The key components of DART 2.0

An overview of the key components of DART 2.0 introducing users to the platform, its functionality and the basics for how to utilise it. Voiceover by Adriyana Stefanova.

0 - 1 mins

Introduction to launch page.

1 - 4 mins

Declare a new or existing dataset.

4 - 6 mins

Register a new / view risk assessment.

6 - 8 mins

Exploring a DART entry.

8 - 8:30 mins

The ‘Document upload’ page.

8:30 - 12:48 mins

Creating, Linking and Declaring a dataset and DART entry.

Data Activity Risk-Assessment Tool (DART)

DART 2.0 is here!

To ensure we comply with data protection legislation (e.g. the UK General Data Protection Regulation (GDPR) and Data Protection Act 2018) and to improve the management of information assets and associated risks across the university, the DART platform is being refreshed to ensure everyone can complete a data risk assessment efficiently.

We are also expanding the data scope to include non-personal data.

What's Changing?

  • Expanded data scope: The new DART will include both personal and non-personal data, broadening our approach to comprehensive data management.
  • Enhanced user interface: A refreshed look and feel that is designed to be more user-friendly and efficient.
  • Shift in data ownership: The responsibility for completing DART entries is with the person who owns the data, and we’ve implemented a requirement to declare any data you are using before submission.
  • Name change: The old Data Asset Registration Tool is now called Data Activity Risk-assessment Tool.

What Do I Need to do?

We are transferring DART entries over to the new platform in a phased approach until we can close the old platform in 2026, and therefore you will see two versions running in parallel. 

For New DART Submissions After 1 December 2025

Please use the following link - DART 2.0

IMPORTANT INFORMATION

  • The first time you access DART 2.0 you will be requested to provide access/link systems that DART is built upon. Please ensure these are allowed.
  • To ensure the best possible performance, please use Google Chrome or Microsoft Edge for access DART. For Firefox, you must first ensure the 'Block pop-ups and third party redirects' is disabled via settings (Settings>Privacy & Security) entirely or by adding an exception for https://apps.powerapps.com/

DART 2.0 Guidance / User Guide:

For 'Old' DART Submissions Already Being Created / Finalised

Please use the following link DART v1.0

DART 1.0 Guidance / User Guide:

Please note that following DART 2.0 going live, you will not be able to add any new DART entries but you can amend / complete / update any that are already present.

Why Do I Need to Do It?

Completing DART entries achieves the following;

  • the creation of Data Protection Impact Assessments (DPIAs), which can be downloaded as a PDF;
  • population of the university Records of Processing Activity (RoPA), to help ensure personal data is being recorded and managed in an effective manner;
  • adherance to contracts where it is legally required to record such information. For example, where the university is acting as a data processor for another organisation(s), such records are mandatory and form part of the contracts agreed with the other organisation(s).
  • population of the university Information Asset Register (IAR) and Records of Processing Activities, which captures all activities involving university data – not just those activities which including personal data - for the purpose of oversight, risk identification and risk mitigation. 

When to Conduct a DART Registration

Any activity / project that processes (uses, stores, analyses etc.) university data, see definitions of university data via the Information Security Policy (PDF) , requires the completion of a DART registration. 

The following scenarios would automatically require the completion of a full DPIA and as such a specific DART Registration:

  • when the university is acting as a data processor (i.e. providing a service / action which includes personal data) to another organisation(s).
  • systematic and/or extensive profiling with significant affect on individuals;
  • processing special category or criminal offence data;
  • processing any data that is deemed to be ‘Restricted’, ‘Confidential’ or requiring a ‘Certified Environment’, as per the Information Security Policy;
  • systematically monitor publicly accessible places on a large scale;
  • use / implementation of new technologies and systems;
  • use of profiling or special category data to decide on access to services;
  • processing biometric or genetic data;
  • processing data that is deemed high risk or has been shared under contract;
  • collect personal data from a source other than the individual without providing them with a privacy notice (‘invisible processing’);
  • as part of best practice, for any new processing activities or subsequent changes in current processing activities;
  • as part of engagement activities with new or current partner organisations; and
  • when undertaking research activities.

More Information

To find out more and start the registration process see as follows;

Data Sensitivity Classification Labels

Unrestricted
Definition

Information that can be shared openly because its disclosure would not negatively affect the University or any individual.

Example data sets that apply
  • Non-sensitive anonymous feedback form data with no free text fields.
  • Charts based on special category data where aggregation has considered small number effects to render the data anonymous.
  • University policies and governance.
  • Public-facing Imperial website content.
  • Published research papers without embargo.
Restricted
Definition

This information could pose a risk to the University if disclosed without authorisation but is unlikely to result in significant legal, regulatory, or personal harm.

Example data sets that apply
  • Event feedback data where a linking key exists back to the individual.
  • Health and Safety data not including health information.
  • Restricted University finance data.
  • Non-human research data prior to publication.
  • Published research papers with embargo.
  • Some non-identifiable Equality and Diversity charts
  • Third party provided data under contractual restrictions. 
Sensitive
Definition

Information where unauthorised disclosure could have a moderate to significant impact on either:

  • the University, its operations, finances, research activities, partnerships, or reputation
  • individuals and potentially result in major legal or regulatory consequences.
Example data sets that apply
  • Any combination of data that could identify gender reassignment, e.g. birth sex and chosen gender collected together.
  • Commercially sensitive data from a third party.
  • Commercially sensitive data sets where Imperial is defined as the ‘processor’ or both ‘processor and controller’ in any legal documentation.
  • Information related to important business and research relationships that Imperial has with external organisations and individuals.
  • Clinical trial data.
  • Dual-use data relating to research and innovation that is intended for beneficial civilian purposes but could also be adapted or repurposed for military, defence, security, or other harmful applications. Examples may include advanced materials, aerospace technologies, artificial intelligence, robotics, or biotechnology research.
  • Health data containing sensitive medical conditions, diagnoses, treatment information, genetic data, mental health information, or other clinical information where disclosure could cause significant harm, distress, discrimination, or loss of privacy to the individual.
  • HR records include EDI demographics.
  • Data on sensitive research areas (e.g. radiation work).
  • Income data.
  • Interview transcripts with ethnicity demographics.
  • Special category personal data such as biometric data, genetic data, health data (physical or mental health information, medical records, disability info), political opinions, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, trade union membership.
Highly Sensitive
Definition

Information where unauthorised disclosure could result in severe harm to individuals, significant legal or regulatory consequences, or major impacts to the University's operations, research activities, partnerships, or reputation. Such information must only be stored and processed within approved, certified, and highly controlled environments.

Example data sets that apply
  • Commercially sensitive data from a third party with a secure enclave has been requested.
  • Data provided by a third party where certification (e.g. Cyber Essentials, DSPT) is specified as required in the contract/agreement.
  • Information subject to government-imposed legal, security, export control, or handling restrictions that limit how it may be accessed, used, stored, shared, or disclosed.
  • NHS digital provided identifiable datasets.
  • NHS digital provided datasets.

Frequently Asked Questions (FAQ)

What does ‘large scale’ mean?

Whilst legislation does not define what ‘large scale’ means, you should consider;

  • the number of individuals concerned;
  • the volume of data;
  • the variety of data;
  • the duration of the processing; and
  • the geographical extent of the processing;
What happens next after I submit my DART?

Following all feedback and outcomes being implemented into the proposed registration it will be signed off and finalised. Following this completion, the entries will remain under constant review to allow for updates / amendments / new data sets to be added.

However if nothing changes then no further action will be necessary outside an annual review which will be necessary as part of the annual declaration process and managed via DART.

Do I need to complete a DART for every single thing I do, or, can it cover a number of activities?

A single DART entry may cover a broad set of activities where they share similar functions, the same technical protections, data types, purpose and legal basis. If unsure, please contact you Faculty Information Governance (IG) Support or Data Protection Office for guidance. 

I previously completed a paper version of a DPIA or filled in the (now closed down) FoM DPIA Tool, do I need to do this as well?

No, the information you provided previously will be entered onto DART by the central support / faculty teams and assigned for your awareness. Following this occurrence you will be required to keep the entry/entries updated and ensure accuracy of the registration.

What about projects / activities / data sets which have already been completed but the data has been retained for retention purposes or future process

If the data set that was collected as part of the activity is still held and/or will be used in the future you will be required to log this and the context under which the data was collected. Imperial recognises that there is a significant amount of historical / ongoing projects that process health and social care data. Whilst these must be registered, given the scale of the task Departmental Managers under the direction of the Faculty Operating Officer (FOO), associated Information Governance lead and Strategy Committee will plan this activity.  

What types of ‘risk’ are being assessed?

Whilst legislation does not define ‘risk’, the focus of risk is always on how it could or would effect individuals rights and freedoms including those relating to privacy/data protection rights and fundamental rights and interests. ‘Risk’ would therefore cover potential harm be it physical, digital  or intangible, economic, social and/or the risk on society as a whole.

Risk would also cover the potential risk to the University should the data become exposed, misused or where the use of data is governed by a contract. It is important to note that risks is not just associated to personal data but any data which university holds. For more information about Data types please see the Information Security Policy.

What will happen to the entries I made in DART version 1?

All current completed DART entries will be moved in to the new system in early 2026.

Unfinished DARTs - If you have started an entry in the old system you will still have access in order to complete it. Once completed and signed off these entries will then be moved over to the new DART platform in a phased approach.

We encourage you to complete any outstanding DART entries as soon as possible in 2026 in order for them to be moved over in the first phase of the migration.

Later in 2026, ICT will close the old DART system and you will lose access to it.

Any remaining incomplete old DART entries will then be migrated for completion in the new DART.

ICT will contact you to let you know when your entries are migrating and when the old DART is closing.

What will Imperial do with the information provided?

Data from the DART will be used to facilitate reporting on key metrics, such as: 

  • Number of registered projects;
  • Number of overdue reviews;
  • Number of high risk datasets;
  • Creation of the Records of Processing Activity (RoPA)
  • Creation of the Information Asset Register (IAR)
  • Imperial stipulates an annual review process for registered projects - these will also be managed via DART and the Annual Declaration Process.  

HoDs and DOOs will receive findings reports for information and action, as appropriate. These reports will also be provided to all relevant Governance and Data Leadership Groups.