Skip to content
compliancebase

Data protection impact assessment (DPIA)

A documented GDPR assessment of high-risk processing, its necessity, risks to people, and measures that address those risks.

In practice

Trigger a DPIA during product intake before high-risk processing begins and retain approvals and residual-risk decisions.

Common confusion

A security risk assessment can inform a DPIA but does not cover necessity, proportionality, or all rights impacts.

Related controls

Framework versions referenced in this page:

Last verified: August 2026 · Primary sources linked above