🛡

Does your organisation need a Data Protection Impact Assessment?

DPIA is mandatory under the GDPR. We conduct, review and integrate your DPIA with audit-grade rigour.

Request DPIA Assessment Learn more
Since 2018
Mandatory
EUR 20M
Maximum fine
4%
Global turnover
22
CNPD categories

What is a DPIA?

The Data Protection Impact Assessment is the central risk management tool for personal data processing.

Set out in Article 35 of the GDPR, a DPIA is a structured process that identifies, assesses and mitigates the risks that a particular processing operation may pose to the rights and freedoms of natural persons.

It is mandatory whenever processing — by its nature, scope, context or purpose — is likely to result in a high risk to data subjects. The Portuguese DPA (CNPD) has defined 22 categories of processing that require a mandatory DPIA in Portugal.

Learn more about DPIA →

When is it Mandatory?

The GDPR defines three situations where a DPIA is always mandatory, and the CNPD has added 22 specific categories for Portugal.

🔍

Systematic Profiling

Systematic and extensive evaluation of personal aspects, including profiling (Art. 35(3)(a)).

📊

Large Scale

Large-scale processing of special categories of data or criminal conviction data (Art. 35(3)(b)).

📷

Systematic Monitoring

Systematic monitoring of a publicly accessible area on a large scale (Art. 35(3)(c)).

View full criteria and CNPD list →

Most Common DPIA Types

The obligation applies to specific processing scenarios. Learn about the most common ones.

Explore all DPIA types →

DPIA Services

Professional Data Protection Impact Assessment services by Audiqcer.

📋

Full DPIA Delivery

Turnkey service: from screening to final documentation, including DPO opinion.

Learn more →
🔎

DPIA Review

Quality audit and update against latest EDPB/CNPD guidelines.

Learn more →
🤖

Integrated DPIA + FRIA

Joint GDPR + AI Act approach for organisations using AI systems.

Learn more →
👤

DPO as a Service

Outsourced Data Protection Officer with DPIA focus.

Learn more →

Audiqcer Methodology

A structured 7-step process with audit-grade rigour and certification orientation.

1Screening
2Description
3Necessity
4Risks
5Measures
6Report
7Review

View full methodology

Why Audiqcer for your DPIA?

Audit-Grade Approach

Methodological rigour inherited from decades of ISO auditing and certification experience.

Multi-Framework Integration

GDPR + AI Act + NIS2 articulation in a single, integrated and efficient approach.

Cross-Sector Experience

Healthcare, banking, telecoms, public administration — proven transversal competence.

Part of the Impact Assessment Ecosystem

dpia.pt is part of Audiqcer's specialised portal ecosystem.

dpia.pt

DPIA (this portal)

aics.pt

CSIA Cybersecurity

Request DPIA Proposal

Fill in the form and our team will contact you within 24 business hours.

Contact

Email: info@dpia.pt

Phone: (+351) 285 107 010

Lisbon | Brussels | San Francisco

The information on this website is for informational purposes only and does not constitute legal advice. Conducting a DPIA should be accompanied by qualified professionals.