Glossary · Compliance and data protection

Data protection impact assessment (DPIA)

A data protection impact assessment (DPIA) is a structured review, required by GDPR before high-risk processing, that identifies and mitigates the risks to individuals from a proposed use of personal data.

Full definition

Data protection impact assessment (DPIA) is defined as: A data protection impact assessment (DPIA) is a structured review, required by GDPR before high-risk processing, that identifies and mitigates the risks to individuals from a proposed use of personal data.

The Information Commissioner publishes a list of processing types that always require a DPIA - profiling, large-scale monitoring, biometric or genetic data, data on vulnerable groups and combinations of large datasets among them.

A DPIA describes the processing, tests its necessity and proportionality, assesses risks to individuals and records the mitigations. It is signed off by the controller and should be revisited when the processing changes.

Also known as

DPIA

Questions and answers

Put it into practice

Manage data protection impact assessment (dpia) in Credbase.

Credbase brings every supplier document into one workspace, tracks expiry dates for you and turns the whole set into a shareable evidence pack. Free to start, no card required.