S2 Ep39:Why Most DPIAs Get Signed Off Too Late to Matter
Data Protection Made Easy Podcast
Written by Caine Glancy and Catarina Santos
A DPIA signed off after the key decisions are made can’t do its job. Join Caine Glancy and Catarina Santos to explore why timing keeps slipping, and what it takes to embed DPIAs earlier in project design.
S2 Ep39:Why Most DPIAs Get Signed Off Too Late to Matter
Live with the Data Protection Made Easy community on Friday 16 October 2026 at 12:30pm.
A DPIA signed off after the key project decisions have already been made can’t do what it’s meant to do: influence design and reduce risk before it’s built in.
Join Caine Glancy and Catarina Santos to explore why this keeps happening, and what needs to change for DPIAs to have real influence rather than just serving as a compliance formality.
What This Session Will Cover
- Why DPIAs so often get approved after key decisions are already made
- The practical consequences of leaving DPIAs until late in a project
- Common barriers to earlier engagement with data protection teams
- Steps organisations can take to embed DPIAs earlier in project design
- What “good” timing actually looks like in practice
Why This Topic Matters
When a DPIA is signed off too late, it stops being a design tool and becomes a paperwork exercise. The risks it should have caught are already baked into the project.
This session looks at why timing keeps slipping and what practical changes can help DPIAs do the job they’re actually meant to do.
Who Should Attend?
- Data Protection Officers
- Privacy and information governance professionals
- Project and product managers
- Compliance and risk teams
- Anyone involved in running or feeding into DPIAs
Meet Your Hosts
Caine Glancy
Catarina Santos
Caine and Catarina will guide the discussion and share practical perspectives on getting DPIA timing right.