---
title: "DPIA"
description: "Data Protection Impact Assessment: the GDPR Article 35 assessment of processing likely to result in high risk to individuals, maintained in this discipline as a versioned artefact, not a one-off…"
canonical: https://aigovernanceengineer.com/glossary/dpia
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-25
---

# DPIA

Data Protection Impact Assessment: the GDPR Article 35 assessment of processing likely to result in high risk to individuals [1], maintained in this discipline as a versioned artefact, not a one-off document.

- Developed in: [ch. 19, The DPIA for AI systems](https://aigovernanceengineer.com/bok/privacy-and-ai#the-dpia-for-ai-systems)
- Chapters: [ch. 04, The Stack](https://aigovernanceengineer.com/bok/the-stack) · [ch. 05, Patterns](https://aigovernanceengineer.com/bok/patterns) · [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- Contrast with: [FRIA](https://aigovernanceengineer.com/glossary/fria)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-dpia

## Sources

[1] Regulation (EU) 2016/679 (General Data Protection Regulation) (Arts. 4(1), 4(5), 4(7), 4(8), 4(12), 4(14), 5, 6, 9, 12(3), 22, 25, 28(2) and 28(4), 30, 33, 35; Recital 26). Publications Office of the EU (EUR-Lex). 2016-04-27. https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng (verified: primary)
