SaaS · Compliance

SaaS DPIA — A Field Guide

A DPIA is GDPR's structured way of thinking through the privacy risk of what you're building — required for high-risk processing, and useful well beyond the cases where it's mandatory.

John Kihiu12 min read

A Data Protection Impact Assessment (DPIA) is a structured process for identifying and reducing the privacy risks of a data-processing activity. Under GDPR it is legally required for high-risk processing, but it is worth understanding as more than a compliance chore: it is a disciplined way to think through the risk you are creating for the people whose data you handle, before you handle it.

When a DPIA is required

GDPR mandates a DPIA when processing is likely to result in a high risk to individuals' rights and freedoms. Certain activities trigger it clearly:

When in doubt, doing one is rarely wrong — it demonstrates the accountability GDPR expects, and it surfaces risks you would otherwise meet after launch.

How to run one

A DPIA is not a form to file; it is an assessment. Describe the processing — what data, why, how, and for how long. Assess necessity and proportionality: do you actually need this data for this purpose, or could you achieve the goal with less? Then identify the risks to individuals — not to the company, but to the people whose data it is — and the measures that reduce those risks. Document the residual risk and the decision to proceed. The individual's perspective is the part teams most often skip and the part that matters most.

Build it into development

The value multiplies when the DPIA happens before you build, as part of designing the feature — this is data-protection-by-design in practice. Assessing privacy risk at the design stage lets you reduce it cheaply, by collecting less data or anonymising it, rather than retrofitting protections onto a shipped system. A DPIA run after launch is a compliance record; one run during design is an actual risk-reduction tool.

Assess risk to people, not to the company

The single most common DPIA mistake is assessing business risk — fines, reputation — instead of risk to the individuals whose data is processed. GDPR cares about the data subject's rights and freedoms. Frame every risk from their perspective: what could go wrong for them, and how you have reduced it. That framing is the whole point of the exercise.

A DPIA is GDPR's structured privacy-risk assessment, required for high-risk processing and valuable whenever you handle sensitive data at scale: describe the processing, test its necessity, assess the risk to individuals, and reduce it — ideally at design time. Treat it as data-protection-by-design rather than paperwork, and it protects both the people in your database and the business that depends on their trust.

John Kihiu
Acumatica ERP Developer · Laravel Engineer

Independent software engineer in Nairobi specialising in Acumatica customisations, Laravel backends, and tax fiscalisation integrations across East and Southern Africa.