Readiness assessment

Obligation

Data Protection Impact Assessment

A Data Protection Impact Assessment (DPIA) is a periodic risk process that Significant Data Fiduciaries must run to assess and manage risks to Data Principals' rights.

Defined inSection 10(2)(c)
CategoryData Lifecycle & Security
Applies toSignificant Data Fiduciaries

What the Act says

DPDP Act 2023, Section 10(2)(c)

periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters as may be prescribed.

In plain language

A DPIA is a structured look at what could go wrong. It describes the rights involved and the purpose of processing, then assesses and manages the risks to those rights.

It is a periodic obligation for Significant Data Fiduciaries, sitting alongside independent audits under Section 10(2).

Example

Before launching a large new data-driven feature, a notified SDF runs a DPIA to map and mitigate the risks to users.

Related terms

Related sections of the Act

Related Rules

Frequently asked questions

Who must run a DPIA?

Significant Data Fiduciaries, periodically, under Section 10(2)(c).

What does a DPIA cover?

The rights involved, the purpose of processing, and assessment and management of risks to those rights.

Continue learning