Datenmaske
← Glossar

Data Protection Impact Assessment (DPIA)

The Data Protection Impact Assessment (DPIA, German: Datenschutz-Folgenabschätzung, DSFA) under Article 35 of the GDPR is a systematic process for assessing the impact of processing operations on the protection of personal data. It is required when a form of processing is likely to result in a high risk to the rights and freedoms of natural persons — for example, in the case of large-scale processing of sensitive data, systematic monitoring, or innovative technologies.

A DPIA must contain at least: a systematic description of the processing operations and their purposes, an assessment of the necessity and proportionality of the processing, an assessment of the risks to data subjects, and the measures to mitigate risk. These also include technical measures such as encryption, pseudonymization, and — in the context of documents — the redaction of personal data.

The use of Datenmaske can be documented in the DPIA as a technical measure for risk mitigation. The automatic detection and irreversible redaction of personal data reduces the risk of a data protection violation when sharing documents. The redaction log serves as evidence of the measures taken.

Verwandte Begriffe