Live 16 practitioner certifications live · First lesson free on every course Back to main site →

Data Protection Impact Assessment (DPIA)

A structured assessment of the privacy risks of a processing activity, mandatory for Significant Data Fiduciaries under Section 10(2)(b) of the DPDP Act 2023.

A Data Protection Impact Assessment is a structured evaluation of a specific processing activity that identifies the personal data involved, the purpose and means of processing, the risks the processing poses to Data Principals, and the mitigations put in place. Under Section 10(2)(b) of the DPDP Act 2023, every Significant Data Fiduciary must undertake DPIAs and other measures as prescribed by the Rules.

A working DPIA follows a consistent structure: description of the processing (what data, from whom, for what purpose, on what legal basis), necessity and proportionality analysis (why this data, why this volume, whether the same purpose could be met with less data), risk assessment (loss of confidentiality, unauthorised access, discriminatory outcomes, reidentification), and mitigation plan (technical safeguards, contractual safeguards, review cadence). The output is signed off by the DPO and referenced in the periodic data protection audit.

DPIAs are also a recognised operator practice under GDPR Article 35, so organisations running parallel EU + India processing typically maintain a single DPIA template that satisfies both regimes. The dcomply Academy GDPR + DPDP Crosswalk Practitioner Certification includes a working DPIA template that aligns to both.

Cited authorities

  • DPDP Act 2023, Section 10(2)(b)
  • DPDP Rules 2025