DPIA

Data Protection Impact Assessment is GDPR Article 35 requirement to assess the impact of a processing operation on data protection before it begins, mandatory whenever the processing is likely to result in high risk, including large-scale use of Biometric categorisation or systematic profiling.

A DPIA finding high residual risk triggers mandatory prior consultation with the supervisory authority under Article 36, and overlaps in practice with the AI Act’s Conformity assessment where the same system is also a high-risk AI system.