SecurSentry
← All notes
UK GDPR

Do I Need a DPIA? A Small Business Guide to Data Protection Impact Assessments

You've come across the term 'DPIA' and want to know whether it applies to you. Here is what it is, when the law requires one, and why most ordinary small-business processing doesn't trigger it.

The short version

If you have come across ‘DPIA’ in a supplier form, a framework checklist, or a worried email and you are wondering whether it applies to your business, this is the right question to ask first. A data protection impact assessment is one of those terms that sounds heavyweight and audit-shaped, when it is really just a structured way of thinking through the risks of a project before you commit to it. Most small businesses doing ordinary work do not need one. But a few specific activities make it a legal requirement, and the honest answer depends on what you are actually doing with people’s data.

What a DPIA actually is

A DPIA is a structured process to identify and reduce the data-protection risks of a specific project before you start it.

The Information Commissioner’s Office (the ICO, the UK’s data protection regulator) describes a DPIA as a way to assess and minimise the risks of a processing activity. The key word is specific. A DPIA is not a one-off form you fill in for the whole business and file away. It attaches to a particular thing you are about to do: launching a new app, installing monitoring software, adopting an AI tool, building a large new database.

Done properly, it walks through a project methodically: what data you’ll process, why, who it affects, what could go wrong for those people, and what you’ll do to lower each risk. The point is to surface problems while they are still cheap to fix, on paper, rather than after you’ve built and launched something.

Two things follow from that. First, the timing matters. A DPIA belongs at the start of a project, while you can still change the design. Doing one after launch is closing the stable door. Second, it scales. The ICO is explicit that a DPIA does not have to be a long or expensive exercise. For a small project the assessment can be short and proportionate. The size of the paperwork should match the size of the risk.

When a DPIA is legally required

A DPIA is mandatory under Article 35 of the UK GDPR before any processing that is ‘likely to result in a high risk’ to people’s rights and freedoms.

That phrase, ‘likely to result in a high risk’, is the legal threshold. Below it, a DPIA is good practice but not compulsory. Above it, it is required by law before you start.

To make that less abstract, Article 35 names three types of processing that always require a DPIA:

The ICO goes further than the three statutory triggers. It publishes its own list of processing that is likely to need a DPIA, including using innovative technology, large-scale profiling, data matching, biometric or genetic data, invisible processing (where people don’t know you hold their data), tracking someone’s location or behaviour, targeting children or other vulnerable people, and using AI to make decisions about individuals. If your project lands on that list, treat a DPIA as required.

THE SME EXAMPLES THAT ACTUALLY MATTER

For a small business, the realistic triggers are narrow: bringing in software that monitors employees in a meaningful way, large-scale tracking of customers' behaviour or location, or adopting an AI tool that makes or shapes decisions about real people. If you are doing one of those, screen it carefully. If you want the wider context first, start with our guide to GDPR for small businesses.

Why most small businesses don’t need one

Everyday processing — a customer list, normal marketing, payroll — is not high-risk and does not require a DPIA.

Here is the reassurance, and it is genuine. The vast majority of small businesses run on ordinary, low-risk processing. Keeping a list of customers and their contact details, sending marketing emails to people who’ve opted in, running payroll, handling supplier invoices: none of that meets the high-risk threshold, and none of it needs a DPIA.

The mistake is to swing the other way and decide DPIAs are irrelevant to you forever. They are project-triggered, not business-triggered. The business that never needs one for years can suddenly need one the day it decides to install keystroke-logging software or plug an AI screening tool into its hiring.

So the right habit is not ‘do a DPIA’ or ‘ignore DPIAs’. It is screen new projects. Before you start something that involves people’s data in a new or bigger way, ask the screening question: does this have features that point to high risk? The ICO publishes screening checklists you can use or adapt for exactly this. If you screen a project and conclude no DPIA is needed, it’s worth keeping a short note of that decision and why, so you can show you thought about it.

A DPIA isn’t a tax on growth. It’s the difference between finding out a project is risky on a one-page form, and finding out from an angry customer or a regulator’s letter.

And when you genuinely can’t tell? The ICO’s own advice is unambiguous: if you are in any doubt, do a DPIA. A short, proportionate assessment costs you an afternoon. Getting a risky project wrong costs a great deal more. Doing one when you didn’t strictly have to is never the thing that gets a business in trouble.

The step you can’t skip: consulting the ICO

If your DPIA finds a high risk you cannot reduce, you must consult the ICO before you go ahead.

This is the part people miss, and it changes how seriously a DPIA should be taken. A DPIA is not just an internal tick-box. If, after you’ve added every mitigation you reasonably can, the project still carries a high residual risk, the law requires you to consult the ICO before starting. This is called prior consultation, and it sits in Article 36 of the UK GDPR.

The detail to get right is ‘residual’. You only have to consult if the risk is still high after your mitigations. If your DPIA found a high risk but the measures you’ve put in place bring it down to an acceptable level, you don’t need to consult anyone, you just proceed with your safeguards in place. It is the risk you can’t design away that triggers the conversation.

And you cannot start the processing while you wait. When the ICO is consulted this way, it aims to respond within eight weeks, extendable to fourteen in complex cases. So a project that runs into this is a project to plan early. The realistic takeaway for most small businesses: if you ever get to the point of consulting the ICO, that is a strong signal the project needs serious, probably professional, attention before it goes live.

AI: the modern reason a DPIA matters

Using AI to make or materially inform decisions about people can be exactly the kind of high-risk processing that requires a DPIA.

A few years ago, DPIAs were mostly a concern for organisations running CCTV or big sensitive databases. AI has changed that, and it is the single most likely reason a small business today crosses the threshold.

The ICO explicitly lists the use of AI, machine learning, and automated decision-making about individuals among the activities likely to need a DPIA. The reasoning is straightforward: when a system makes or shapes a decision about a real person, perhaps screening a job application, scoring a customer, flagging behaviour, the stakes for that person are high, and the workings are often hard to see or explain. That combination is what ‘high risk’ is built to catch.

This matters because adopting AI feels easy. You sign up to a tool, paste in some data, and it produces an answer. The data-protection weight of that decision is invisible at the point you make it. If the AI is touching people, particularly making or strongly influencing decisions about them, a DPIA is how you make the risk visible before it becomes a problem. We’ve written more on where that responsibility sits in the legal responsibilities of using AI tools in a small business.

A DPIA also leans on knowing what data you actually process in the first place. If you don’t yet have a clear picture of the personal data flowing through your business, that record is the foundation everything else stands on, and it’s worth building before you tackle anything as project-specific as a DPIA. Our guide to keeping a record of processing activities is the place to start.

So, do you need a DPIA? For your day-to-day, almost certainly not. For the next ambitious project, the new monitoring tool, the AI you’re about to wire into a decision, the answer is: screen it honestly, and if there’s any real chance of high risk, do the assessment. It is the cheapest insurance you’ll buy all year.

SecurSentry is launching soon to help UK SMEs build practical, evidence-backed data protection, including knowing when a project needs a DPIA and screening new work before it goes live. Join the waitlist to be first to know when we open.


This article is general information, not legal or compliance advice. If you are planning high-risk processing, or you’re unsure whether a DPIA applies to your project, seek qualified guidance from a data protection professional or solicitor.

Frequently asked questions

Do I need a DPIA for my small business?

Probably not for your everyday processing. A customer database, ordinary email marketing, and payroll are not high-risk activities and do not require a DPIA. You only need one before processing that is likely to result in a high risk to people, such as significant employee monitoring, large-scale tracking, or using AI to make decisions about individuals. The safe habit is to screen each new project rather than assume.

When is a DPIA legally required under UK GDPR?

A DPIA is mandatory under Article 35 of the UK GDPR before any processing that is likely to result in a high risk to people's rights and freedoms. The law sets out three automatic triggers: systematic and extensive automated evaluation or profiling that significantly affects people; large-scale processing of special-category data (such as health or biometric data) or criminal-offence data; and systematic monitoring of a publicly accessible area on a large scale. The ICO also publishes a list of other activities that need one.

What happens if a DPIA shows a high risk I can't reduce?

If your DPIA identifies a high risk and you cannot take measures to reduce it, you must consult the ICO before you start the processing. This is called prior consultation, set out in Article 36. You cannot go ahead until the ICO responds. If your mitigations bring the risk down so it is no longer high, you do not need to consult them.

Does using AI mean I need a DPIA?

Not automatically, but often yes if the AI affects people. The ICO lists the use of AI, machine learning, and automated decision-making about individuals among the activities likely to need a DPIA. Using an AI tool to make or materially inform decisions about customers, applicants, or staff is the kind of processing you should screen carefully and, in most cases, document a DPIA for.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

Cyber Essentials

How to Get ISO 27001 Certified: The Process, Step by Step

21 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Risk Assessment, Without Overcomplicating It

18 Aug 2026 · 9 min
Cyber Essentials

ISO 27001 Annex A Controls, in Plain English

14 Aug 2026 · 8 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.