- ICO process for screening, assessment, measures, prior consultation, implementation, and review.
References and citations
- ICO operational requirements for appointing, supporting, and documenting a DPO.
- Binding Articles 35, 36, and 37 to 39.
A DPIA helps you identify and minimise the data protection risks of a project. A DPO is the person who advises, monitors compliance, and supports your organisation's UK GDPR obligations where appointment is required.
A DPIA and a DPO solve different problems. The controller or processor remains responsible for compliance; a DPO advises and monitors without owning the processing decision.
Structured answer sets in this page tree.
Cited legal and guidance references.
Complete a before processing likely to result in a high risk to people's rights and freedoms. Consult the ICO before starting if measures cannot reduce the residual high risk. Separately, appoint a if Article 37 applies to the organisation's status or . A project may need a DPIA even where no DPO is required, and appointing a DPO does not transfer the controller's or processor's responsibility.
A is a process for identifying and minimising the data protection risks of a project. Under the UK GDPR, you must do one before processing that is likely to result in a high risk to individuals, including some specified types of processing such as systematic and extensive profiling with significant effects, large-scale processing of special category or criminal offence data, or systematic monitoring of a publicly accessible area on a .
Screen before design choices become fixed. Consider the processing's nature, scope, context, purposes, use of new technology, likelihood of harm, and severity of possible harm. The three Article 35 examples are not the only triggers; the ICO's published high-risk list and relevant combinations of risk factors also matter.
A is required for a public authority or body, except a court acting in its judicial capacity, or where require large-scale regular and systematic monitoring, or large-scale processing of special category or criminal-offence data. These appointment duties apply to controllers and processors.
The controller owns the decision and is responsible for carrying it out. The , where one is appointed, advises, monitors compliance, and supports the assessment but does not replace the controller's responsibility.
The must describe the processing and purposes, assess necessity and proportionality, assess risks to people's rights and freedoms, and state the measures that address those risks and demonstrate compliance. Seek the 's advice where one is appointed, consider consulting affected people or their representatives where appropriate, and record disagreements and sign-off.
For appointment, record the applicable Article 37 trigger or the reason no trigger applies. If the appointment is voluntary, the Article 37 to 39 requirements still apply to the role. Publish the DPO's contact details and communicate them to the ICO; the public contact details do not have to include the person's name.
A mandatory or voluntary must report to the highest management level, work independently, receive adequate resources and access, and avoid conflicting duties. A role that decides the purposes and means of processing, often a senior operational, finance, HR, IT, or marketing post, may conflict with the DPO's monitoring function; assess the person's actual authority rather than the job title alone.
New technology alone does not automatically require a , and there is no fixed numerical definition of . Assess the number of people, data volume and range, geographical extent, duration or permanence, monitoring frequency, vulnerability, and possible effects. A single risk factor may be enough where potential harm is serious.
are the organisation's primary objectives, not ordinary support functions such as its own payroll. The same processing may be core for a service provider. A health insurer's large-scale health-data processing or a large service's continuous behavioural tracking can trigger a appointment; an individual clinician's patient records ordinarily do not amount to .
High-risk screening must cover the operation as a whole. Examples that may require closer assessment include combining datasets from different sources, invisible processing, tracking location or behaviour, biometric identification, processing about children or other vulnerable people, and using new technology to make decisions that deny a service. An example is not an automatic result unless the statutory or ICO high-risk test is met on the facts.
Start the while the project is still being designed. Describe what the processing does, why it is needed, what risks it creates, and what controls reduce those risks. If the remaining risk is still high, stop and consult the ICO before starting processing. Article 36 gives the ICO up to eight weeks to provide written advice, extendable by six weeks for complexity; the clock can be suspended while requested information is outstanding.
If you must appoint a , involve the DPO early, publish and notify the contact details, provide resources and access, protect independence, ensure direct access to the highest management level, and prevent conflicting duties. The DPO may be an employee, an external provider, or shared where the role remains effective and accessible.
Screen before design is fixed, complete and approve the DPIA before high-risk processing starts, consult the ICO where residual high risk remains, and document an independent DPO arrangement where Article 37 applies.
Turn DPIAs and DPOs into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.