Data Protection Impact Assessment (DPIA): The Framework
A Data Protection Impact Assessment (DPIA) is the GDPR's risk assessment for processing likely to result in high risk to individuals' rights and freedoms. Where your RoPA records the facts of what you do, the DPIA is the judgement about whether you should do it — and it must happen before the processing begins.
This is the framework page for the DPIA — the single definition the blog links to instead of re-explaining the assessment each time.
When a DPIA is mandatory
Article 35(1) requires a DPIA for any processing "likely to result in a high risk to the rights and freedoms of natural persons". Article 35(3) names three situations that always require one: systematic and extensive profiling with significant effects, large-scale processing of special category or criminal offence data, and systematic monitoring of publicly accessible areas at scale.
The ICO publishes a longer list under Article 35(4): innovative technology, biometric or genetic data, invisible processing, data matching, tracking, and decisions that deny a service. A screening checklist turns the judgement into a short structured exercise worth running for every new project.
What a DPIA contains
Article 35(7) prescribes the minimum content, which resolves into four parts: a systematic description of the processing, an assessment of necessity and proportionality, identification of risks to individuals, and measures to address those risks with residual risk stated.
The description section is largely an extract from your Article 30 record if it is current. If residual risk stays high after mitigation, Article 36 requires you to consult the supervisory authority before processing begins.
The DPIA in your wider programme
The DPIA reads its facts from your RoPA and feeds the results back into it. It is the natural companion to the DSAR: an individual's right to know how your risk judgements were made depends on records you assessed before the request ever arrived.
For the full trigger analysis, a worked example and where DPIAs actually fail, see our guide to when a DPIA is required and how to do one.