What is Data Protection Impact Assessment (DPIA)?
A Data Protection Impact Assessment (DPIA) is a structured process for identifying and reducing privacy risks when a project or system will process personal data in ways that could harm people. It helps organisations decide whether a project is safe, legally compliant and what controls are needed before launch.
A DPIA (sometimes called a privacy impact assessment) is a documented review that looks at how a service or project collects, stores, uses and shares personal data, then assesses the likelihood and severity of harms to individuals. It is recommended — and in some jurisdictions required by law (for example under the EU's GDPR) — when processing is likely to result in high risk to people’s rights and freedoms. A DPIA typically: describes the processing, identifies the legal basis, maps data flows, lists potential risks (e.g. unauthorised access, re-identification, inaccurate translations), evaluates those risks, and sets out measures to reduce them (technical, organisational and procedural). The DPIA is a living document: it should be reviewed and updated as the project changes.
Usage example
A council plans a multilingual resident survey that asks about health needs and uses automated translation. Before launching, the project lead completes a DPIA to identify risks (sensitive health data, third‑party AI translation, data transfers), documents how responses will be stored and accessed, and specifies mitigations such as pseudonymisation, restricted staff access, clear consent wording in all languages and a translation review workflow.
Practical application
Doing a DPIA matters because it makes privacy risks concrete and actionable — helping teams design safer surveys, avoid legal problems, and build trust with participants. For organisations using Hearo-style multilingual forms, a DPIA helps decide whether automatic translation or human review is appropriate for specific questions, sets retention and access controls for open-text responses, and shows funders or oversight bodies that you considered inclusion and risk before collecting responses. Completing a DPIA early can prevent costly rework, reduce the chance of data breaches, and provide evidence of due diligence in consultations or service delivery.
FAQ
Is a DPIA legally required for every survey?
Not always. A DPIA is required when processing is likely to result in high risk to individuals — for example, systematic monitoring, large-scale handling of special category (sensitive) data (health, ethnicity, political opinions), or new technologies like automated profiling or third-party AI translation. If your survey only collects basic contact details or anonymous responses it may not need a DPIA, but it's good practice to screen for risk first.
Who should complete the DPIA?
The data controller (the organisation deciding why and how data is processed) is responsible for the DPIA, but the work should involve project leads, IT/security staff, legal/compliance or a Data Protection Officer (if you have one), and frontline colleagues who understand how participants will actually use the survey. For Hearo users this can be done by the survey owner with oversight from an appropriate reviewer.
What practical steps does a DPIA recommend for multilingual surveys?
Common mitigations include: minimising sensitive questions, pseudonymising or anonymising open-text responses, restricting access to raw data, encrypting stored responses, documenting translation processes, giving participants clear consent in every language, keeping retention periods short, and adding participant feedback mechanisms for translation accuracy so wording can be improved.
How long does a DPIA take and how often should it be updated?
Duration ranges from a few hours for low-risk projects to several days for complex systems. It should be completed before the survey goes live and revisited whenever the processing changes significantly (new questions, new languages, different storage or third-party services) or if a risk or incident occurs.