Data Protection Impact Assessment (DPIA)
Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the control…
Data Protection Impact Assessment (DPIA)
Where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, the controller must carry out, prior to the processing, an assessment of its impact. We conduct and document the DPIA, define mitigation measures and, where the residual risk remains high, prepare the prior consultation of the supervisory authority.
What it includes
- Risk screening against the CNPD/EDPB criteria
- Full impact assessment and mitigation plan
- Prior consultation of the authority, where required
Legal basis: GDPR, Arts. 35–36