DPIA (data protection impact assessment)
Short definition
A DPIA is an assessment, provided for in Article 35 of the GDPR, that the controller must carry out before any data processing likely to result in a high risk to people's rights and freedoms.
In plain language
It describes the processing and its purpose, assesses whether it is necessary and proportionate, identifies the risks to people and sets out the measures to reduce them. It is mandatory, for example, for large-scale processing of health data, and the CNPD has published a list of processing operations that require one. It should take into account the advice of the data protection officer, where there is one.
