Data Protection Impact Assessment (DPIA) Procedure
This procedure sets out the University’s approach towards identifying the need for, undertaking and implementing Data Protection Impact Assessments (DPIAs) to ensure that the rights and freedoms of individuals are protected in compliance with the UK General Protection Regulation (UK GDPR) and Data Protection Act 2018.
On this page
1. Introduction & Scope
1.1. The UK General Protection Regulation (UK GDPR) and Data Protection Act 2018 require the University as a data controller to consider and apply appropriate measures and safeguards into activities involving the processing of personal data. This is to ensure that the rights and freedoms of individuals are protected and is known as “Privacy by Design.”
1.2. A key element of the UK GDPR’s focus on accountability and privacy by design is to undertake Data Protection Impact Assessments (DPIAs) where processing is “likely to result in a high risk to the rights and freedoms of individuals.”
1.3. A DPIA, therefore, is a process that helps systematically identify, analyse and where possible mitigate the data protection risks of specific projects, plans or activities (initiatives) within the University.
1.4. DPIA’s are a mandatory requirement of some research funding grants, collaboration agreements, procurement or implementation of new services or systems.
1.5. This procedure sets out the University’s approach towards identifying the need for, undertaking and implementing DPIAs.
1.6. This procedure is governed by the University’s Data Protection Policy. In the event of a conflict between this procedure and the Data Protection Policy, the Data Protection Policy will take precedence.
1.7. This procedure is supported by the following resources:
- The University’s Data Protection webpages and relevant internal guidance and resources
1.8. The University’s Data Protection Policy provides an explanation of what is meant by “Personal Data” and “Special Category Personal Data” and what “Processing” personal data means.
1.9. This procedure applies to all personal data processed by the University, regardless of format or location and pertains to all the University’s schools, faculties and professional divisions. It is relevant to both business functions and research activities.
2. Responsibilities
2.1. The Director of Governance and University Secretary. The Director of Governance and University Secretary has overall responsibility to ensure that the University meets its legal and regulatory responsibilities under the UK GDPR.
2.2. Data Protection Officer. The University’s Data Protection Officer (DPO) is responsible for oversight and implementation of this procedure and for ensuring compliance with data protection legislation. The Data Protection Officer may assign responsibility for reviewing and approving a DPIA to a member of the Information Compliance team.
2.3. Other members of the University. All members of the University staff and students must comply with this procedure. Staff and students must recognise where there is a requirement to carry out a DPIA and ensure this is completed in accordance with this procedure.
2.4. Data Processors. All data processors must comply with any instructions given by the University under this procedure to undertake and assist with DPIA’s in line with their contract with the University.
2.5. External parties. External parties may be required to contribute towards a DPIA.
3. Data Protection Impact Assessment Procedure
When is a DPIA required
3.1. Data Protection legislation requires that a DPIA is carried out before the commencement of any processing that is “likely to result in a high risk to the rights and freedoms” of individuals. As such it is necessary to identify whether there are any factors that point to the potential for a widespread or serious impact on individuals.
3.2. The GDPR requires a DPIA to be undertaken where any initiative will involve:
- the systematic and extensive evaluation of personal data by automated means, including profiling, resulting in decisions that would have significant effects for those individuals;
- the processing of special categories of personal data or personal data relating to criminal convictions and offences on a large scale; or
- the systematic monitoring of a publicly accessible area on a large scale.
3.3. The ICO also provides guidance on processing activities that require a DPIA, some in isolation and some when they occur in combination with other criteria:
- use innovative technology (in combination with any of the criteria from the European guidelines);
- use profiling or special category data to decide on access to services;
- profile individuals on a large scale;
- process biometric data
- process genetic data
- match data or combine datasets from different sources;
- collect personal data from a source other than the individual without providing them with a privacy notice (‘invisible processing’)
- track individuals’ location or behaviour
- profile children or target marketing or online services at them; or
- process data that might endanger the individual’s physical health or safety in the event of a security breach.
3.4. Where any new initiative will involve processing likely to result in a high risk to individuals a full DPIA is required. However you may not know whether this is a requirement until you have carried out a preliminary assessment, in this case the data protection initial screening form can be completed. This includes a set of questions used to help determine where a full DPIA is needed. Associated internal guidance is available on the DPIA page. This should be considered at the start of a new initiative or activity, or before any changes are made to existing activities to establish whether a full DPIA is required.
3.5. Where the outcome of the initial screening form or advice from the Information Compliance team suggests that the processing is likely to result in a high risk to individuals a full DPIA is required, internal guidance is available on the DPIA page.
3.6. Where the outcome of the initial screening or advice from the Information Compliance team suggests that the processing is unlikely to result in a high risk to individuals, there may be circumstances where it is advisable to undertake a DPIA anyway. These should be discussed with the Information Compliance team. Key factors such as the scope of the processing, the groups of individuals involved or the level of investment in the initiative, will be taken into consideration
When should a DPIA commence
3.7. A DPIA should be undertaken at the earliest opportunity in the development of any initiative, this incorporates a ‘privacy by design approach’ and allows us to identify and minimise risks as early as possible.
3.8. This assessment may be required for a range of University activities including:
-
- Research activities (see advice for researchers);
- projects;
- IT solutions;
- New suppliers;
- Changes to University processes;
- New Apps, platforms, third party solutions;
- New websites;
- Sharing data with third parties
- International transfers of personal data
Who is responsible for undertaking a DPIA
3.9. It is the responsibility of the staff member or team leading the initiative within the University to undertake the initial conversations with the Information Compliance team, the initial screening form and to complete a DPIA (where required). This applies even where the project is led by another institution as the University must assess its own processing activities independently.
3.10. It is important to identify the key stakeholders in the initiative so that that they can provide their input into the assessment. It is also important to have a clear understanding of the scope and objectives of the initiative to allow a full and accurate assessment.
3.11. Where the University is acting as a joint controller or a processor for an activity involving a partner organisation the arrangements to complete the DPIA should be discussed and agreed between all parties taking into consideration any contractual arrangements.
Undertaking the DPIA
3.12. Having established that a DPIA is necessary the Information Compliance team will confirm with you:
- The name of the initiative, project or processing activity,
- The Business Owner or Information Asset Assistant responsible for completing the DPIA.
3.13. The Information Compliance team use the One Trust platform to carry out DPIAs. An assessment will be sent from this platform to those responsible for completing these. Guidance on how the assessment will be received and how to complete these can be found on the One Trust user guide and FAQ’s
3.14. Part of the DPIA may involve consultation with relevant internal and external stakeholders e.g. IT, Information Security, Procurement, research contracts. In these cases the assessment can forwarded to the relevant parties, should this be required contact the Information Compliance team. The Information Compliance team may also consult with other stakeholders as part of the assessment process.
3.15. Once the DPIA is completed and approved, a record of this will be kept on One Trust and a report sent with risks, mitigations and recommended actions. These should be implemented as soon as possible to remediate and reduce any remaining risks and the Information Compliance team notified of their completion.
3.16. A review period may be set for a re-assessment of the DPIA taking into consideration the nature and risks associated with the processing and any changes to the processing activities or scope of the initiative. The Information Compliance team will determine this requirement with the Business Owner.
3.17. The Information Compliance team should be contacted as soon as possible if there are any changes to the processing activities or scope of the initiative whilst this is ongoing.
3.18. The Information Compliance team will undertake to complete the initial data protection screening within 10 working days, dependent on the complexity of the initiative. The full DPIA may take up to 6-8 weeks to complete as there can be extensive follow-up discussion before a DPIA review can be finalised.
Consultation with the ICO
3.19. Where the outcome of a DPIA is that the processing of personal data in the context of an initiative would result in a high risk and it is not possible to take any measures to eliminate or mitigate that risk, the GDPR requires that the processing cannot commence before the Information Commissioner’s Office (ICO) has been consulted.
3.20. The ICO should not be consulted without the approval of the University’s Data Protection Officer, who will usually initiate contact with the ICO. Consultation with the ICO should only be necessary in very exceptional instances as it is expected that the University will be able to apply measures to appropriately mitigate or eliminate risk on most occasions.