I always find a real misconception across organisations about who does a Data Protection Impact Assessment (DPIA). One of the things I hear all the time is:
Can you complete this DPIA for us?
Now, that might sound like a perfectly reasonable request, especially when I’m acting as an outsourced Data Protection Officer (DPO). But my answer is usually…
“I’ll absolutely help you with it and make sure it’s done properly, but I don’t want to do it for you.”
That often surprises people.
The reason is simple.
A Data Protection Impact Assessment (DPIA) isn’t just another compliance document that needs completing to satisfy a regulator. It’s a risk management exercise, and the people who understand the processing best are the people who own it.
The DPO is there to advise, challenge and support.
The process owner is the one who understands why the processing is happening, what systems are involved, what information is being collected and what the intended outcome is.
Without that knowledge, a DPIA simply becomes paperwork.
I’ve worked with organisations where the DPO has completed every DPIA on behalf of the business.
The documents looked great, the templates were fully completed and every section had been filled in.
But when I asked the process owner about the risks associated with their own project, they couldn’t answer. That’s the problem.
The real value of a DPIA isn’t the finished document. The value comes from the conversations that happen while it’s being completed.
Perhaps it’s the investigator in me from my policing career, but I rarely accept the first answer at face value. I’ll often ask, “What happens next?” and then, “And after that?” Those questions usually reveal where personal data is really flowing, who is making decisions and where the privacy risks actually exist. That’s exactly what a good DPIA should do—it should help people explore the process, not simply complete a template.
What personal data are we collecting? Do we need all of it? Who will have access? Could someone be harmed if something went wrong? How could we reduce that risk before we launch?
Those discussions help project teams think differently. They start considering privacy from the beginning instead of trying to fix problems later.
They begin to understand that good data protection isn’t something the DPO does to the organisation—it’s something the organisation does for itself.
As a DPO, I see my role as helping people ask the right questions. I’ll explain the legislation, I’ll identify where risks exist, I’ll challenge assumptions and I’ll suggest ways to reduce those risks.
And I’ll make sure the organisation has considered the impact on the individuals whose information they’re processing as its difficult for an employee to think from the end user’s perspective, as a DPO I am responsible for looking at it from the data subjects position to make sure we consider any potential harm to them from the processing.
But accountability remains with the organisation and the process owner.
That’s exactly where it should be.
When process owners take ownership of their DPIAs, something interesting happens.
Privacy becomes part of everyday decision-making rather than an annual compliance exercise. Projects are designed better. Risks are identified earlier. Mitigations become more practical because they’re developed by the people delivering the work.
And over time, organisations build something far more valuable than a collection of completed templates.
They build a culture where managing privacy risks becomes second nature.
So the next time someone says, “Can you just do the DPIA?” I’d encourage a different conversation.
Let’s complete it together.
Because a DPIA isn’t just paperwork.
It’s one of the best risk management tools your organisation has.
Author – Irene Coyle, Data Protection Officer, OSP Cyber Academy


