Data Protection Impact Assessment (DPIA)
An assessment, required under data-protection law (for example the GDPR, Regulation (EU) 2016/679, Article 35) where processing is likely to result in a high risk to individuals, of the risks a data-processing activity poses to people and the measures to address them. Systematic worker monitoring or automated performance evaluation typically requires one. It is a distinct duty from worker consultation, owed to the individual rather than the representative body, so completing it does not discharge a consultation or co-determination duty over the same system (see Topic 10.4).
Defined in 6 GAGE programs, which carry 11 distinct definitions of it. The wording above is taught in AI Governance: Applied Mastery.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
An assessment, required under data-protection law (for example the GDPR, Regulation (EU) 2016/679, Article 35) where processing is likely to result in a high risk to individuals, of the risks a data-processing activity poses to people and the measures to address them. Systematic worker monitoring or automated performance evaluation typically requires one. It is a distinct duty from worker consultation, owed to the individual rather than the representative body, so completing it does not discharge a consultation or co-determination duty over the same system (see Topic 10.4).
A written assessment documenting an organisation's data protection reasoning for a specific processing activity; the 2026 guidelines require a DPIA or equivalent written record wherever an organisation relies on the Publicly Available Exception despite a reasonably arguable digital barrier, and this topic recommends the same documentation discipline for the full decision sequence.
A structured, documented risk assessment, required under GDPR before deploying a system likely to pose high risk to individuals such as biometric recognition, that walks through what data is collected, why, and what mitigations apply, functioning as the formal record of the same reasoning the four-question check in Section 3F applies informally.
A Western-style internal risk-assessment record, required under frameworks like the GDPR for high-risk processing, that differs structurally from a China algorithm filing in that it is not typically a public-facing document and does not itself function as a gate to lawful operation the way a required China filing does.
The assessment required by Article 35 of Regulation (EU) 2016/679 (GDPR), to be conducted before processing that is likely to result in high risk to the rights and freedoms of natural persons, examining risks arising from personal data processing.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Privacy and Data Rights in AI Systems · Ethical and Responsible AI and Operational Governance, AI Literacy & Professional Conduct
- PDPA for AI: What Singapore Actually Allows · Consent, Purpose, and the Law of Data, AI Data Governance: The Data Chair
- The RAG corpus under Singapore's PDPA: access, correction, and what "delete" actually means · Feeding the Machines, AI Data Governance: The Data Chair
- The retention decision: what you must keep, what you must destroy, and proving both · Data Reality, AI Governance: Applied Mastery
- The provenance file: your data map an auditor could follow · Data Reality, AI Governance: Applied Mastery
- The union question, the works council, and consultation done right · The Humans: Leading People Through AI Change, AI Governance: Applied Mastery
- The DPIA and FRIA, run jointly: one assessment, two regimes, no duplicate work · Evidence Engineering, AI Governance: Applied Mastery
- AI Act and GDPR: FRIA vs DPIA · Regulatory Interplay and Liability, EU AI Act Implementation Expert
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.