Last reviewed: August 2026.
This deserves a careful answer, because the honest one is more useful than a simple one.
The Personal Data Protection Act 2010 does not contain a section that says "you must carry out a DPIA". There is no standalone statutory DPIA duty in the Act itself.
What exists is this. Section 12A of the Act requires data controllers and data processors to appoint a Data Protection Officer. The Commissioner's Circular No. 1/2025 sets out what that officer is responsible for, and one of those responsibilities is supporting and advising on DPIAs. The DPIA Guideline is then issued by the Commissioner under section 48(g) of the Act to set out the requirements for carrying them out.
The Guideline itself is written in obligatory language. Where a data controller foresees that a planned processing operation is likely to result in a high risk to personal data protection, it states that a DPIA shall be carried out.
In our view, the practical position is straightforward even if the statutory route is indirect. A data controller who processes personal data in the circumstances the Guideline describes, and who has carried out no DPIA, would be in a difficult position if the Commissioner asked why. Whether or not you characterise it as a strict statutory duty, it is the standard against which your decision-making will be measured.
Our advice to clients is to treat it as a requirement and to keep a written record of the decision either way. Where you have concluded that no DPIA was needed, that conclusion is itself worth documenting.
Two things follow from the timing, and they catch people out:
It is prospective. A DPIA is for a planned processing operation. If the system is already live, you are no longer doing a DPIA in the way the Guideline intends. You are doing remedial work.
It has an owner. The obligation sits on the data controller, and ultimate responsibility for the assessment and for whatever is decided as a result sits with senior management. Not with IT. Not with the vendor.
Four roles, and they are commonly confused.
The data controller carries the obligation. The Guideline is explicit that this is because a data processor does not process personal data for its own purposes, so it is the controller who decides whether an activity proceeds and who must make sure the risks are addressed.
Senior management carries ultimate responsibility for the assessment and for the decisions that follow from it. Where the overall residual risk comes out as high, the findings must be reported to them. In practice most organisations report all findings regardless of level, so that management is not partially informed.
The Data Protection Officer supports rather than executes. Under the Guideline the DPO's role is to identify whether a DPIA is needed at all, advise on carrying it out and on the mitigation measures, and develop templates and checklists suited to the organisation.
The DPIA Lead runs the exercise. This may be the DPO, but it may equally be the project manager or someone else the controller considers appropriate. The Lead gathers input from the people who actually understand the processing.
Beyond those four, the Guideline expects input from the project manager, IT, legal, any relevant subject matter experts, the data processor, and relevant third parties.
Look at the first item on the DPO's list again: identifying whether a DPIA is needed at all.
That is a judgment call, it has to be made by someone with the standing to make it, and it has to be made before the project starts rather than after. If your organisation has not appointed a DPO, or has appointed one in name without the time or the background to make that call, then nobody is making it. The question is not being answered wrongly. It is not being asked.