Data Protection Impact Assessment (DPIA)
The formal privacy risk review done before high-risk processing, while the design can still change and harms can still be reduced.
What it is
A Data Protection Impact Assessment is the documented risk review GDPR Article 35 requires before processing that is likely to create high risk for people's rights and freedoms. It describes the processing and purposes, tests necessity and proportionality, identifies risks to people, and records the measures that reduce them. Systematic scoring with significant effects, large-scale use of special category or criminal-conviction data, and large-scale systematic monitoring of public areas are named triggers.
Start while the design can still change. Map the data flow, consult the DPO if one is designated, involve security and product owners, and seek the views of affected people or explain why that is not appropriate. If high residual risk remains after planned controls, GDPR Article 36 requires prior consultation with the supervisory authority before processing begins.
Gotcha: a DPIA is about harm to people, not only fines or company reputation. Running the template after launch, scoring every risk low, and collecting signatures does not make it a prior assessment. Revisit it when the model, data, scale, audience, purpose, or vendor changes.
Ask AI for it
Produce a GDPR Article 35 DPIA for the project below using the LINDDUN privacy threat-modeling technique. Include the processing scope and purposes, a Mermaid data-flow diagram, necessity and proportionality tests, data-subject consultation or a reason it is omitted, and a risk register covering linkability, identifiability, non-repudiation, detectability, disclosure, unawareness, and non-compliance. Score likelihood and severity to people, assign controls and owners, rescore residual risk, record DPO advice, and end with a proceed, redesign, or stop decision. If high residual risk remains, add the GDPR Article 36 prior-consultation packet for the supervisory authority.