Artifact GuideUKDPIAs and DPOs

UK GDPR DPIAs and DPOs

A DPIA helps you identify and minimise the data protection risks of a project. A DPO is the person who advises, monitors compliance, and supports your organisation's UK GDPR obligations where appointment is required.

A DPIA and a DPO solve different problems. The controller or processor remains responsible for compliance; a DPO advises and monitors without owning the processing decision.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 27, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 27, 2026
Overview

Complete a before processing likely to result in a high risk to people's rights and freedoms. Consult the ICO before starting if measures cannot reduce the residual high risk. Separately, appoint a if Article 37 applies to the organisation's status or . A project may need a DPIA even where no DPO is required, and appointing a DPO does not transfer the controller's or processor's responsibility.

Section 1

What should teams decide about DPIAs and DPOs under the UK GDPR?

A is a process for identifying and minimising the data protection risks of a project. Under the UK GDPR, you must do one before processing that is likely to result in a high risk to individuals, including some specified types of processing such as systematic and extensive profiling with significant effects, large-scale processing of special category or criminal offence data, or systematic monitoring of a publicly accessible area on a .

Screen before design choices become fixed. Consider the processing's nature, scope, context, purposes, use of new technology, likelihood of harm, and severity of possible harm. The three Article 35 examples are not the only triggers; the ICO's published high-risk list and relevant combinations of risk factors also matter.

A is required for a public authority or body, except a court acting in its judicial capacity, or where require large-scale regular and systematic monitoring, or large-scale processing of special category or criminal-offence data. These appointment duties apply to controllers and processors.

  • Decide whether the project is likely to result in a high risk and therefore needs a .
  • Identify the nature, scope, context, purposes, necessity, proportionality, risks, and mitigation measures.
  • Decide whether the ICO must be consulted because the residual high risk cannot be reduced.
  • Check whether the organisation must appoint a because of its status or the nature, purpose, and scale of its .
  • Keep the decision, the rationale, and any review date in your records.
Section 2

Who should own DPIAs and DPOs, and what evidence should prove the decision?

The controller owns the decision and is responsible for carrying it out. The , where one is appointed, advises, monitors compliance, and supports the assessment but does not replace the controller's responsibility.

The must describe the processing and purposes, assess necessity and proportionality, assess risks to people's rights and freedoms, and state the measures that address those risks and demonstrate compliance. Seek the 's advice where one is appointed, consider consulting affected people or their representatives where appropriate, and record disagreements and sign-off.

For appointment, record the applicable Article 37 trigger or the reason no trigger applies. If the appointment is voluntary, the Article 37 to 39 requirements still apply to the role. Publish the DPO's contact details and communicate them to the ICO; the public contact details do not have to include the person's name.

A mandatory or voluntary must report to the highest management level, work independently, receive adequate resources and access, and avoid conflicting duties. A role that decides the purposes and means of processing, often a senior operational, finance, HR, IT, or marketing post, may conflict with the DPO's monitoring function; assess the person's actual authority rather than the job title alone.

  • Name the controller owner and the reviewer, if one is appointed.
  • Keep the screening checklist, template, approval notes, and review date together.
  • Record the reasons for any decision not to do a , and revisit that decision if the project changes.
  • Document why the organisation must appoint a , or why no appointment is required.
  • Keep the 's contact details current, publish them, provide them in privacy information, and communicate them to the ICO.
  • Document any decision not to follow the 's advice; the controller or processor owns that decision.
Section 3

Which borderline cases need closer review?

New technology alone does not automatically require a , and there is no fixed numerical definition of . Assess the number of people, data volume and range, geographical extent, duration or permanence, monitoring frequency, vulnerability, and possible effects. A single risk factor may be enough where potential harm is serious.

are the organisation's primary objectives, not ordinary support functions such as its own payroll. The same processing may be core for a service provider. A health insurer's large-scale health-data processing or a large service's continuous behavioural tracking can trigger a appointment; an individual clinician's patient records ordinarily do not amount to .

High-risk screening must cover the operation as a whole. Examples that may require closer assessment include combining datasets from different sources, invisible processing, tracking location or behaviour, biometric identification, processing about children or other vulnerable people, and using new technology to make decisions that deny a service. An example is not an automatic result unless the statutory or ICO high-risk test is met on the facts.

  • Review the project again if the purpose, scale, data categories, or recipients change.
  • Use the early, before processing starts, and update it when the risk changes.
  • Consult the ICO if the shows a high risk that you cannot mitigate.
  • Make sure the can perform their tasks independently and has adequate resources.
  • If the screening does not require a , record why; doing one may still be appropriate for a major or uncertain use of personal data.
  • Check separate DPA 2018 regimes for law-enforcement or intelligence-services processing rather than assuming the UK GDPR test controls.
Section 4

How should teams run DPIAs and support the DPO?

Start the while the project is still being designed. Describe what the processing does, why it is needed, what risks it creates, and what controls reduce those risks. If the remaining risk is still high, stop and consult the ICO before starting processing. Article 36 gives the ICO up to eight weeks to provide written advice, extendable by six weeks for complexity; the clock can be suspended while requested information is outstanding.

If you must appoint a , involve the DPO early, publish and notify the contact details, provide resources and access, protect independence, ensure direct access to the highest management level, and prevent conflicting duties. The DPO may be an employee, an external provider, or shared where the role remains effective and accessible.

  • Use a plain-English template that covers purpose, necessity, proportionality, risks, and mitigation.
  • Document why the project needs a or, if not, why it does not.
  • Keep a review schedule and reopen the when the project changes.
  • List the 's contact details in privacy information and relevant records.
  • Treat the as an adviser and monitor, not as the owner of the processing decision.
  • Reopen the when the nature, scope, context, purposes, technology, recipients, or risk changes.
Primary sources

References and citations

Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR Lawful Bases Guide
Choose among the six familiar Article 6 bases and the UK's recognised legitimate interests basis, then document any Article 9 or 10 condition.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.