Certus
← All insightsDPIA Guidance · 6 min read

When a DPIA is actually required — and when it is theatre

A DPIA done on every project, regardless of risk, quickly becomes a box-ticking exercise that slows delivery without improving privacy outcomes. A DPIA skipped on a genuinely high-risk project — new biometric authentication, a large-scale profiling engine, a sensitive health data integration — is a far more serious problem.

The right approach starts with a short, honest screening question set applied at project intake: does this involve new or expanded processing of sensitive data, large-scale monitoring, automated decision-making with legal effect, or a new cross-border transfer? If yes to any, a full DPIA is warranted. If not, a lighter-touch privacy check may be sufficient.

Where DPIAs go wrong operationally is timing: run after a system is already built, they become a documentation exercise rather than a design input. Run early, alongside architecture and vendor selection decisions, they can genuinely change the outcome — a different data retention default, a narrower data field, a different vendor.

A credible DPIA programme is judged less by how many DPIAs were completed, and more by how many decisions they actually changed.

Want this applied to your organisation?

Talk to a Certus privacy partner about what this means for your specific risk.