory Radar

Research-admin question? Get an answer that links its sources.

An AI assistant specialized in research administration. Every answer links its sources to check before you act. 2 questions free, no account. $29/month after.

  • Answers draw on CASRAI's guides and dictionary plus the federal and funder documents we index: Federal Register, Grants.gov, Regulations.gov and UKRI.
  • Every answer numbers its sources and links each one, so you can check the source yourself.