Skip to content
GDPR

What is DPIA?

Data Protection Impact Assessment. A required impact assessment for high-risk processing under GDPR Article 35.

DPIA stands for Data Protection Impact Assessment. Think of it like adding a new room to your house that draws a lot of power. Before you start, you sketch a plan and work out whether the fuses can handle it, so nothing catches fire. A DPIA is the same thing for personal data: before you start something that could be risky for people's privacy, you sit down and map what could go wrong and how you avoid it.

Under GDPR (the EU General Data Protection Regulation) Article 35, a DPIA is required when processing is likely to involve a high risk to people's rights and freedoms. That could mean large-scale CCTV, mapping customer behaviour, or processing sensitive data such as health information. You describe what you plan to do, why, what risks exist and what measures you put in place to reduce them.

What matters is that a DPIA is not a one-off form you fill in and forget. It is a living document you update when processing changes. It also shows you have thought things through, which is invaluable if a data protection authority ever comes knocking.

Why does a DPIA matter for your business?

A DPIA protects you in two ways. First, it forces you to spot privacy problems before they become expensive leaks or complaints. Second, it is proof that your company takes data protection seriously, which builds trust with both customers and regulators.

Ignoring a DPIA when one is actually required can itself lead to fines. Doing it properly is therefore both insurance against penalties and a way to build a secure product from the start instead of patching afterwards.

DPIA in practice

Say you run a healthcare clinic that wants to launch an app where patients log their symptoms. That is sensitive health data at scale — exactly the kind of situation where a DPIA is needed. You go through how the data is stored, who can access it and what happens in a data breach, and decide that all data must be encrypted and access must require strong authentication.

At ZORC we build these kinds of assessments into the architecture from the start, so privacy sits in the foundation rather than being glued on afterwards.

Common questions about DPIA

What does DPIA mean?

DPIA means Data Protection Impact Assessment — an analysis you carry out before starting personal data processing that could pose a high risk to people's privacy.

When must you do a DPIA?

A DPIA is required under GDPR Article 35 when processing is likely to involve high risk, for example large-scale processing of sensitive data, systematic monitoring or extensive profiling. If you are unsure, it is usually wiser to do a simple assessment anyway.

Who is responsible for carrying out a DPIA?

Responsibility lies with the data controller — the company or organisation that decides why and how the data should be processed. If you have a data protection officer, they should be involved in the work.

Related terms

← Full glossary