top of page

How to Conduct a Data Protection Impact Assessment (DPIA) for Surveillance Activities

By SIASS

Surveillance activities can be an essential tool in investigations, fraud prevention, litigation support, and safeguarding legitimate business interests. However, because surveillance often involves the collection and processing of personal data without an individual's knowledge, it can present significant privacy risks.

Under UK GDPR, organisations must assess and manage these risks through a Data Protection Impact Assessment (DPIA). In many surveillance scenarios, a DPIA is not simply good practice – it is a legal requirement.

What is a DPIA?

A Data Protection Impact Assessment is a structured process that helps organisations identify, assess, and minimise the privacy risks associated with processing personal data.

The Information Commissioner's Office (ICO) describes a DPIA as an "early warning system" that enables organisations to identify and address potential privacy issues before processing begins.

A DPIA should be completed before surveillance activities commence and should be reviewed whenever circumstances change.

When is a DPIA Required?

A DPIA is mandatory where processing is likely to result in a high risk to the rights and freedoms of individuals.

Surveillance activities commonly trigger this requirement because they often involve:

  • Covert observation or monitoring.

  • Tracking individuals' movements.

  • Collection of personal information without direct interaction.

  • Processing special category data.

  • Processing criminal offence data.

  • Monitoring behaviour over a period of time.

If there is any doubt, organisations should err on the side of caution and complete a DPIA.

Step 1: Define the Purpose

Before considering surveillance, clearly identify:

  • Why the surveillance is necessary.

  • What legitimate objective is being pursued.

  • Whether the objective can be achieved by less intrusive means.

Ask yourself:

Is surveillance genuinely necessary, or could the same result be achieved through interviews, audits, document reviews, or other investigative methods?

If a less intrusive option exists, surveillance may not be justified.

Step 2: Describe the Processing

Document exactly what will happen during the surveillance operation.

This should include:

  • Who is being monitored.

  • What information will be collected.

  • How information will be obtained.

  • How long surveillance will take place.

  • Whether images, video, audio, or tracking data will be collected.

  • Who will have access to the information.

  • How the information will be stored and secured.

The more detailed the description, the easier it will be to assess the risks.

Step 3: Identify the Lawful Basis

Every surveillance activity must have a lawful basis under UK GDPR.

In many investigative scenarios, organisations rely on:

  • Legitimate Interests

  • Legal Obligations

  • Establishment, Exercise or Defence of Legal Claims

The chosen lawful basis must be documented and justified.

If special category data or criminal offence data may be collected, additional legal conditions will also apply.

Step 4: Assess Necessity and Proportionality

A key question is whether the surveillance is proportionate to the issue being investigated.

Consider:

  • How serious is the issue?

  • How intrusive is the surveillance?

  • What impact could the surveillance have on the individual?

  • Are there safeguards in place to minimise intrusion?

The greater the intrusion, the stronger the justification must be.

For example, monitoring a suspected fraudulent insurance claim may be easier to justify than monitoring routine employee conduct.

Step 5: Identify Privacy Risks

Consider all potential risks to the rights and freedoms of individuals.

Examples include:

  • Unauthorised disclosure of personal data.

  • Excessive data collection.

  • Misidentification.

  • Reputational damage.

  • Emotional distress.

  • Loss of confidentiality.

  • Collection of information about third parties not directly involved in the investigation.

Document each identified risk.

Step 6: Identify Mitigation Measures

For every risk identified, consider how it can be reduced.

Typical mitigation measures include:

  • Limiting surveillance duration.

  • Restricting surveillance locations.

  • Providing investigator training.

  • Applying strict access controls.

  • Encrypting recordings and evidence.

  • Establishing retention and deletion schedules.

  • Conducting regular supervisory reviews.

The aim is to reduce privacy risks to the lowest practical level.

Step 7: Record and Approve the DPIA

The DPIA should be formally documented and approved by the appropriate decision-maker within the organisation.

The completed assessment should include:

  • Purpose of the surveillance.

  • Lawful basis.

  • Risk assessment.

  • Mitigation measures.

  • Final decision and rationale.

This record demonstrates accountability and may be required if challenged by regulators, courts, clients, or data subjects.

Step 8: Review the Outcome

A DPIA is not a one-off exercise.

Review the assessment if:

  • The scope of surveillance changes.

  • New technology is introduced.

  • Additional personal data is collected.

  • New risks emerge.

Regular review ensures that the surveillance remains lawful, necessary, and proportionate.

What If High Risks Remain?

If a DPIA identifies a high risk that cannot be adequately mitigated, the organisation may need to consult the Information Commissioner's Office before proceeding.

This requirement should never be ignored.

Proceeding with high-risk processing without appropriate safeguards can lead to enforcement action, financial penalties, and reputational damage.

Final Thoughts

A properly conducted DPIA is more than a compliance exercise. It demonstrates that surveillance has been carefully considered, is genuinely necessary, and respects individuals' privacy rights.

For organisations conducting surveillance, investigations, or litigation support activities, a robust DPIA provides evidence of accountability, professionalism, and compliance with UK GDPR.

At SIASS, we encourage all organisations and investigators to make DPIAs an integral part of their surveillance planning process. Doing so not only reduces legal risk but also helps maintain public trust in the responsible use of surveillance.

Comments


SIASS Limited
58 Low Friar Street
Newcastle upon Tyne
NE1 5UD


07919475876
email@siass.org.uk

Protecting privacy. Supporting investigations. Delivering clarity.

© 2020 by SIASS

 

Frequently asked questions

bottom of page