Data protection & AI

DPIA (data protection impact assessment)

Published Reviewed

A data protection impact assessment is the structured analysis the GDPR requires before processing that is likely to result in a high risk to individuals — systematic monitoring, large-scale sensitive data, new technology. It describes the processing, assesses necessity and proportionality, identifies risks, and decides mitigations. In Sweden, IMY publishes a list of processing operations that always require one.

Läs definitionen på svenska: Konsekvensbedömning avseende dataskydd (DPIA)

Also known as: Data protection impact assessment

Where this term does its work

This definition is general information, not legal advice. Always verify the current official source.