Term
Data protection impact assessment (DPIA)
Term, not defined in lawGDPR
This is not a legal definition. Obligation and content: Art. 35 GDPR (prior consultation: Art. 36 GDPR).
A mandatory prior risk assessment for high-risk processing. Note that a DPIA need not be repeated for every similar processing: if the dataset differs but the processing is the same, it need not be redone.
Questions about what this term means for your organisation? Contact Mr. Dr. Vlieger.
