Scanning your connection...
Back to Glossary
Legal

What is Data Protection Impact Assessment (DPIA)?

A process required under GDPR for evaluating the privacy risks of new projects or technologies that process personal data at scale.

A DPIA is a systematic analysis of how a project collects, uses, and protects personal data.

When It's Required

  • Systematic monitoring of public areas (CCTV)
  • Large-scale processing of sensitive data (health records, biometrics)
  • Automated decision-making that affects individuals (credit scoring, profiling)
  • New technologies with unknown privacy implications

What It Includes

  1. Description of the processing and its purposes
  2. Assessment of necessity and proportionality
  3. Evaluation of risks to individuals
  4. Measures to mitigate those risks

Privacy by Design Connection

DPIAs are most effective when done early in development. Retrofitting privacy into a finished system is expensive and often inadequate. The best organizations make DPIAs part of their product development process.

Related Terms

Have more questions?

Use our guided flow to get the right next privacy step for Data Protection Impact Assessment (DPIA).

Open Guided Flow