Flag of Brazil

LGPD

close

Article 38

DPIA or Data Protection Impact Report

The national authority may require the controller to draw up a report on the impact of the protection of personal data, including sensitive data, regarding its data processing operations, under the terms of the regulation, subject to commercial and industrial secrets.

  • Single paragraph. Subject to the provisions of the caption to this article, the report shall contain, at a minimum, a description of the types of data collected, the methodology used for the collection and assurance of information security, and the controller's analysis of measures, safeguards and risk mitigation mechanisms adopted.
OSZAR »