Data protection impact assessments (DPIAs)

Data producer support home page

Data protection impact assessments (DPIAs)

A Data Protection Impact Assessment (DPIA) is a structured approach used to evaluate, identify, and reduce potential data protection risks associated with a project or initiative. It helps researchers in identifying potential privacy risks early on and putting appropriate safeguards in place so that data can be shared responsibly.

Within the context of the UK GDPR, a DPIA also helps demonstrate that data is managed in a transparent and accountable way. Rather than aiming to remove all risk, the process helps you reduce risks to a reasonable level.

UK GDPR requires you to carry out a DPIA when a type of data processing is likely to create a high level of risk to individuals’ rights and freedoms. Here, “risk” refers to the possibility of meaningful harm whether physical, financial, or psychological. To decide if something qualifies as “high risk,” you need to consider both how likely the harm is to happen and how serious it could be. A general risk means there is more than a minimal chance of harm, while a high risk suggests either a greater probability, more severe consequences, or both. Evaluating this likelihood and impact is a key part of completing a DPIA.

In a research context, you may not always need to carry out a DPIA when planning to share data for future use. For example, if your data processing is required under a legal obligation or carried out in the public interest (such as certain types of publicly funded research), a DPIA may not be necessary provided there is a clear legal basis.

Where public task is relied upon as the lawful basis for processing, the requirement to carry out a DPIA depends on the level of risk and whether the processing is already clearly defined and assessed within a statutory framework. The following examples illustrate both scenarios:

Case study 1

A publicly funded university research project processes and shares identifiable health data under a public task basis, involving large-scale data analysis and linkage across multiple institutions.

Explanation: Despite relying on public task, a DPIA is necessary because the processing involves sensitive data, operates at scale, and includes data sharing, all of which may pose significant risks to individuals’ rights and freedoms.

Case study 2

A government-led research programme processes and shares personal data in line with a specific legal obligation for public health monitoring, where the legislation clearly defines the scope, safeguards, and purpose, and a data protection risk assessment was completed when the law was established.

Explanation: In this situation, a DPIA may not be required because the processing is explicitly governed by law and the associated risks have already been assessed through the legislative process.

The table below provides illustrative examples of research data sharing scenarios in which a Data Protection Impact Assessment (DPIA) is likely to be required, along with an explanation of the associated risks that necessitate such an assessment.

Scenario Description Why DPIA is needed
Sharing sensitive health/genetic data Sharing genetic or sensitive health data with collaborators where reidentification risks exist. High risk due to sensitivity of data and potential harm if confidentiality is breached.
Linking multiple datasets Combining and sharing datasets (e.g. health, education, social care) for longitudinal analysis. Increases risk of identification and profiling through data linkage.
Use of AI on shared data Applying AI or machine learning techniques to shared datasets to generate predictions about individuals. Introduces risks related to automated decision-making and lack of transparency.
International data transfers Sharing data with partners in other countries where data protection standards may differ. Potential for inadequate safeguards and loss of control over data.
Vulnerable populations Sharing data relating to children, patients, or marginalised groups with increased risk of harm. Higher ethical and legal risks due to vulnerability of participants.
Pseudonymised data risks Sharing pseudonymised data that could be reidentified when combined with other datasets. Residual risk of reidentification despite safeguards.
Open data repositories Creating repositories for future reuse by multiple or unknown users. Uncertain future uses increased risk and reduces control over data.
Automated profiling Sharing data used for automated decision-making or profiling affecting individuals. Potential significant impact on individuals’ rights and freedoms.
Sharing fully anonymised data Sharing data that has been anonymised so individuals cannot be identified. Low risk as individuals is no longer identifiable.
Internal reuse of assessed data Reusing data within the same team for similar purposes already covered by a DPIA. Risks have already been assessed, and no significant changes are introduced.
Low-risk non-sensitive data Sharing aggregated or non-sensitive data without special category information. Minimal likelihood of harm to individuals.
Small-scale minimal data research Limited data processing with no new technologies and low impact on individuals. Low scale and limited impact significantly reduce risk.

The UK’s Information Commissioner’s Office (ICO) has made a DPIA template and various checklists available to help organisations carry out assessments in a clear and structured way.

Detailed guidance on Data Protection Impact Assessments (DPIAs) is available from the Information Commissioner’s Office (ICO) website.