Glossary / Compliance
What is Data Protection Impact Assessment (DPIA)?
A DPIA is a structured assessment of privacy risk carried out before deploying technology, such as a camera-equipped robot, that processes personal data in a way likely to affect individuals.
Last reviewed:
Under UK GDPR, a Data Protection Impact Assessment is required where new technology is likely to result in a high risk to individuals' rights and freedoms. Robots equipped with cameras for navigation or safety can trigger this requirement, particularly in sensitive settings like healthcare or areas with vulnerable people, because they capture footage of a public or semi-public space.
A DPIA identifies what data is captured, how long it's retained, who can access it, and what safeguards are in place, such as footage being used only for immediate obstacle detection rather than stored or reviewed routinely. It should be documented before deployment, not treated as an afterthought.
A responsible robot supplier should be able to describe, in plain terms, what their robot's cameras actually record, whether footage is stored, and how that fits with a customer's own data protection obligations, to support the customer's own DPIA process.
Common questions
- Do I need a DPIA to deploy a cleaning robot?
- If the robot uses cameras in a way likely to affect individuals' privacy — particularly in sensitive settings — a DPIA is good practice and may be a legal requirement under UK GDPR.
- Do robot cameras record and store footage?
- This depends on the model; many process camera data only in real time for navigation and safety without storing it, but you should confirm this directly with the supplier.
- Who is responsible for the DPIA, us or the robot supplier?
- The deploying organisation is generally responsible for the DPIA, but a good supplier will provide the technical detail needed to complete it accurately.
Related terms
Next steps
