DPIA
A DPIA — data protection impact assessment — is GDPR’s mandated risk assessment for processing “likely to result in a high risk” to individuals. It’s a structured document: what you’re processing and why, necessity and proportionality, the risks to data subjects, and the measures that reduce them.
When it’s required
Article 35 names the triggers: systematic large-scale monitoring, large-scale processing of sensitive data, and automated decision-making with significant effects. In current practice the most common trigger for SaaS companies is shipping AI features — profiling, automated scoring, model training on personal data — which is why DPIAs moved from rare to routine around 2024 and stayed there.
What a credible DPIA contains
A description of the processing and its purpose; the lawful basis and why the processing is proportionate; the risks — identified honestly, not argued away; mitigations mapped to each risk; the DPO’s advice if you have one; and a conclusion someone accountable signed. If high residual risk remains, GDPR requires consulting the supervisory authority before processing — which in practice means: mitigate until it doesn’t.
The procurement angle
Enterprise customers increasingly ask for your DPIA on AI features during security review, alongside the DPA and sub-processor list. A completed DPIA turns a fraught “how does your AI use our data” conversation into a document handoff.
Data Processing Agreement (DPA) — A DPA is the contract governing how a processor handles personal data on a controller's behalf — required under GDPR whenever a vendor touches personal data.
Sub-processor — A sub-processor is any third party your company uses to process customer personal data — your cloud host, email provider, analytics. You must disclose them.