Glossary · Data protection

DPIA (data protection impact assessment)

Also known as: data protection impact assessment, impact assessment, AIPDIn Portuguese: AIPD (avaliação de impacto sobre a proteção de dados)

Short definition

A DPIA is an assessment, provided for in Article 35 of the GDPR, that the controller must carry out before any data processing likely to result in a high risk to people's rights and freedoms.

In plain language

It describes the processing and its purpose, assesses whether it is necessary and proportionate, identifies the risks to people and sets out the measures to reduce them. It is mandatory, for example, for large-scale processing of health data, and the CNPD has published a list of processing operations that require one. It should take into account the advice of the data protection officer, where there is one.

Related terms

Sources

Glossary edited by the RVer team. Definitions are for information and do not replace clinical, legal or tax assessment or advice.Reviewed on 7 October 2026