Skip to main content
    Pritect
    All resources
    Data ProtectionHow-to6 min readUpdated 25 Jun 2026

    DPIA in practice: when and how to run one

    When a Data Protection Impact Assessment is required, how to run one that holds up, and how to connect it to AI Act assessments instead of duplicating the work.

    By Magdalena Goralczyk·Data Protection Partner, White Label Consultancy

    A Data Protection Impact Assessment (DPIA) is required where processing is likely to result in a high risk to people's rights and freedoms. In practice that covers large-scale profiling, systematic monitoring, special-category data at scale, and most novel uses of AI on personal data. Done well, a DPIA is a genuine risk tool. Done badly, it is a form-filling exercise that protects nobody.

    When you need one

    If you are unsure whether a DPIA is required, the European Data Protection Board's criteria are a useful screen. Two or more of these usually means yes: evaluation or scoring; automated decision-making with legal or similarly significant effect; systematic monitoring; sensitive data or data of a highly personal nature; large-scale processing; matching or combining datasets; data about vulnerable subjects; innovative use of technology; and processing that prevents people from exercising a right or using a service.

    When in doubt, a short screening assessment is cheaper than a missed obligation. Many organisations run a lightweight threshold assessment on every new project and only escalate to a full DPIA when the screen trips.

    Running one that holds up

    1. Describe the processing and its purposes in plain terms, including the data, the systems, and the recipients.
    2. Assess necessity and proportionality against the purpose. Could you achieve the same outcome with less data, or less intrusive means?
    3. Identify risks to data subjects, not risks to the organisation. The question is what could go wrong for the people whose data this is.
    4. Decide mitigations and record the residual risk that remains after them.
    5. Consult your DPO, and the supervisory authority where high residual risk cannot be reduced.

    The most common weakness is step three. A DPIA that catalogues risks to the company, reputational, regulatory, commercial, and never quite states the risk to the individual has missed the point of the exercise.

    Don't run it twice for AI

    When the processing is an AI system, the EU AI Act assessment and the DPIA overlap heavily: both examine the system, the data, the risks, and the safeguards. Running them on the same record, rather than in two tools, removes duplicate data entry and the contradictory conclusions that come from maintaining two descriptions of the same system. The DPIA answers the data protection question; the AI assessment answers the model-fitness question; they share a foundation.

    A DPIA is ultimately a thinking tool. The template matters far less than whether the people who understand the processing actually sat down and asked what could go wrong for the people affected, and did something about it.

    See how DPIAs connect to RoPA, AI assessments, and the risk register in Pritect.

    Explore Data Protection