Confidential Dispatch

How to run a Data Protection Impact Assessment (DPIA) without expensive lawyers

4 min readUpdated 2026-07-05
On this page
  1. 01Who has to do a DPIA — and who just should
  2. 02What a DPIA actually is
  3. 03Run one yourself, step by step
  4. 04When to bring in help
  5. 05FAQ
At a glance

A Data Protection Impact Assessment (DPIA) is a structured check of what could go wrong with a piece of personal-data processing and how you’ll reduce the risk. Under India’s DPDP Act it’s a mandatory, periodic duty for Significant Data Fiduciaries — and sensible practice for any business launching something data-heavy. You don’t need a law firm to run a basic one: describe the processing, list the data and purposes, spot the risks to people, and record the mitigations. The steps below are a plain-English DIY version.

Educational resource only. This explains Data Protection Impact Assessments under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice.

The situation

“DPIA” sounds like a big-budget, law-firm exercise. For a Significant Data Fiduciary it’s a formal requirement — but the underlying activity is something any team can do: think through the privacy risks of what you’re building before you build it, and write down how you’ll handle them. Done early, it’s cheap; done never, it’s expensive.

Who has to do a DPIA — and who just should

It’s mandatory for Significant Data Fiduciaries; for everyone else it’s strong practice, not a legal must. The Act requires a Significant Data Fiduciary to carry out a DPIA periodically (as part of the Section 10 obligations) and have it, with an audit, reported to the Board. If you’re not an SDF, you’re not legally required to run one — but doing a lightweight DPIA before a data-heavy launch (a new app feature, a big collection, a new vendor) is one of the cheapest ways to catch a compliance problem while it’s still easy to fix.

What a DPIA actually is

It’s a written risk assessment for a specific processing activity — plain and structured, not legalistic. A DPIA answers, for one project or feature: what data are we processing, why, for whom, what could go wrong for the people involved, and what are we doing to reduce that. The value isn’t the document; it’s being forced to think about the risk to individuals before you ship, and having a record that you did.

Run one yourself, step by step

Work through six questions and write the answers down — that’s a serviceable DPIA.

  1. Describe the processing. What are you doing, with whose data, using which systems and vendors.
  2. List the data and purposes. Each data type, why you need it, and the lawful basis (consent or a legitimate use).
  3. Check necessity and minimisation. Do you need all of it? Cut anything the purpose doesn’t require.
  4. Identify the risks to people. What harm could a breach, misuse, or over-collection cause the individuals — and how likely is it?
  5. Set the mitigations. For each risk, what reduces it — access controls, encryption, shorter retention, masking, a tighter consent flow, a better vendor contract.
  6. Record decisions and residual risk. Note what you’re doing, what risk remains, and who signed off.

Revisit it when the processing changes materially — a DPIA is a living record, not a one-time form.

When to bring in help

Do the thinking in-house; call in expertise for the genuinely hard or high-stakes calls. A DIY DPIA is fine for most routine processing. Consider outside help when: you’re an SDF and need the formal, reportable version; the processing is unusually sensitive (health, children, biometrics at scale); you’re doing something novel (new profiling, AI on personal data); or the cross-border or sector-specific rules get complicated. Even then, arriving with your own draft DPIA makes the expert time shorter and cheaper.

FAQ

Is a DPIA mandatory under the DPDP Act?

It’s mandatory and periodic for Significant Data Fiduciaries. For other businesses it isn’t legally required, but it’s strong practice before data-heavy processing.

Do I need a lawyer to run a DPIA?

Not for a basic one. You can run a serviceable DPIA in-house by working through the processing, data, risks and mitigations. Bring in help for SDF-formal, high-sensitivity, or novel processing.

When should I run a DPIA?

Before launching something data-heavy — a new feature, a large collection, a new vendor — and again when the processing changes materially.

What makes a DPIA “good”?

Honesty about the risks to individuals and concrete mitigations, recorded. A tidy document that ignores the real risks isn’t worth much.

Reviewed by Confidential Dispatch Editorial Team
Last updated 5 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →