Obligation
A Data Protection Impact Assessment (DPIA) is a periodic risk process that Significant Data Fiduciaries must run to assess and manage risks to Data Principals' rights.
periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters as may be prescribed.
A DPIA is a structured look at what could go wrong. It describes the rights involved and the purpose of processing, then assesses and manages the risks to those rights.
It is a periodic obligation for Significant Data Fiduciaries, sitting alongside independent audits under Section 10(2).
Before launching a large new data-driven feature, a notified SDF runs a DPIA to map and mitigate the risks to users.
Who must run a DPIA?
Significant Data Fiduciaries, periodically, under Section 10(2)(c).
What does a DPIA cover?
The rights involved, the purpose of processing, and assessment and management of risks to those rights.