24 September 2026

DPIA Fatigue: Are Organisations Assessing Too Much?

By Alison Sigsworth, Information Governance Manager

When the General Data Protection Regulation first came into being, many organisations went into panic mode and began completing a Data Protection Impact Assessment (DPIA) for every system, process, or project that involved processing someone’s name and address. Whilst many people now have a clearer understanding of data protection requirements, there are still many that believe that a DPIA must always be completed to ‘tick a box’. This has led to a growing volume of DPIAs being carried out, but is this actually reducing risk or just becoming a burden?

What is a DPIA and when should one be completed?

A Data Protection Impact Assessment is exactly that, an assessment to consider the risks and potential impact of processing people’s personal data. It helps an organisation to identify and assess any high risks to individuals’ rights and freedoms and allows you to put in place measures to mitigate those risks. The key point here is ‘high risk’. A DPIA was never intended to be a form to complete for every activity that involves handling someone’s basic details.

Although a DPIA is mandatory in some cases, such as large-scale use of personal data, systematic and extensive profiling, and monitoring public spaces, other cases need to take a risk-based approach. If the processing involves low-risk activities that are unlikely to impact individuals, for example, a routine software update, a minor process change, or sharing minimal contact details to simply set-up an account, a DPIA is usually not needed.

The rise of ‘DPIA Fatigue’

While being cautious is understandable, this can lead to ‘DPIA fatigue’. Someone may become so overwhelmed with the volume of assessments, that they rush through them, giving very little thought to any actual risks or potential for harm, just so they can tick the box to say that a DPIA has been completed. Then, when there really is a new project or system that needs real consideration, time, and resource, they can’t possibly look at another DPIA for the rest of their life and throw in the towel!

Perhaps this is slightly dramatic, but this can be a real issue.  By completing assessments for every single activity, they have forgotten what the real purpose was, which is considering how processing people’s personal information could cause them significant harm, and putting measures in place to ensure that these people can continue to rely on the organisation to keep their data safe and maintain their trust.

The hidden cost of over-assessment

DPIA overload can create several challenges:

  • Reduced capacity to review genuinely high-risk activities.
  • Delayed systems and project delivery caused by unnecessary work.
  • Assessment fatigue among staff who begin to view data protection requirements as a ‘tick-box exercise’.
  • Lower quality assessments as teams attempt to process increasing volumes of work.

Most importantly, organisations may develop a false sense of assurance. Having a large volume of completed DPIAs does not necessarily mean that your organisation is compliant and assessing risk correctly. Instead, organisations need to make sure that DPIAs are completed for the right activities; those that pose a high risk. One way to do this is by carrying out a screening exercise to help identify those processes, projects, and systems that could likely cause significant harm and impact individuals. For any that indicate a full DPIA isn’t needed, a privacy by design approach can be followed.

Finding the right balance

DPIAs remain one of the most valuable tools available to assess data protection risk. They help us to understand risk, demonstrate accountability, and build trust. As organisations face growing demands with limited resources, the challenge may not be encouraging more DPIAs but ensuring that focus is on the processing activities that genuinely deserve it.

If you’d like to learn more about DPIAs and how to ensure your organisation finds the right balance, our upcoming CPD UK accredited course, Privacy by Design, next runs on 27 October, 9:30am – 1pm. To learn more or book your place, click the links above or get in touch by emailing info@naomikorn.com.

Recent News

Back to News

Discover more from Naomi Korn Associates

Subscribe now to keep reading and get access to the full archive.

Continue reading