A DPIA example is the quickest way to see what a finished data protection impact assessment should say, because Article 35 of the GDPR lists what it must contain but not what it looks like. This guide walks through a complete DPIA example for a fictional delivery company about to put telematics and in-cab cameras in its vans, step by step, from the screening decision to the sign-off.
Every section follows the order Article 35(7) sets out and the seven steps the UK Information Commissioner’s Office uses in its own guidance, so you can hold your own DPIA up against it and see what is missing.

What a DPIA Must Contain
Article 35(7) sets the minimum content of every DPIA:
- a systematic description of the processing and its purposes, including any legitimate interest pursued;
- an assessment of the necessity and proportionality of the processing in relation to those purposes;
- an assessment of the risks to the rights and freedoms of the people concerned;
- the measures envisaged to address those risks, including safeguards and security measures.
Around that core, Article 35(2) requires the controller to seek the advice of the data protection officer where one is designated, Article 35(9) asks for the views of the people concerned or their representatives where appropriate, and Article 36 requires prior consultation with the supervisory authority if high risk remains that the measures cannot reduce. The ICO’s guidance on how to do a DPIA turns this into seven steps: identify the need, describe the processing, consider consultation, assess necessity and proportionality, identify and assess risks, identify measures, and sign off. Our DPIA guide explains each requirement in depth.
The Organization in This DPIA Example
Coastline Deliveries (a fictional company) runs 180 vans from four depots. It plans to fit every van with telematics that record location, speed and harsh braking, and an in-cab camera that uses software to detect signs of driver fatigue and send an alert. The data feeds a weekly driver score. The aims are to cut accidents, answer customer queries about deliveries and reduce fuel costs. Around 40 drivers take their vans home at night.
Step 1: Screening
The first question in any DPIA example is whether a DPIA is needed at all. None of the three cases in Article 35(3) applies. Against the nine criteria in the WP248 guidelines endorsed by the European Data Protection Board, the plan meets five:
| WP248 criterion | Met? | Why |
|---|---|---|
| Evaluation or scoring | Yes | The weekly driver score rates each driver’s behaviour |
| Systematic monitoring | Yes | Location and driving are tracked on every shift |
| Sensitive or highly personal data | Yes | Location data and camera images of drivers in the cab |
| Vulnerable data subjects | Yes | Employees, who have little real choice in the relationship |
| Innovative technology | Yes | Fatigue detection from in-cab video |
| Large scale, matching datasets, automated decisions with legal effect, preventing a right or service | No | 180 drivers; data not combined with other sources; no decision is made without a manager |
The guidelines say processing that meets two criteria will usually need a DPIA. At five, the answer is clear, and the screening note records it. Our guide to when a DPIA is required covers the screening tests in full.
Step 2: Describe the Processing
| Part | What Coastline recorded |
|---|---|
| Purposes | Reduce accidents and fatigue-related incidents; answer delivery queries; reduce fuel use |
| Nature | Telematics units send location and driving events every 30 seconds; the camera analyses video in the van and uploads a 20-second clip only when fatigue is detected |
| Scope | 180 drivers; location, speed, braking events, fatigue clips and driver scores; kept on the supplier’s platform |
| Context | Drivers were not consulted at first; some take vans home; in-cab cameras are new to the business |
| Lawful basis | Legitimate interests (safety and operations), with a balancing test recorded |
| Retention | Location 90 days; fatigue clips 30 days unless an incident is under investigation; scores 12 months |
| Recipients and transfers | Telematics supplier as processor; data hosted in the UK; no transfers |
Because the lawful basis is legitimate interests, the balancing test belongs with the DPIA. Our guide to the legitimate interests assessment shows how to record it, and DPIA vs LIA explains how the two documents fit together.
Step 3: Consultation
The data protection officer was involved from the start, as Article 35(2) requires. Coastline also met the drivers’ union representatives and ran a short survey, which is what Article 35(9) means by seeking the views of the people concerned. Drivers accepted tracking during shifts but objected strongly to tracking at home and to continuous video, and those objections shaped the measures below.
Step 4: Necessity and Proportionality in This DPIA Example
| Question | Answer | Explanation |
|---|---|---|
| Does the processing achieve the purpose? | Yes | Trial depot saw fewer harsh-braking events after three months |
| Is there a less intrusive way? | Partly | Location is not needed outside shifts; a privacy mode will switch it off |
| Is only the data needed collected? | Partly | Continuous video was proposed; only fatigue-triggered clips are needed |
| Is retention justified? | Yes | Periods set per category, as above |
| Are drivers told? | Yes | Driver privacy notice and a briefing at each depot |
| Can drivers exercise their rights? | Yes | Drivers can see their own data and challenge a score with their manager |
Two “partly” answers are not a failure: they are the DPIA doing its job. Each one became a design change.
Step 5 and 6: Risks and Measures
Risks are rated for the drivers, not the company, on 1 to 5 scales for likelihood and severity. The DPIA example uses the same scale throughout, so levels can be compared:
| Risk to drivers | Level before | Measures | Level after |
|---|---|---|---|
| Tracking of private movements when vans are taken home | 16 High | Privacy mode outside shift hours; location hidden from managers after hours | 6 Medium |
| Continuous in-cab video intruding on drivers’ privacy | 15 High | Video analysed in the van; only fatigue clips uploaded; no audio | 6 Medium |
| Unfair disciplinary action based on the driver score alone | 12 High | Score never used alone; a manager reviews context before any action; drivers can contest | 6 Medium |
| Fatigue alerts wrongly triggered for some drivers | 12 High | Accuracy checked by depot during a 3-month pilot; human review of every alert | 8 Medium |
| Supplier access to video and location data | 8 Medium | Processor contract, UK hosting, access logging | 4 Low |
If the driver score had been used to make disciplinary decisions without any human involvement, the DPIA would also have to deal with Article 22 on solely automated decisions. Our article on UK GDPR automated decision-making covers that test.
Step 7: Sign-off and the Article 36 Decision
After the measures, no risk in this DPIA example remains High, so prior consultation with the supervisory authority is not required. Had one remained High with no further measure available, Article 36 would require Coastline to consult the authority before starting; the authority then has up to eight weeks to respond, extendable by six weeks for complex processing.
The sign-off records the DPO’s advice (make the privacy mode automatic rather than driver-activated; delete clips after 30 days), notes that both points were adopted, records the union’s views, and sets the outcome: proceed once the measures are in place. The operations director approved it, with a review date twelve months on or sooner if the system changes.
Common Mistakes This DPIA Example Avoids
- Doing it after launch. Article 35(1) requires the DPIA before the processing starts. Coastline’s was done during the pilot, while the design could still change.
- Rating risk to the company. Fines and reputation matter, but a DPIA is about the people whose data it is.
- Skipping necessity. A risk table alone is not a DPIA. The necessity and proportionality test is where the design changed most.
- No record of the DPO’s advice. If it is not written down, there is no evidence it was sought.
- Never reviewing it. Article 35(11) expects a review at least when the risk changes, such as a new camera feature or a new use of the scores.
Frequently Asked Questions
Can I reuse this DPIA example as a template?
The structure transfers to any processing: screening, description, necessity, risks, measures and sign-off. Replace the facts, ratings and measures with your own; a DPIA copied from someone else’s processing will not describe yours.
How long should a DPIA be?
Long enough to cover the four elements in Article 35(7) for the processing in question. For a single system like this one, a clear DPIA often fits on a handful of pages plus the risk register.
Is a DPIA the same as a privacy risk assessment?
No. A DPIA looks at one processing operation before it starts; a privacy risk assessment looks across all of your processing. Our comparison of privacy risk assessment vs DPIA explains how the two fit together.
Does a DPIA have to be published?
No, the GDPR does not require publication, although publishing a summary can help build trust. It must be available to the supervisory authority on request.
To build your own DPIA in the same order, use our free DPIA template, which screens the processing, tests necessity, rates the risks to individuals and flags whether prior consultation is needed. For the policies, records and templates around it, see the GDPR Toolkit.