Skip to main content

DPIA (Data Protection Impact Assessment)

An assessment required by GDPR Article 35 (or Directive (EU) 2016/680 Article 27 for law enforcement) when processing personal data is likely to result in high risk to the rights and freedoms of natural persons. Covers data-protection-specific risks; does not substitute for the FRIA under the EU AI Act.

Defined in 2 GAGE programs, which carry 3 distinct definitions of it. The wording above is taught in EU AI Act Implementation Expert.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

AI Data Governance: The Data Chair

A GDPR-required assessment (Article 35) for processing likely to result in a high risk to individuals' rights and freedoms. Referenced in this topic because the Digital Omnibus proposal would tie the Article 30(5) exemption threshold to the DPIA high-risk standard rather than the current occasional-processing test.

EU AI Act Implementation Expert

An assessment required by GDPR Article 35 (or Directive (EU) 2016/680 Article 27 for law enforcement) when processing personal data is likely to result in high risk to the rights and freedoms of natural persons. Covers data-protection-specific risks; does not substitute for the FRIA under the EU AI Act.

AI Data Governance: The Data Chair

A formal, documented risk assessment required under GDPR Article 35 before certain high-risk processing begins, including, under Article 35(3)(b), any large-scale processing of special category data under Article 9.

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.