Data Protection Impact Assessment (DPIA) Template for UK GDPR
A Data Protection Impact Assessment (DPIA) is a structured risk assessment completed before any use of personal data that could seriously affect people. Article 35(1) of the UK GDPR requires one wherever processing is “likely to result in a high risk to the rights and freedoms” of individuals. The DPIA template for UK GDPR on this page turns that duty into a working document: what you plan to do with the data, why, what could go wrong for the people involved, and how you will reduce the risk.
The document does two jobs. It is your accountability evidence — the ICO warns that failing to carry out a DPIA when required can mean a fine of up to £8.7 million, or 2% of global annual turnover if that is higher. Its conclusion also decides whether you may proceed: where a high residual risk remains that you cannot reduce, Article 36 of the UK GDPR obliges you to consult the ICO before processing begins.
The access-to-a-service trigger
Start your screening with one item from the ICO’s own list of operations that require a DPIA, published as Article 35(4) requires: decisions about someone’s access to a product, service, opportunity or benefit that rest to any extent on automated decision-making, or that involve special category data. The rest of the ICO’s list, and the three types of processing that always require a DPIA, are set out below.
When you need a DPIA
The test is a screening one: you are looking for features pointing to potential high risk, not proof of harm. Article 35(3) names three types of processing that always require a DPIA:
- Profiling with significant effects — systematic and extensive automated evaluation, including profiling, on which decisions are based that produce legal or similarly significant effects — automated credit scoring, for example.
- Large-scale sensitive data — special category data (Article 9(1)) or criminal offence data (Article 10) processed on a large scale, such as a hospital’s patient records.
- Systematic public monitoring — monitoring a publicly accessible area on a large scale; town-centre CCTV is the classic case.
Alongside those three, the ICO’s list adds ten operations:
- innovative technology, including AI, and novel applications of existing technology;
- decisions about access to a product, service, opportunity or benefit — the trigger set out above;
- profiling of individuals on a large scale;
- biometric data;
- genetic data, outside direct care given by an individual health professional;
- combining, comparing or matching personal data obtained from multiple sources;
- invisible processing — data obtained from someone other than the individual, where you judge that telling them would be impossible or a disproportionate effort;
- tracking someone’s geolocation or behaviour, online or offline;
- using the data of children or other vulnerable people for marketing, profiling or automated decisions, or offering online services directly to children;
- processing where a breach could jeopardise physical health or safety.
Some of these require a DPIA on their own; others only when they occur alongside another item on the list, or one of the European guideline criteria the ICO points to. Check the ICO’s current list rather than relying on this summary.
Our free hybrid and remote working policy template covers homeworking arrangements.
There are limited exceptions. You may not need a DPIA where you have already done a substantially similar one, or where the processing rests on a legal obligation or public task and a data protection risk assessment was carried out when that legislation was adopted. Where that is not clear, the ICO’s advice is to err on the side of caution and do the DPIA.
What a DPIA template should cover
Eight sections map the ICO’s seven-step process onto a working document:
- Screening record — why a DPIA is needed, or your documented reasons for deciding it is not.
- Description of the processing — nature, scope, context and purposes: collection, storage, access, sharing, retention, any new technology.
- Consultation record — the views of the people affected and any processors; if you skip consulting individuals, record why.
- Necessity and proportionality — your lawful basis, whether a less intrusive route exists, how you enforce data minimisation.
- Risk assessment — likelihood and severity of harm to individuals: discrimination, financial loss, physical harm, loss of control over their data protection rights.
- Mitigation measures — for each risk, the step that reduces it: collecting less, shorter retention, pseudonymisation, a proper data processing agreement with any processor.
- Residual risk and sign-off — whether each risk is eliminated, reduced or accepted; high residual risk is what triggers the Article 36 consultation duty. If you have a Data Protection Officer you must seek their advice and record it, along with your reasons if you do not follow it.
- Review triggers — the changes in scope, purpose or technology that mean revisiting the assessment.
Common mistakes
- Writing it after the system is built. The duty is to assess before processing starts, while the design can still change.
- Proceeding despite unmitigated high risk. Consulting the ICO first is not optional — the ICO is clear you cannot go ahead until you have.
- Not recording the decision not to do one. An undocumented screening decision is indistinguishable from no decision.
- Assessing only privacy harm. Physical, material and non-material harm all count, not just confidentiality.
- Filing it away. If the project changes shape and the assessment does not, it stops protecting you.
England & Wales, Scotland and Northern Ireland
Data protection is not devolved law that changes at the UK’s internal borders. The GDPR was retained in UK law as the UK GDPR and is read alongside the Data Protection Act 2018, and the ICO is the UK’s data protection regulator, so the DPIA duty and the Article 36 consultation route work the same way in England and Wales, in Scotland and in Northern Ireland. There is no separate Scottish or Northern Irish DPIA regime to complete instead. Organisations also serving people in the EU may face separate impact-assessment duties under the EU’s own GDPR, owed to an EU supervisory authority — that is outside this page’s scope.
Frequently asked questions
Is a DPIA a legal requirement in the UK?
Yes, where processing is likely to result in a high risk to individuals — Article 35(1) of the UK GDPR. The ICO warns that failing to do one when required can mean a fine of up to £8.7 million, or 2% of global annual turnover if that is higher.
When must I consult the ICO before processing?
When your completed DPIA identifies a high risk you cannot reduce. The ICO says it will write within 10 days to confirm whether it has accepted the DPIA, and gives written advice within eight weeks of receiving it, extendable to a maximum of 14 weeks in complex cases.
Do I need a DPIA before deploying AI tools?
Often. The ICO’s list names innovative technology, including AI, and calls for a DPIA where it is combined with one of the European guideline criteria — and AI projects frequently involve profiling or automated decisions that require one in their own right.
Is there an official ICO DPIA template I have to use?
No. The ICO publishes a sample you can use or adapt, and says you can make your own as long as it covers all the key elements of the process. Ours follows the same seven steps, as a starting point for you to adapt and check against the ICO’s current guidance.
Has the Data (Use and Access) Act changed the DPIA rules?
The ICO’s DPIA guidance currently carries a notice that it is under review following that Act, so check the ICO’s pages for the current position before relying on fine detail.
Statutory references on this page were checked against primary sources (legislation.gov.uk, GOV.UK, HSE, ICO and Acas) on 8 August 2026. Our templates themselves are not solicitor-drafted — see the note below.
This page is legal information, not legal advice.
Dogetlawyer is a Legal-Technology platform, not a law firm.
Our templates are not solicitor-drafted and have not been checked against primary sources. They are starting points to adapt, not finished documents.
This page describes the law of England and Wales unless it says otherwise. For anything significant, consider taking advice from a qualified professional.
Get the DPIA template
This template is one of around 114 free UK legal templates on Dogetlawyer. Browse every title on the free A–Z template index without signing in; downloading needs a free account — registration, not payment. A privacy policy template and a website terms and conditions template sit in the same library.