Data Protection Impact Assessment (DPIA)
Definition
A structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights and freedoms. DPIAs are mandatory for large-scale profiling, systematic monitoring of public spaces, and processing of special-category data at scale.
Related terms
- Aadhaar Exclusion (DPDP Act S.17(2))
- Provision that exempts processing covered by the Aadhaar Act 2016 from the general DPDP Act regime, meaning UIDAI biometric data is governed...
- Adequate Country (GDPR Ch. V)
- A country that the European Commission has determined provides a level of data protection essentially equivalent to the EU's. As of mid-2026,...
- Biometric Identifier (BIPA)
- Under Illinois BIPA: a retina or iris scan, fingerprint, voiceprint, or scan of a person's hand or face geometry; distinct from 'biometric...
- Controller
- The natural or legal person, authority, agency, or other body that determines the purposes and means of processing personal data. The controller...
- Data Fiduciary (DPDP Act)
- Any person who alone or in conjunction with others determines the purpose and means of processing personal data; the DPDP Act equivalent...
- Explicit Consent (GDPR)
- A higher consent standard required for special-category data processing under Article 9(2)(a): must be freely given, specific, informed, and involve an explicit...
- Lawful Basis
- One of the six conditions listed in Article 6 that must be satisfied before personal data may be processed. The controller must...
- Per-Violation Damages (BIPA)
- BIPA's statutory damages structure: USD 1,000 per negligent violation or USD 5,000 per intentional/reckless violation; confirmed by Cothron v. White Castle (2023)...
- Processor
- A natural or legal person that processes personal data on behalf of the controller. Processors are directly bound by certain GDPR obligations...
- Real-Time Remote Biometric Identification (RTBI)
- As defined in the EU AI Act: automated identification of natural persons at a distance by comparing their biometric data to those...
- Record of Processing Activities (ROPA)
- The inventory of processing operations required under Article 30. It documents the purposes, data categories, recipients, retention periods, and security measures for...
- Special-Category Data (GDPR)
- Personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data for unique identification, health data,...
Explained in these topics
- Biometric Privacy Law: EU GDPR, India DPDP and US BIPAA risk assessment required by GDPR Article 35 before processing likely to result in high risk. Systematic biometric identification always triggers DPIA require...
- GDPR: Core Principles and Audit ObligationsA structured risk assessment required under Article 35 before any processing that is likely to result in high risk to individuals' rights and freedoms. DPIAs a...