Skip to main content
Category: Impact Assessments & Documentation

Ongoing Review of the DPIA

Also known as: DPIA Review, DPIA Ongoing Monitoring, DPIA as a Living Process
Simply put

A Data Protection Impact Assessment (DPIA) is not a one-time document but a 'living' process that should be revisited over time. Organisations are generally expected to review a DPIA regularly and whenever there is a significant change to the processing activity or the risks involved. This helps ensure that the risks identified and the safeguards put in place remain appropriate as circumstances change.

Formal definition

Ongoing review of the DPIA refers to the continuing obligation to treat a DPIA as an iterative, living process rather than a static deliverable completed at project outset. In practice this typically involves periodic reassessment of ongoing processing operations, and a fresh review triggered by any significant change in the nature, scope, context, or purposes of the processing, or in the associated risks to individuals. The review reassesses whether the identified risks, the necessity and proportionality of the processing, and the mitigating measures remain adequate, and updates the DPIA accordingly. The precise cadence and triggers are not prescribed by a fixed figure in the source evidence and should be determined on a risk basis; readers should verify specific procedural requirements against the current UK GDPR / EU GDPR text and relevant supervisory authority guidance, as regulator expectations and national implementing rules may vary.

Why it matters

A DPIA that is completed at project launch and then filed away can quickly become inaccurate. Processing activities evolve: new data sources are added, purposes expand, vendors change, and the wider risk environment shifts. Because a DPIA is designed to identify and minimise the data protection risks of a project, an out-of-date assessment can leave an organisation relying on safeguards that no longer match the actual processing. Treating the DPIA as a living process, as reflected in ICO guidance, helps ensure that identified risks and mitigating measures remain appropriate as circumstances change.

Ongoing review is also closely tied to the accountability principle. The value of a DPIA lies not only in the initial analysis but in the organisation's ability to demonstrate, over time, that it continues to understand and manage the risks its processing poses to individuals. Commentary in this area suggests that ongoing monitoring is frequently where organisations fall short, because the discipline of revisiting an assessment after sign-off is easy to neglect once a project moves into business-as-usual operation.

The practical consequence is that risks can drift out of alignment with the controls documented at the outset. Where a significant change occurs and no fresh review is carried out, an organisation may find that its necessity and proportionality analysis, or its mitigation measures, no longer reflect reality. Because the precise cadence and triggers for review are not fixed by a single prescribed figure in the source material, organisations should verify specific procedural expectations against the current UK GDPR or EU GDPR text and relevant supervisory authority guidance, noting that regulator expectations and national implementing rules may vary.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are typically responsible for maintaining DPIAs as living documents and for building review triggers into governance processes. They generally need to define when periodic reassessment occurs and what constitutes a significant change warranting a fresh review, while confirming specific expectations against current supervisory authority guidance.
Project and Product Owners
Those who own processing activities are often best placed to detect when the nature, scope, context, or purposes of processing have changed. Their role is to flag significant changes so that the DPIA can be revisited before new or heightened risks to individuals go unaddressed.
Compliance and Accountability Functions
Teams responsible for demonstrating accountability rely on up-to-date DPIAs as evidence that risks are being managed on an ongoing basis. Ongoing review supports the ability to show that safeguards continue to match the actual processing, rather than only the position at project outset.
Engineers and Technical Implementers
Engineers who implement or modify processing systems can introduce changes that materially affect risk, such as new data flows or integrations. Their awareness of when technical changes are significant helps ensure that ongoing monitoring is effective and that reassessment is triggered when appropriate.

Inside Ongoing Review of the DPIA

Review Trigger
An event or change that prompts reassessment of a previously conducted Data Protection Impact Assessment (DPIA). Under Article 35 GDPR, a DPIA should be reviewed where there is a change in the risk represented by the processing operations. Typical triggers include changes to the nature, scope, context, or purposes of the processing, the introduction of new technologies, or new risks becoming apparent.
Reassessment of Risk
The core substantive activity of ongoing review: revisiting the identified risks to the rights and freedoms of data subjects and evaluating whether they remain accurately characterised. This generally involves confirming whether existing mitigations are still effective and whether residual risk remains at an acceptable level, subject to assessment against the specific circumstances.
Verification of Compliance
Confirmation that the processing continues to be carried out in accordance with the DPIA. Article 35 indicates that, at least when there is a change of the risk, the controller should carry out a review to assess whether processing is performed in line with the assessment. This element focuses on the gap between what was assessed and what is actually happening in practice.
Documentation and Version Control
A record of when reviews occurred, what changed, and the rationale for any decisions. Maintaining dated and versioned DPIA records supports the accountability principle and helps demonstrate that the assessment reflects the current state of the processing rather than a historical snapshot.
Role of the DPO
Where a Data Protection Officer (DPO) has been designated, the controller should seek the DPO's advice on the DPIA and monitoring its performance is among the DPO's tasks under the Regulation. The DPO's involvement in ongoing review is advisory and monitoring in nature; responsibility for the processing and the assessment generally remains with the controller.

Common questions

Answers to the questions practitioners most commonly ask about Ongoing Review of the DPIA.

Is a DPIA a one-time document that can be filed away once the processing goes live?
No. A DPIA is generally understood as a living process rather than a one-off deliverable. Article 35(11) provides that the controller shall, where necessary, carry out a review to assess whether processing is performed in accordance with the DPIA, at least when there is a change of the risk represented by the processing operations. Treating the assessment as complete at launch misunderstands its purpose; the analysis typically needs revisiting as the processing, its context, or the associated risks evolve.
Does an ongoing review only need to happen if the underlying technology changes?
Not exclusively. A change in technology is one common trigger, but the obligation is framed around a change in the risk represented by the processing, which can arise from many sources beyond technology alone, such as changes in purposes, data categories, the volume of data subjects affected, retention, recipients, or the wider context and safeguards. In most cases a review should be considered whenever any factor that shaped the original risk assessment shifts, subject to the controller's own assessment of what is necessary.
When should we schedule a review of an existing DPIA?
There is no single interval fixed in the Regulation text, so the timing is generally a matter for the controller's judgement. A common practical approach is to combine event-driven triggers (such as material changes to the processing, its purposes, recipients, or safeguards) with a periodic calendar review at a defined cadence. Many organisations align the review point with related governance activities, but the appropriate frequency should be set by reference to the level and volatility of the risk and any applicable internal policy.
Who within the organisation should be responsible for keeping a DPIA under review?
Responsibility for the DPIA rests with the controller. In practice the review is typically coordinated by the business or project owner accountable for the processing, working with relevant functions. Where a Data Protection Officer has been designated, the controller is generally expected to seek the DPO's advice in connection with the DPIA and to involve them in monitoring its performance. Clear ownership and documented roles help ensure reviews are actually carried out rather than assumed.
How should the outcome of an ongoing review be documented?
It is generally good practice to record the fact that a review took place, what was assessed, any changes identified in the processing or its risks, the resulting decisions, and the date. Maintaining version history alongside the original assessment supports the accountability principle by demonstrating that the DPIA has been kept current. The specific format is not prescribed by the Regulation, so organisations typically follow their own internal standards, which the reader should verify against current guidance and policy.
What practical triggers might prompt an unscheduled review outside the normal cycle?
Practical triggers commonly include material changes to the purposes or scope of processing, new categories or larger volumes of personal data, new recipients or transfer arrangements, changes to retention, adoption of new tools or vendors, the emergence of a security incident, new regulatory guidance, or feedback from data subjects. Because the review obligation is tied to changes in the risk represented by the processing, any development that could alter that risk profile is generally worth assessing to decide whether a fuller review is needed.

Common misconceptions

A DPIA is a one-time exercise completed before processing begins and then filed away.
A DPIA is generally intended to be a living document. Where there is a change in the risk represented by the processing, it should be reviewed, and good practice typically favours periodic reconsideration even absent an obvious trigger. Treating it as a static, one-off artefact undermines the accountability rationale for conducting it.
Only major system overhauls require a DPIA review.
Reviews can be prompted by any change that alters the risk to data subjects, including changes to purposes, context, data flows, recipients, or the introduction of new technology. Smaller or incremental changes may cumulatively shift the risk profile, so whether a review is needed is a matter for assessment rather than a fixed threshold.
If regulators have not raised concerns, the original DPIA remains adequate indefinitely.
The adequacy of a DPIA depends on whether it still reflects the actual processing and its current risks, not on the absence of enforcement contact. Guidance and regulator expectations can also evolve, and there may be divergence between authorities, so the boundary of what is considered sufficient should be verified against current official sources.

Best practices

Establish defined triggers for review, such as changes to the nature, scope, context, or purposes of processing, or the introduction of new technologies, and document these triggers within the DPIA itself.
Schedule periodic reviews at planned intervals in addition to trigger-based reviews, so the assessment does not become outdated during periods without an obvious change.
Involve the Data Protection Officer, where one is designated, in reviewing and monitoring the DPIA, while keeping accountability and decision-making with the controller.
Maintain dated, version-controlled records of each review, capturing what changed, the reassessed risks, and the reasoning behind any decisions, to support the accountability principle.
Reassess the effectiveness of existing mitigations and residual risk at each review, rather than assuming that measures that were adequate at the outset remain sufficient.
Verify the current legal and regulatory position, including any evolving guidance or divergence between authorities, against official sources rather than relying on the state of the assessment at the time it was first completed.