1. Section 3: Individual rights and accountability

1.4. 3.4 DPIAs, processors and international transfers

UK data protection learning

3.4 DPIAs, processors and international transfers

Assessing high-risk processing and managing external suppliers.

Data protection impact assessments

A DPIA is required before processing that is likely to result in a high risk to individuals. It helps an organisation describe the processing, assess necessity and proportionality, identify risks and select measures to reduce those risks.

Potential high-risk indicators include systematic monitoring, large-scale use of special category data, innovative technology, significant automated decisions, vulnerable people or combining datasets in unexpected ways.

Timing matters: A DPIA must be early enough to change or stop the proposed processing.

Using processors

A controller must use processors that provide sufficient guarantees. A written contract must address the required Article 28 matters, including documented instructions, confidentiality, security, sub-processors, assistance with rights and breaches, return or deletion, and audit information.

Restricted international transfers

Where a restricted transfer is made outside the UK, the organisation must use an available legal route, such as adequacy regulations or appropriate safeguards, and complete any required transfer risk assessment. The general principles, transparency and security requirements continue to apply.

Activity: DPIA screening

A college proposes an AI-assisted monitoring system that analyses learner behaviour, attendance, online activity and welfare indicators to predict disengagement.

  1. Identify at least five possible privacy risks.
  2. Explain why a DPIA is likely to be required.
  3. List the groups that should be consulted.
  4. Suggest measures that could reduce risk.
  5. Identify questions to ask the supplier about data, models, security, deletion and human oversight.
Open the answer guidance

Risks may include unfair or inaccurate profiling, excessive collection, special category inferences, opaque decisions, over-reliance by staff, data breaches, function creep, discrimination and chilling effects.

Possible controls include clear purposes, data minimisation, human review, accuracy testing, access controls, retention limits, transparency, challenge routes, supplier assurance and regular monitoring.


Official reference points

Legal accuracy: reviewed against official UK sources on 14 July 2026. This learning content is educational and is not a substitute for case-specific legal advice.