What is a data protection impact assessment (DPIA)?
A data protection impact assessment (DPIA) is a documented review of the privacy risks of a processing activity before it starts. GDPR Article 35 requires one when processing is likely to result in high risk to individuals. It records the purpose, the risks, and the measures that reduce them.
What the buyer is really asking
Buyers want to know that you assess privacy risk before launching features that process personal data in new ways. Say what triggers a DPIA and who signs it off. If you have never needed one, explain how you decide.
Other ways buyers ask it
Every one of these wants the same answer:
- “Do you conduct data protection impact assessments (DPIAs)?”
- “How do you assess privacy risk for new processing activities?”
- “Can you share a DPIA covering our use of your service?”
Evidence to have ready
- A DPIA template or procedure
- A completed DPIA for your main processing activity, redacted if needed
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.