Data Protection Impact Assessment (DPIA)

A Data Protection Impact Assessment, abbreviated as DPIA, is an analysis that a controller must carry out before beginning processing likely to result in a high risk to the rights and freedoms of individuals. This typically covers large-scale systematic monitoring of publicly accessible areas, large-scale processing of special categories of data, monitoring of employee behaviour, or automated decision-making with a legal effect. The document describes the purpose and necessity of the processing, identifies risks and sets out measures to mitigate them. If the residual risk remains high even after the measures, the supervisory authority must be consulted before launch. For companies, a DPIA is relevant particularly for camera systems, the deployment of AI tools, and tracking customers across channels. The completed document is not published, but must be available for inspection.

See also: Fundamental rights impact assessment, Privacy policy, Profiling and automated decision-making.