The Data Protection Impact Assessment (DPIA) aims to identify potential risks in the processing of personal data and to take measures to mitigate these risks. It is especially important when new technologies or data collection methods are introduced.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Executable approach: can be applied and produces an outcome.
What organizes, connects, or makes decisions possible.
A data protection impact assessment evaluates risks to people before processing begins and defines suitable safeguards.
The data protection impact assessment was established as a risk-based privacy review in the General Data Protection Regulation. Article 35 requires one where processing is likely to create a high risk, for example through new technologies or large-scale sensitive-data processing.
Imagine safety planning before construction: map possible paths to harm, estimate their severity, and decide safeguards before people are exposed.
Purpose, scope, data types, and parties are described concretely.
The likelihood and severity of possible harm are assessed.
Technical and organizational measures reduce identified risks.
A DPIA makes privacy risks visible before processing and records the reasoning behind decisions. It is not a one-time approval seal; changes and residual risk require review and sometimes consultation with a supervisory authority.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.