Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Data Protection Impact Assessments for ML Projects
Software Strategy

Data Protection Impact Assessments for ML Projects

When a machine learning project needs a formal assessment, what it should contain, and why doing it early improves the design rather than delaying it.

Updated 2 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Projects involving systematic evaluation of people, large-scale personal data or automated decisions with significant effects generally require an assessment. Doing it at design stage tends to improve the system; doing it before launch to tick a box tends to delay it. This is general information, not legal advice.

When one is likely needed

A data protection impact assessment is required where processing is likely to result in high risk to individuals. Machine learning projects frequently land in that category without anyone noticing, because the processing looks like ordinary analytics.

  • Systematic and extensive evaluation of people, including profiling and scoring
  • Automated decisions producing legal or similarly significant effects
  • Large-scale processing of special category data
  • Systematic monitoring, including of employees
  • Combining datasets in ways individuals would not expect
  • Using personal data for a purpose different from the one it was collected for

That last point catches many internal projects. Data collected to fulfil orders, repurposed to predict customer behaviour, is a change of purpose and needs thinking about. We are describing general practice here rather than giving legal advice - take proper advice for your situation.

Do it while the design can still change

An assessment written after the system is built becomes a documentation exercise, and any problem it finds is expensive. Written during design, it is genuinely useful and frequently improves the system.

Questions like 'do we need this field at all', 'could this work on aggregated data' and 'how long should we keep this' are design questions. Answering them early usually produces a simpler system with less to protect.

What it should actually contain

  1. What the processing is, in plain language a non-specialist can follow.
  2. Why it is necessary, and whether a less intrusive approach would achieve the same purpose.
  3. The lawful basis, and where relying on legitimate interests, the balancing assessment.
  4. What data, from where, retained how long, and who can access it.
  5. The risks to individuals - not to the business - and their likelihood and severity.
  6. The mitigations, and the residual risk after them.
  7. Whether decisions are automated, and what human involvement exists.

The distinction in point five is the one most often got wrong. A DPIA assesses risk to people, not commercial or reputational risk to you.

Questions specific to machine learning

QuestionWhy it matters
Can training data be minimised or aggregated?Often the model needs less than was assumed
Could the model infer special category data?Inferred health or ethnicity carries the same protections
Can an individual be identified from outputs?Models can leak training data in some circumstances
How is accuracy monitored across groups?Uneven performance is a fairness risk
What is the route to challenge a decision?Often required, and usually not designed

The second row surprises people. A model predicting something innocuous from behaviour may effectively infer a protected characteristic, and inferences attract the same protections as collected data.

Keep it alive

A DPIA is not a launch artefact. Retraining on new data, adding a feature, extending to a new customer group or changing what the output drives can all alter the risk profile.

Reviewing it when the model materially changes keeps it accurate and demonstrates the ongoing accountability regulators look for. Attaching the review to your existing model release process is the practical way to make that happen rather than relying on memory.

An assessment written after the build measures a decision you already made.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Who should write the DPIA?

Usually the project owner with input from the data protection lead, plus technical input on what the system actually does. It should not be written by one person in isolation.

Does anonymised data need one?

Genuinely anonymous data falls outside data protection law, but the bar is high - pseudonymised data with a key still counts as personal data.

What if the assessment finds high residual risk?

In several jurisdictions that triggers a requirement to consult the regulator before proceeding. Take specific advice.

Do we need one for a model bought from a vendor?

Probably, since you remain the controller for how it is used on your data. The vendor's documentation informs it but does not replace it.

Keep reading

More on Software Strategy

Software Strategy

Machine Learning Myths That Waste Budgets

Eight beliefs about machine learning that quietly inflate project costs, what is actually true instead, and how to spot each one in a proposal.

Start here

Want machine learning project details from us?

Tell us what you are trying to predict and roughly what data you hold. We will come back with an honest view on whether machine learning is the right tool, what the work would involve and a realistic cost range. If a spreadsheet would do the job, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →