Data protection impact assessment

An assessment a controller must carry out before processing that is likely to result in a high risk to people's rights and freedoms (GDPR Article 35).

It describes the processing and its purposes, assesses necessity and proportionality, weighs the risks to individuals and sets out the measures to address them. Article 35(3) names cases that always need one, such as large-scale processing of special categories of data, and supervisory authorities publish lists of others. Adding a vendor that brings new technology, such as an AI provider, can be what triggers one.

Source: GDPR Art. 35 ↗

ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.