A Data Protection Impact Assessment (DPIA) is required under UK GDPR Article 35 when processing is "likely to result in a high risk" to individuals. Failing to conduct a mandatory DPIA can result in ICO enforcement action and fines.
A DPIA should also be conducted if your processing meets two or more of the following ICO criteria:
There is no fixed threshold. The ICO considers: the number of data subjects, the volume of data, the geographical extent, and the duration of processing. An NHS Trust processing patient data for a catchment area of 500,000 people is clearly large scale. A sole trader's client list of 200 names is not.
Run the DPIA Screening wizard in Folelse (Dashboard → DPIAs → New DPIA) to automatically score your processing against these 9 criteria and get a recommendation on whether a full DPIA is needed.
Need more help with this?
Contact support