DPIA Review Checklist: How to Review an Existing Assessment
To review an existing DPIA, compare its description with today's processing, test necessity and proportionality, reassess risks to people, verify safeguards and record every unresolved decision. A dated approval alone is not evidence that the assessment still fits.

When should an existing DPIA be reviewed?
Review a DPIA when the nature, scope, context or purpose of processing changes, when a new supplier or data flow is introduced, or when a safeguard no longer works as described. A material change in risk can make an earlier conclusion unreliable. Periodic review is also useful when a project remains high risk but appears operationally unchanged.
First establish which regime and controller the assessment concerns. EU GDPR and UK GDPR have closely related DPIA requirements, but the applicable authority, consultation route and local context should be checked separately. Keep the original decision and version history so the reviewer can see what has changed.
- Identify the decision owner and the date of the last approved version.
- Collect the current data-flow map, RoPA entry, vendor contracts, notices, security design and incident history.
- Ask product and operations owners to confirm how the feature actually works, including exceptions and manual workarounds.
Seven checks for the reviewer
Check whether the processing description matches the live service; whether the purpose and legal basis remain accurate; whether each dataset and retention period is necessary; whether affected people and their likely harms are identified; whether controls are implemented and tested; whether residual risk is acceptable to the responsible decision maker; and whether consultation or further action is required.
A review should distinguish a gap in evidence from a control failure. For example, missing test results do not prove that access controls failed, but they do mean the claimed reduction in risk is unverified. Record the uncertainty and assign a verification action.
Illustrative review: a SaaS analytics feature
The fictional company Northstar Workspace has an approved DPIA for account analytics. It later adds a support vendor with access to detailed activity logs. The table shows how a reviewer could record open questions. It does not conclude that the processing is lawful or that the risk is acceptable.
| Finding | Evidence and people affected | Safeguard / owner | Closure evidence |
|---|---|---|---|
| Vendor access missing from old flow | New support integration diagram; account users' activity logs | Restrict support roles and document access purpose; engineering owner | Updated flow and access test signed off |
| Retention claim unverified | DPIA says 30 days; live log setting not documented | Confirm configuration and deletion path; platform owner | Configuration export and deletion test |
| Residual risk not reconsidered | New access path and no dated risk decision | Reassess likelihood and harm; privacy lead and controller | Dated risk decision and revised DPIA |
Close the review with a decision record
Record the reviewer, processing version, evidence considered, unresolved facts, actions, owners and dates. The controller should document its decision on residual risk and whether processing must change or consultation is needed. If the facts are incomplete, mark the review open rather than describing it as approved.
The ICO's DPIA guidance and the EDPB's accountability guidance are useful reference points. A provider can challenge the assessment and help structure the evidence, but the controller retains responsibility for decisions and implementation.
Frequently asked questions
Is reviewing a DPIA the same as writing a new one?
No. A review compares an existing assessment with the current processing and risk. A major change may require substantial reworking or a new assessment, depending on the facts.
Can a DPIA be closed with missing evidence?
Do not treat an unverified safeguard as proven. Record the evidence gap, responsible owner and decision on whether processing may continue while the question is resolved.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.
Sources: EUR-Lex: GDPR, ICO: Data protection impact assessments, EDPB: Be compliant
