DPIA · Review checklist

DPIA Review Checklist: How to Review an Existing Assessment

To review an existing DPIA, compare its description with today's processing, test necessity and proportionality, reassess risks to people, verify safeguards and record every unresolved decision. A dated approval alone is not evidence that the assessment still fits.

By The Data Protection OfficersReading time: 4 min
Original DPIA review illustration showing a processing change, risk matrix and evidence trail

When should an existing DPIA be reviewed?

Review a DPIA when the nature, scope, context or purpose of processing changes, when a new supplier or data flow is introduced, or when a safeguard no longer works as described. A material change in risk can make an earlier conclusion unreliable. Periodic review is also useful when a project remains high risk but appears operationally unchanged.

First establish which regime and controller the assessment concerns. EU GDPR and UK GDPR have closely related DPIA requirements, but the applicable authority, consultation route and local context should be checked separately. Keep the original decision and version history so the reviewer can see what has changed.

  • Identify the decision owner and the date of the last approved version.
  • Collect the current data-flow map, RoPA entry, vendor contracts, notices, security design and incident history.
  • Ask product and operations owners to confirm how the feature actually works, including exceptions and manual workarounds.

Seven checks for the reviewer

Check whether the processing description matches the live service; whether the purpose and legal basis remain accurate; whether each dataset and retention period is necessary; whether affected people and their likely harms are identified; whether controls are implemented and tested; whether residual risk is acceptable to the responsible decision maker; and whether consultation or further action is required.

A review should distinguish a gap in evidence from a control failure. For example, missing test results do not prove that access controls failed, but they do mean the claimed reduction in risk is unverified. Record the uncertainty and assign a verification action.

Illustrative review: a SaaS analytics feature

The fictional company Northstar Workspace has an approved DPIA for account analytics. It later adds a support vendor with access to detailed activity logs. The table shows how a reviewer could record open questions. It does not conclude that the processing is lawful or that the risk is acceptable.

FindingEvidence and people affectedSafeguard / ownerClosure evidence
Vendor access missing from old flowNew support integration diagram; account users' activity logsRestrict support roles and document access purpose; engineering ownerUpdated flow and access test signed off
Retention claim unverifiedDPIA says 30 days; live log setting not documentedConfirm configuration and deletion path; platform ownerConfiguration export and deletion test
Residual risk not reconsideredNew access path and no dated risk decisionReassess likelihood and harm; privacy lead and controllerDated risk decision and revised DPIA

Close the review with a decision record

Record the reviewer, processing version, evidence considered, unresolved facts, actions, owners and dates. The controller should document its decision on residual risk and whether processing must change or consultation is needed. If the facts are incomplete, mark the review open rather than describing it as approved.

The ICO's DPIA guidance and the EDPB's accountability guidance are useful reference points. A provider can challenge the assessment and help structure the evidence, but the controller retains responsibility for decisions and implementation.

Frequently asked questions

Is reviewing a DPIA the same as writing a new one?

No. A review compares an existing assessment with the current processing and risk. A major change may require substantial reworking or a new assessment, depending on the facts.

Can a DPIA be closed with missing evidence?

Do not treat an unverified safeguard as proven. Record the evidence gap, responsible owner and decision on whether processing may continue while the question is resolved.

Keep researching

A practical next step

Make the next privacy decision clearer

Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.

This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.

Sources: EUR-Lex: GDPR, ICO: Data protection impact assessments, EDPB: Be compliant

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services