Company Brochure

Data Protection Impact Assessments on the Isle of Man: When One Is Required and How to Do It

A compliance team assessing data-protection risk before a new project on the Isle of Man

Strengthen your compliance strategy

— with confidence. clarity. experts.

Book a
consultation

A Data Protection Impact Assessment is required on the Isle of Man wherever a type of processing is likely to result in a high risk to the rights and freedoms of individuals. The obligation is set by Article 35 of the Applied GDPR — the Island's own regime, enforced by the Isle of Man Information Commissioner, not the UK ICO and not an EU authority. You decide whether one is needed as early as practicable in a project, and always before processing begins.

That last point is where most of the difficulty lives. A DPIA is not a form you complete after go-live to tidy the file; it is a decision you make at the design stage, and getting the trigger wrong carries real consequences. This post sets out how the Commissioner actually approaches DPIAs — the test for "high risk", what the assessment has to contain, who signs it off, and what happens if you skip one that was required.

Do DPIAs even apply on the Island?

Yes — and this is the first thing to settle, because "impact assessment" reads to many people as an EU import that stops at the water. It does not. The DPIA duty applies here through the Applied GDPR, the framework created by the Data Protection (Application of the GDPR) Order 2018 alongside the Data Protection Act 2018 and the GDPR and LED Implementing Regulations 2018. Article 35 sits inside that applied text as Manx law. We cover how the whole regime fits together in our guide to GDPR compliance for Isle of Man firms, but the short version is that the substance mirrors the GDPR you have read about while the instrument and the regulator are local.

The practical consequence is that your reference point is the Isle of Man Information Commissioner's guidance on Data Protection Impact Assessments at inforights.im — not ICO templates and not EU supervisory-authority material. The underlying method is largely shared, but the accountability is Manx: it is the Island's Commissioner who can require a DPIA, who must be consulted where a high risk remains, and who enforces the duty. Citing "the ICO" in your assessment signals you have not mapped the obligation to the jurisdiction that actually governs you.

A compliance officer reviewing a new-project data flow on the Isle of Man

When is a DPIA actually mandatory?

The trigger, in the Commissioner's own words, is that "a DPIA is required where a type of processing is likely to result in a high risk to the rights and freedoms of individuals." That is a genuine test, not a box-ticking category — which is exactly why firms find it slippery. To make "high risk" workable, the Commissioner adopts the nine screening criteria set out by the European Data Protection Board. Meeting two or more of them makes a DPIA likely required; in some cases meeting even one is enough. Timing runs alongside the test: you make this assessment as early as practicable in the lifecycle of a project and, in all cases, before processing commences.

The nine criteria are worth knowing by name, because they map onto ordinary business projects far more often than firms expect. They are: evaluation or scoring, including profiling and predicting; automated decision-making with legal or similarly significant effect; systematic monitoring, including of a publicly accessible area — CCTV, ANPR, or monitoring staff email and internet use; special-category data under Article 9 together with criminal-offence data, and financial, location or communications data; data processed on a large scale; datasets matched or combined in ways beyond individuals' reasonable expectations; data about vulnerable subjects such as employees, children or patients; innovative use or new technology; and processing that prevents people from exercising a right or using a service or contract.

Read that list against a real project and the answer usually becomes clear. Workplace CCTV that also monitors staff touches systematic monitoring and vulnerable subjects — two criteria, DPIA. A new HR analytics tool that scores employees touches evaluation, vulnerable subjects and new technology. This is the honest answer to "mandatory versus nice-to-have": there is no closed list of three magic categories that switches the duty on. There is a risk test, operationalised through nine flags, and the moment two of them light up you are almost certainly in scope.

We help Isle of Man firms screen new projects against the nine criteria and decide, on the record, whether a DPIA is required.

What a DPIA must contain, and who signs it off

Once you are in scope, the Article 35 requirements — which the Commissioner runs across a structured, eight-step process — define what the assessment has to do. Four elements sit at its core. First, a systematic description of the processing and its purposes: what data, from whom, how it flows, and why. Second, an assessment of necessity and proportionality — identifying your lawful basis under Article 6 (and Articles 9 or 10 for special-category or criminal-offence data), and asking whether a less intrusive means would achieve the same end, which is where data protection by design and by default under Article 25 does its work.

Third, an assessment of the risks to individuals themselves — identity theft, fraud, financial loss, reputational or physical harm, discrimination — each weighed by likelihood and severity rather than treated as a vague worry. Fourth, the measures to mitigate those risks and bring them down to an acceptable level. Where appropriate, Article 35(9) expects you to go further and consult the people affected: "Where appropriate the controller shall seek the views of the data subjects or their representatives on the intended processing." That step is easy to skip and often the most persuasive evidence that the assessment was genuine.

On sign-off: the DPIA is the controller's responsibility. In practice it is owned by whoever is accountable for the processing — typically a senior manager or the project sponsor — with the data protection officer advising and, where one is appointed, reviewing the assessment. If your firm uses an outsourced DPO, that adviser will normally help scope, challenge and quality-check the DPIA, but the decision to proceed remains with the controller, not the DPO. The document is a governance record, so it should carry a clear owner, a date, and evidence of who reviewed it.

Senior managers signing off a completed impact assessment

What happens if a high risk remains

Completing a DPIA does not automatically clear you to proceed. If, having assessed the risks and applied your mitigations, a high risk to individuals still remains, the Applied GDPR requires that the Information Commissioner be consulted before any processing takes place. This is the Article 36 prior-consultation obligation, and it is a genuine stop point: you do not press ahead and hope. In our experience it is rarely reached, because a well-run DPIA usually finds mitigations that bring residual risk down — but where it cannot, the referral is not optional.

The consequence of ignoring the duty altogether is where the guidance is bluntest. Failing to undertake a DPIA that was required "may result in a monetary penalty being imposed and an Order imposing a ban on processing." A processing ban is often the sharper sanction than any fine: a system you have built and launched can be ordered to stop. That is the real reason to make the trigger decision early — the cost of getting it wrong lands after you have already invested in the project.

A DPIA is also not a one-off artefact. Keep it under review and repeat it on any substantial change — a new data source, a new purpose, a new supplier — and treat publication as good practice rather than an exposure. Like the wider accountability duty under Articles 5 and 24, a DPIA that is filed and forgotten stops evidencing anything the moment the processing moves on.

We review draft and existing DPIAs against the Commissioner's expectations and flag where residual risk means prior consultation is needed.

Common mistakes we see

The most common error is timing: running the DPIA after the system is built, as a compliance write-up rather than a design tool. By then the assessment cannot change anything, and its main value — steering the processing towards a less intrusive design — is gone. The Commissioner's own framing is that the decision belongs at the start of the project lifecycle.

Close behind is under-scoping the trigger. Firms look for one obvious "sensitive data" flag, do not find it, and conclude no DPIA is needed — missing that two lesser criteria together, such as monitoring of employees plus new technology, already put them in scope. A related mistake is treating the nine criteria as if they were the closed EU-style list of mandatory categories; they are a screening aid for a risk test, and the risk test is what governs.

We also see DPIAs that describe the processing well but never actually assess risk to individuals — no likelihood, no severity, no mitigation weighed against residual risk — and DPIAs with no named owner or review date. And occasionally the most serious: a residual high risk identified honestly in the document, but no referral to the Commissioner under Article 36 before go-live. The assessment was done; the obligation it triggered was not.

An organised set of data-protection governance records kept under review

If you are standing up a new system or supplier arrangement and are not sure whether it crosses the threshold, it is cheaper to settle that at the design stage than to unpick a live process later.

Frequently asked questions

Do DPIAs apply on the Isle of Man, or is that an EU rule?

They apply on the Island. The duty comes from Article 35 of the Applied GDPR — the Data Protection (Application of the GDPR) Order 2018, read with the Data Protection Act 2018 and the GDPR and LED Implementing Regulations 2018 — and is enforced by the Isle of Man Information Commissioner, not the UK ICO or an EU authority. The method resembles the wider GDPR, but the law and the regulator are Manx.

When is a DPIA mandatory rather than optional?

Whenever a type of processing is likely to result in a high risk to individuals. The Commissioner assesses this through the European Data Protection Board's nine criteria — evaluation or scoring, automated decisions with significant effect, systematic monitoring, special-category or criminal data, large-scale processing, unexpected data matching, vulnerable subjects, new technology, and processing that blocks a right or service. Meeting two or more makes a DPIA likely required, and one may be enough.

Who signs off a DPIA?

The controller is responsible for the DPIA, so sign-off sits with whoever is accountable for the processing — usually a senior manager or project sponsor — advised and reviewed by the data protection officer where one is appointed. An outsourced DPO can scope and challenge the assessment, but the decision to proceed remains the controller's, and the document should record its owner, date and reviewer.

What if a high risk remains after the DPIA?

Then the Isle of Man Information Commissioner must be consulted before any processing takes place — the Article 36 prior-consultation obligation. Failing to carry out a required DPIA at all can, under the Commissioner's guidance, lead to a monetary penalty and an Order banning the processing, which is why the trigger decision belongs at the start of a project rather than after launch.

Get the trigger decision right at the design stage and the DPIA becomes the cheapest insurance in the project; get it wrong and the bill arrives after everything is built.

Knight Consultancy Limited
(Company No: 136669C)
Design House, Hills Meadow, Douglas,
Isle of Man ,IM1 5EB

© Knight Consultancy Limited {{Y}}. All Rights Reserved. Privacy Policy

Website and marketing partner: Yellowstone Accounts

Knight