UK data protection impact assessments: the retained Article 35, section 64 of the Data Protection Act 2018, and the ICO's screening rules
What the UK GDPR kept, what the ICO added — ten listed operations, a screening checklist and a seven-step process — how prior consultation with the ICO actually runs, the separate law-enforcement regime in Part 3, what the Data (Use and Access) Act 2025 did and did not change, and where each element lives in AccessPoint. For data protection officers, information governance leads and the service managers who need an assessment before a system goes live.
Article 35 of the UK GDPR, as retained and amended from 31 December 2020, requires a data protection impact assessment before any processing likely to result in a high risk to individuals, names three cases where one is always required, and makes the Information Commissioner responsible for the list of further operations that need one. The ICO's list has ten entries, its screening checklist folds in the nine WP248 criteria, and its process guidance sets seven steps. Where residual risk stays high, Article 36 requires prior consultation with the ICO, which gives written advice within eight weeks, extendable to 14. Law-enforcement processing runs on section 64 of the Data Protection Act 2018 with a six-week consultation clock in section 65. The Data (Use and Access) Act 2025 left all of those provisions unamended.
The United Kingdom kept the GDPR's DPIA machinery almost word for word: the EU Exit regulations of 2019 substituted “the Commissioner” for the supervisory authority, dropped the paragraphs that only made sense inside the Union's consistency mechanism, and left the substance alone. A UK public authority therefore works with three layers: the retained Article 35 and 36 text, the ICO's guidance and Article 35(4) list, and, for police forces and other competent authorities, the parallel duty in Part 3 of the Data Protection Act 2018.
The retained text: Articles 35 and 36 of the UK GDPR
Article 35(1) is unchanged: where a type of processing, “in particular using new technologies,” is likely to result in a high risk to the rights and freedoms of natural persons, the controller must, prior to the processing, assess its impact on the protection of personal data. Article 35(3) keeps the three automatic cases: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, with legal or similarly significant effects; large-scale processing of Article 9(1) special categories or Article 10 criminal-conviction data; and systematic monitoring of a publicly accessible area on a large scale.
The UK-specific edits are in the lists and the exemption. Under 35(4) “the Commissioner shall establish and make public a list” of operations that require a DPIA, under 35(5) may publish a list of operations that do not, and paragraph 6, the consistency mechanism, is omitted. Paragraph 10 refers to a DPIA already carried out “as part of a general impact assessment required by domestic law” for processing under Article 6(1)(c) or (e). The rest stands: the DPO's advice under 35(2), the four minimum contents in 35(7), data subjects' views where appropriate under 35(9), and the 35(11) review at least when the risk changes.
Article 36 keeps the duty in 36(1) and the clock in 36(2): written advice “within period of up to eight weeks of receipt of the request,” an extension of six weeks for complex processing, notice of the extension with reasons within one month, and suspension until requested information arrives. Paragraph 4 is rewritten for the devolved settlement: a “relevant authority” — the Secretary of State, the Welsh Ministers, the Scottish Ministers or a Northern Ireland department under new paragraph 4A — must consult the Commissioner while preparing a legislative measure for Parliament, the Senedd, the Scottish Parliament or the Northern Ireland Assembly that relates to processing. Paragraph 5, which let Member State law require prior authorisation, is omitted.
Screening: three automatic cases, ten listed operations, nine criteria
The ICO describes the “likely to result in a high risk” question as a screening test, not the assessment itself: “are there features which point to the potential for high risk?” Article 35(3) supplies the three automatic cases; the ICO's Article 35(4) list, which “complements and further specifies” the European guidelines and which the European Data Protection Board reviewed in Opinion 22/2018, supplies ten more; and the nine WP248 criteria supply the indicators for everything else.
| ICO list entry | What it covers | DPIA required |
|---|---|---|
| Innovative technology | New technologies or the novel application of existing ones, including AI | With another WP248 criterion |
| Denial of service | Decisions about access to a product, service, opportunity or benefit based to any extent on automated decision-making or involving special-category data | Always |
| Large-scale profiling | Any profiling of individuals on a large scale | Always |
| Biometrics | Any processing of biometric data to uniquely identify an individual | With another WP248 criterion |
| Genetic data | Any processing of genetic data, other than by an individual GP or health professional caring directly for the patient | With another WP248 criterion |
| Data matching | Combining, comparing or matching personal data from multiple sources | Always |
| Invisible processing | Data not obtained from the individual where the controller relies on Article 14(5)(b) not to provide privacy information | With another WP248 criterion |
| Tracking | Tracking an individual's geolocation or behaviour, online or offline | With another WP248 criterion |
| Targeting of children or other vulnerable individuals | Their data used for marketing, profiling or automated decision-making, or online services offered directly to children | Always |
| Risk of physical harm | Processing where a personal data breach could jeopardise the physical health or safety of individuals | Always |
The nine WP248 criteria are evaluation or scoring; automated decision-making with legal or similar significant effect; systematic monitoring; sensitive data or data of a highly personal nature; large-scale processing; matching or combining datasets; data concerning vulnerable data subjects; innovative use or new technological or organisational solutions; and processing that prevents data subjects from exercising a right or using a service or contract. The ICO restates the rule of thumb and loosens it: “In most cases, a combination of two of these factors indicates the need for a DPIA. However, this is not a strict rule.” You may justify not doing one if you are confident the processing is unlikely to result in a high risk, but you should document your reasons, and one factor alone may be enough. The ICO's screening checklist ends with the two lines that make a programme auditable: “We carry out a new DPIA if there is a change to the nature, scope, context or purposes of our processing,” and “If we decide not to carry out a DPIA, we document our reasons.”
Two ICO definitions matter for public services. Large scale turns on the number of individuals, the volume and variety of data, the duration and the geographical extent; a hospital is large scale, an individual doctor is not, and “tracking individuals using a city's public transport system” is the ICO's own example. Vulnerable individuals include children, elderly people, those with certain disabilities and anyone in a power imbalance with the controller, which the ICO says can include employees.
The ICO's seven steps
The ICO's process guidance is flexible — your own project or risk method will do “as long as it contains these key elements” — and offers a sample DPIA template to use or adapt. The steps are: identify the need for a DPIA; describe the processing; consider consultation; assess necessity and proportionality; identify and assess risks; identify measures to mitigate the risks; and sign off and record outcomes. Four points of detail decide whether the result survives an audit.
- Describe by nature, scope, context and purpose: how data are collected, stored, used, shared and retained, who has access, any processors or new technology, which screening criteria were flagged, and the individuals' relationship with you, their expectations and any vulnerability.
- Consult, or record why not. Seek and document the views of individuals or their representatives “unless there is a good reason not to,” and record the reasons if your decision differs from theirs. Ask processors to assist and involve information security staff.
- The DPO's advice is a recorded step. You must seek it on whether a DPIA is needed, how to do it, the measures, whether it was done correctly and whether the processing can go ahead; record the advice, and your reasons if you do not follow it. The DPO also monitors the DPIA's ongoing performance.
- Assess risk objectively, then decide the residual risk. The ICO lists the harms to look for, from inability to exercise rights through discrimination and financial loss to physical harm, and recommends a structured likelihood-and-severity matrix. At sign-off you record the additional measures, whether each risk is eliminated, reduced or accepted, the overall residual risk and whether you need to consult the ICO, then keep the DPIA under review.
On publication the ICO says it is good practice, with redaction or a summary where detail is sensitive, and adds that public authorities “should think about their wider transparency obligations, such as complying with the Freedom of Information Act.”
Prior consultation as the ICO runs it
The trigger is Article 36(1): a DPIA that identifies a high risk you cannot reduce. The ICO is direct: “You cannot go ahead with the processing until you have consulted us.” The submission goes to the ICO's DPIA consultation mailbox (dpiaconsultation@ico.org.uk) with the Article 36(3) contents: the roles of any joint controllers or processors, the purposes and methods, the measures and safeguards, the DPO's contact details and a copy of the DPIA. The ICO then:
- writes within 10 days to say whether it has accepted the DPIA for prior consultation, with reasons;
- assesses the whole submission, including how far compliance with the principles is evidenced, and may ask for more information, during which the assessment cannot continue;
- provides written advice within eight weeks of receipt, extendable in complex cases to a maximum of 14 weeks, telling you within one month if it needs to extend; and
- concludes with a view that the risks are sufficiently mitigated, advice on further mitigation, an official warning where the processing is likely to contravene the UK GDPR, or a limitation or ban on the intended processing.
Warnings are not subject to appeal, though judicial review is available; a limitation or ban can be appealed to the First-tier Tribunal. Include every document the assessment refers to, such as privacy notices, so the clock is not suspended for want of them.
Law-enforcement processing: section 64 of the Data Protection Act 2018
Processing by a competent authority for law-enforcement purposes sits outside the UK GDPR in Part 3 of the Data Protection Act 2018. Section 30 defines a competent authority as a person specified in Schedule 7 or any other person to the extent that they have statutory functions for the law-enforcement purposes; intelligence services are excluded. Section 64 is Part 3's DPIA duty:
- 64(1) — where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, the controller must, prior to the processing, carry out a data protection impact assessment;
- 64(3) — it must include a general description of the envisaged processing operations; an assessment of the risks to the rights and freedoms of data subjects; the measures envisaged to address those risks; and safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with Part 3;
- 64(4) — in deciding whether processing is likely to result in a high risk, the controller must take into account its nature, scope, context and purposes.
Section 65 is the Part 3 consultation duty, with a different clock. It applies where a controller intends to create a filing system and process personal data forming part of it: where the section 64 assessment indicates a high risk in the absence of mitigating measures, the controller must consult the Commissioner before processing, and where the Commissioner considers the processing would infringe Part 3, written advice must be given before the end of six weeks from receipt, extendable by a further month for complexity, with notice within the first month. The ICO's Guide to Law Enforcement Processing restates the rule with a worked example of a police force assessing a drone system before purchase. A force or prosecutor therefore runs two regimes in one office: Article 35 for its general processing, section 64 for its operational processing.
What the Data (Use and Access) Act 2025 changed, and did not
The Act received Royal Assent on 19 June 2025 and, under section 142, comes into force mainly by commencement regulations. It did not amend Article 35 or 36 of the UK GDPR, or section 64 or 65 of the Data Protection Act 2018; the only amendments recorded against those provisions on legislation.gov.uk are the 2019 EU Exit substitutions and one prospective change below. The Act's own “impact assessment” provision, section 93, concerns the Commissioner's codes of practice, not a controller duty. What did change sits around the DPIA:
- Automated decision-making. Section 80 replaced the Article 22 regime with Articles 22A to 22D and came into force on 5 February 2026 under the Commencement No. 6 Regulations (S.I. 2026/82). Article 35(3)(a) and the ICO's “denial of service” entry both turn on automated decisions with significant effects, so the ADM inventory and the DPIA screener should be read together.
- Complaints procedure. Section 103 requires controllers to facilitate complaints from data subjects and came into force on 19 June 2026 under the same regulations.
- The Information Commission. Section 117, establishing the Commission, was commenced on 20 August 2025 by the Commencement No. 1 Regulations (S.I. 2025/904), except section 117(4)(a). Sections 118 and 119, which abolish the office of Information Commissioner and transfer its functions, were not in force as of 5 September 2026. S.I. 2026/386 will substitute “the Commission” for “the Commissioner” in Article 35(4) and (5), Article 36, Article 83 and section 65, but under regulation 1(2) only when section 119 is fully brought into force. Until then the ICO's DPIA process is unchanged.
Penalties
Article 83(4)(a) of the UK GDPR places the controller's obligations under Articles 25 to 39 — Articles 35 and 36 among them — in the tier fined up to £8,700,000 or, for an undertaking, 2% of total worldwide annual turnover, whichever is higher; section 157(6) of the Data Protection Act 2018 calls that the “standard maximum amount.” The ICO's guidance says that “failure to carry out a DPIA when required may leave you open to enforcement action, including a fine of up to £8.7 million, or 2% global annual turnover if higher.” The “higher maximum amount” of £17,500,000 or 4% in section 157(5) applies to the principles, lawful bases and data-subject rights. Nothing in the UK text mirrors the EU's Article 83(7) discretion to exempt public authorities, and the corrective powers, including a limitation or ban on processing, apply in any case.
Building the programme
- Inventory the processing first. The listed operations — data matching, large-scale profiling, tracking — usually live in what already runs, not in new projects.
- Build the screener from the ICO's checklist. Its “We always carry out a DPIA if we plan to” items are the listed operations and automatic cases in plain language; its “We consider whether to do a DPIA” items are the nine criteria. Record the determination either way.
- Use the ICO's template or map yours to its seven steps, checked against Annex 2 of WP248 rev.01.
- Make the DPO's advice and the individuals' views dated entries with the decision taken on each.
- Score risks, decide each risk's fate and state the residual risk; if it is still high, open the prior-consultation file with the Article 36(3) contents and plan for 14 weeks. Track every measure to completion.
- Competent authorities: run section 64 as its own assessment type, with the section 64(3) contents and the six-week section 65 clock.
How AccessPoint runs it
AccessPoint's United Kingdom packs carry the regimes separately. The UK GDPR and Data Protection Act 2018 pack ships subject access on the one-calendar-month clock, the Schedule 2 and 3 exemptions, personal-data-breach handling on the ICO's 72-hour clock and DPIAs, with the ICO as the oversight body; the DPA 2018 Part 3 pack, for police forces, prosecutors and other competent authorities, carries section 45 subject access, sensitive-processing policy documents, section 62 logging and 72-hour breach notification; and the Freedom of Information Act 2000 pack sits beside them for the same office's FOI work. Templates are pack-maintained and versioned, the UK DPIA template was rebuilt against the ICO's own published template in the August 2026 template programme, and each assessment runs on a derived copy, so a later template version never rewrites an approved record.
The screening checklist as a screener
A template can carry a preliminary screener with yes/no and choice questions and guidance on each; every question must be answered, a “screened out” result produces a lightweight compliance record with no sections, and anything else instantiates the full section set.
Seven steps, typed answers
Sections carry free-text, yes/no, choice, date, number, attachment, finding and table questions, with an information-flow diagram question on templates that carry one. Answers bound to the privacy subject fill empty fields on its record of processing on approval and queue the rest as proposals a person applies once the assessment is In Effect.
Delegation to the service
Any section can be assigned to a service expert who sees only that section, answers with autosave, logs hours and attaches documents, then submits for the coordinator to approve or return with a note. Delegates work only within their assigned section and see no requestor personal information.
Risks scored the way the ICO draws them
A five-point likelihood-and-impact register with inherent and residual scores, a harm-to-individuals determination, avoid-reduce-transfer-accept treatments, acceptances that need an approver, an expiry and a justification when over appetite, key risk indicators, and controls from the controls library.
Sign-off, consultation and review
A configurable review stepper moves the assessment to In Effect, and the DPO's advice and the senior official's sign-off can each be a recorded step; key dates carry a submitted-to-regulator date, and the closure tab keeps an append-only regulator consultation log whose first Submitted entry stamps it. Approved assessments are read-only, and a change to the subject's recorded purpose pulls the reassessment date forward onto My Day.
Publication and the Commissioner's copy
The closure tab generates the regulator summary as a document beside executive and publication summaries suited to a publication scheme, and the assessment's documents, activity trail and approvals export together. A deterministic case check flags a screener not run, an overdue reassessment, risks without an owner or mitigation, expired acceptances and overdue commitments.
Breach response runs beside it: the notification checklist is computed from the governing authority, so a UK GDPR incident shows the ICO obligation with its 72-hour due date and required contents, and a risk that materialises records the incident that realised it. Everything runs inside your own Microsoft 365 and Azure tenant, with the database in your Azure SQL and case documents in your own Blob Storage; the apps are distributed through Microsoft AppSource, where they are reviewed and tested by Microsoft.
A readiness checklist
- Confirm which regime each activity falls under: UK GDPR Article 35, or Part 3 section 64 for law-enforcement purposes by a competent authority.
- Build the screener from Article 35(3), the ICO's ten listed operations and the nine WP248 criteria, and record every determination with reasons.
- Adopt the ICO's sample template or map your own to the seven steps and to Article 35(7).
- Record the DPO's advice and your decision on it; record individuals' views or the reasons they were not sought.
- Cross-check the ADM inventory against the DPIA screener now that Articles 22A to 22D are in force.
- Give every mitigating measure an owner and a date, and every accepted risk an approver and an expiry.
- Write the prior-consultation procedure: the residual-risk decision, the Article 36(3) contents, the 10-day acceptance letter and a 14-week horizon; six weeks plus one month under section 65.
- Decide the publication position with the FOI publication scheme in mind, set a review date on approval, and note that nothing changes procedurally until section 119 is commenced and S.I. 2026/386 takes effect.
Sources
- UK GDPR, Article 35 (Data protection impact assessment), Article 36 (Prior consultation) and Article 83 (General conditions for imposing administrative fines), as retained and amended by S.I. 2019/419 with effect from 31 December 2020 — legislation.gov.uk (accessed September 4, 2026).
- Data Protection Act 2018, s. 30 (Meaning of “competent authority”), s. 64 (Data protection impact assessment), s. 65 (Prior consultation with the Commissioner) and s. 157 (Maximum amount of penalty) — legislation.gov.uk (accessed September 4, 2026).
- Data (Use and Access) Act 2025, c. 18 (Royal Assent 19 June 2025), including s. 80, s. 93, s. 103, s. 117, s. 118, s. 119 and s. 142 with their commencement annotations — legislation.gov.uk (accessed September 4, 2026).
- The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026, S.I. 2026/82; The Data (Use and Access) Act 2025 (Commencement No. 1) Regulations 2025, S.I. 2025/904; and The Data (Use and Access) Act 2025 (Consequential Amendments and Transitional Provision) Regulations 2026, S.I. 2026/386 — legislation.gov.uk (accessed September 4, 2026).
- Information Commissioner's Office, Data protection impact assessments (DPIAs): What is a DPIA?, When do we need to do a DPIA?, How do we do a DPIA?, Do we need to consult the ICO? and Examples of processing “likely to result in high risk” (accessed September 4, 2026).
- Information Commissioner's Office, Data protection impact assessments (Guide to accountability and governance), including the awareness, screening and process checklists and the sample DPIA template; and Guide to Law Enforcement Processing: Data protection impact assessments (accessed September 4, 2026).
- Article 29 Working Party, WP248 rev.01, Guidelines on Data Protection Impact Assessment (DPIA) (as last revised and adopted 4 October 2017) and EDPB Opinion 22/2018 on the draft list of the competent supervisory authority of the United Kingdom (2018).
Related reading on this site: AccessPoint for the UK GDPR and Data Protection Act 2018, AccessPoint for DPA 2018 Part 3 competent authorities, AccessPoint for Freedom of Information Act 2000 requests, privacy impact assessment software, the companion guides on GDPR DPIAs under Articles 35 and 36 and algorithmic impact assessments, the PIA readiness check, a comparison with OneTrust, or book a demo to see a UK DPIA run end to end.
This guide is general information for data protection practitioners, not legal advice. Rely on the official text of the UK GDPR and the Data Protection Act 2018 on legislation.gov.uk, the ICO's current guidance, and your organisation's counsel.
UK DPIA Questions
When must a UK public authority carry out a DPIA?
Under Article 35(1) of the UK GDPR, before any processing that is likely to result in a high risk to the rights and freedoms of individuals. Article 35(3) makes it automatic for systematic and extensive profiling with legal or similarly significant effects, large-scale processing of special-category or criminal-offence data, and systematic monitoring of a publicly accessible area on a large scale. The ICO's Article 35(4) list adds ten more operations, several of which require a DPIA only in combination with another criterion from the European guidelines, and the ICO says that in most cases a combination of two of the nine WP248 criteria indicates the need for a DPIA. If you decide not to do one, document the reasons. For law-enforcement processing under Part 3 of the Data Protection Act 2018, the duty is in section 64.
What is on the ICO's list of processing that requires a DPIA?
Ten operations: innovative technology, including AI, in combination with another criterion; denial of service, meaning decisions about access to a product, service, opportunity or benefit based on automated decision-making or special-category data; large-scale profiling; biometrics in combination with another criterion; genetic data in combination with another criterion, other than by an individual health professional treating the patient; data matching; invisible processing under Article 14(5)(b) in combination with another criterion; tracking of location or behaviour in combination with another criterion; targeting children or other vulnerable individuals for marketing, profiling or automated decisions, or offering online services directly to children; and processing where a breach could jeopardise individuals' physical health or safety.
What must a UK DPIA contain?
The same four elements as the EU text, retained in Article 35(7): a systematic description of the processing and its purposes; an assessment of necessity and proportionality; an assessment of the risks to individuals' rights and freedoms; and the measures to address those risks. The ICO's guidance turns that into seven steps: identify the need, describe the processing, consider consultation, assess necessity and proportionality, identify and assess risks, identify mitigating measures, and sign off and record outcomes. You must seek and record your DPO's advice, and record your reasons if you do not follow it.
When must we consult the ICO, and how long does it take?
Under Article 36(1), where the DPIA identifies a high risk that you cannot reduce, before the processing starts. The submission must include the roles of any joint controllers or processors, the purposes and methods, the measures and safeguards, the DPO's contact details and a copy of the DPIA. The ICO says it will write within 10 days to say whether it has accepted the DPIA for prior consultation, will give written advice within eight weeks of receipt, and can extend to a maximum of 14 weeks in complex cases, telling you within one month. Outcomes range from advice to an official warning or a limitation or ban on the processing. For law-enforcement processing, section 65 of the Data Protection Act 2018 gives the Commissioner six weeks, extendable by a further month.
Did the Data (Use and Access) Act 2025 change DPIAs?
Not the DPIA provisions themselves. The Act, which received Royal Assent on 19 June 2025, made no amendment to Articles 35 or 36 of the UK GDPR or to sections 64 and 65 of the Data Protection Act 2018. Changes around them matter for screening: the new automated decision-making rules in section 80 came into force on 5 February 2026, and the duty to have a data-subject complaints procedure in section 103 on 19 June 2026. Section 117 established the Information Commission on 20 August 2025, but sections 118 and 119, which abolish the office of Information Commissioner and transfer its functions, are not yet in force; the consequential regulations that will rename the Commissioner as the Commission in Articles 35, 36 and 83 and section 65 take effect only when section 119 is fully commenced.
What are the penalties for failing to do a DPIA in the UK?
Infringements of Articles 25 to 39 of the UK GDPR, which include Articles 35 and 36, carry a penalty up to the standard maximum amount: £8,700,000 or, for an undertaking, 2% of total annual worldwide turnover, whichever is higher, under Article 83(4) and section 157(6) of the Data Protection Act 2018. The ICO's guidance says failure to carry out a DPIA when required may leave you open to enforcement action including a fine at that level. The higher maximum of £17,500,000 or 4% applies to infringements of the principles, lawful bases and data-subject rights, and the Commissioner's other corrective powers, including a ban on processing, apply to public authorities in any case.