Ongoing Review of the DPIA
A Data Protection Impact Assessment (DPIA) is not a one-time document but a 'living' process that should be revisited over time. Organisations are generally expected to review a DPIA regularly and whenever there is a significant change to the processing activity or the risks involved. This helps ensure that the risks identified and the safeguards put in place remain appropriate as circumstances change.
Ongoing review of the DPIA refers to the continuing obligation to treat a DPIA as an iterative, living process rather than a static deliverable completed at project outset. In practice this typically involves periodic reassessment of ongoing processing operations, and a fresh review triggered by any significant change in the nature, scope, context, or purposes of the processing, or in the associated risks to individuals. The review reassesses whether the identified risks, the necessity and proportionality of the processing, and the mitigating measures remain adequate, and updates the DPIA accordingly. The precise cadence and triggers are not prescribed by a fixed figure in the source evidence and should be determined on a risk basis; readers should verify specific procedural requirements against the current UK GDPR / EU GDPR text and relevant supervisory authority guidance, as regulator expectations and national implementing rules may vary.
Why it matters
A DPIA that is completed at project launch and then filed away can quickly become inaccurate. Processing activities evolve: new data sources are added, purposes expand, vendors change, and the wider risk environment shifts. Because a DPIA is designed to identify and minimise the data protection risks of a project, an out-of-date assessment can leave an organisation relying on safeguards that no longer match the actual processing. Treating the DPIA as a living process, as reflected in ICO guidance, helps ensure that identified risks and mitigating measures remain appropriate as circumstances change.
Ongoing review is also closely tied to the accountability principle. The value of a DPIA lies not only in the initial analysis but in the organisation's ability to demonstrate, over time, that it continues to understand and manage the risks its processing poses to individuals. Commentary in this area suggests that ongoing monitoring is frequently where organisations fall short, because the discipline of revisiting an assessment after sign-off is easy to neglect once a project moves into business-as-usual operation.
The practical consequence is that risks can drift out of alignment with the controls documented at the outset. Where a significant change occurs and no fresh review is carried out, an organisation may find that its necessity and proportionality analysis, or its mitigation measures, no longer reflect reality. Because the precise cadence and triggers for review are not fixed by a single prescribed figure in the source material, organisations should verify specific procedural expectations against the current UK GDPR or EU GDPR text and relevant supervisory authority guidance, noting that regulator expectations and national implementing rules may vary.
Who it's relevant to
Inside Ongoing Review of the DPIA
Common questions
Answers to the questions practitioners most commonly ask about Ongoing Review of the DPIA.