
Practical guide on when and how to conduct a Data Protection Impact Assessment.

A Data Protection Impact Assessment (DPIA) is a process designed to identify and minimize the data protection risks of a project or processing activity.
GDPR requires a DPIA when processing is "likely to result in a high risk to the rights and freedoms of natural persons". This includes:
If after the DPIA the residual risk remains high, you should consult the supervisory authority before starting the processing.
DPIA is an essential accountability and risk management tool. When well executed, it protects both the organization and data subjects.

Lawyer · Digital Law
Practice areas: GDPR, LGPD and digital contracts, operating in Portugal and Brazil.
This site uses cookies to improve your browsing experience. You can accept all cookies, reject non-essential ones or customize your preferences.
Your data is processed in compliance with GDPR and Portuguese legislation.
Learn more in our Cookie Policy.