The building blocks of Compliance e: stonearch@protonmail.com t: 01706 559 022
The building blocks of Compliance e: stonearch@protonmail.com t: 01706 559 022

Privacy by design’ is a concept that features heavily in the legislation. Your organisation needs to be able to demonstrate that all processes and practices involving personal data have been adequately thought-out to incorporate the provisions of the UK GDPR.
A data protection impact assessment (DPIA) is a way of extracting the data protection requirements, and implementing measures to reduce as far as possible the impact on people’s privacy. A key part of these assessments is to conduct a detailed risk assessment to help you identify and mitigate the risks involved.
Importantly, DPIAs are a statutory requirement where the processing you conduct is likely to lead to a ‘high risk’ to the rights and freedoms of your data subjects. This means that in certain circumstances, by law, you must conduct an assessment. It is also advised by the Information Commissioner’s Office that even where there may not be high risks present, it is still a good idea to complete one of these assessments. It is also a great way to demonstrate your organisation’s accountability in complying with the legislation, which in itself is one of the requirements.
StoneArch also recommend that your organisation have embedded procedures and policy in place to ensure that DPIAs are considered whenever you do anything new, or change the way you process, personal data. Please see our the ‘policy creation’ services.
DPIAs make up a part of our recommended five steps to compliance - please see below for further information about this aspect of your compliance journey. And don't forget to reach out to ask us about our "5 Steps to Compliance" course!
🔴 High
A DPIA is a glorified risk assessment process designed to identify and reduce privacy risks before they materialise. It also sets out how you comply with each of the principles of the UK GDPR.
Rather than waiting for issues to emerge after implementation, a DPIA encourages organisations to consider privacy impacts during the planning stage of a project or initiative.
DPIAs are particularly valuable when introducing new technologies, large-scale processing, monitoring activities, or any initiative that could significantly affect individuals. Its never too late: you should conduct DPIAs for existing higher-risk processes to identify risks in your current set-up.
Failing to complete a DPIA when one is required can result in privacy risks remaining unidentified until after implementation.
As well as being a breach of the legislation, this can lead to:
The earlier a privacy risk is identified, the easier and cheaper it is usually to address.
A DPIA begins with understanding exactly what the project or activity involves. This includes identifying what personal data is involved, who the individuals are, how the data will be used and what technology or suppliers support the process.
Once the proposed processing is understood, the assessment focuses on:
A DPIA is not intended to prevent projects from proceeding or systems being implemented. Instead, it provides a structured way of identifying issues early and ensuring appropriate safeguards are implemented.
For many projects, privacy risks can be significantly reduced through relatively simple design decisions made at the planning stage.
If you are planning a new project, system, process or supplier engagement involving personal data, or need to retrospectively assess how you use personal data, contact Stone Arch as early as possible. Early engagement typically results in quicker reviews and more effective risk management.