Section 10 of the template

Impact assessment & product safety checks

When you need a DPIA, what a product-safety check covers, and a free tool to get the assessment started.

Home › Impact assessment & product safety checks

A DPIA, or Data Protection Impact Assessment, is simply the structured assessment the law requires whenever a tool is likely to create a high risk to people. Done early, before decisions are made, it’s exactly what the DfE guidance expects.

What it is

The trigger and the process: a DPIA before you deploy AI that processes personal data; the product-safety checks that align to the DfE generative AI product safety standards; and the point in procurement where these happen, which is during tool approval, not after go-live. It sets out who coordinates the assessment (your DPO or data protection lead) and who signs it off.

Why it’s important

A DPIA completed after a tool is already embedded changes very little; the decisions have been made. Completed early, it brings the controller and processor question, international transfers, retention, sub-processors, and any training on your data into view before you’re committed. A tool that lacks a particular compliance feature isn’t ruled out automatically: the question is whether you can put sensible operational safeguards around it, and record them.

Get the screening tool

The AI & Digital Tool DPIA Screening Tool is a plain-English questionnaire that runs in your browser, for any AI or digital product you’re thinking of buying. It works through purpose, data, roles, transfers, retention, automated decisions and what the supplier does with the data, then tells you whether your answers are detailed enough to send to your DPO for sign-off. Unlock a copy to keep and reuse.

A non-negotiable

A DPIA before you deploy AI that processes personal data is a non-negotiable. The screening tool supports that assessment; it doesn’t replace your DPO’s sign-off.