Flag of Brazil



Article 38

DPIA or Data Protection Impact Report

The national authority may require the controller to draw up a report on the impact of the protection of personal data, including sensitive data, regarding its data processing operations, under the terms of the regulation, subject to commercial and industrial secrets.

  • Single paragraph. Subject to the provisions of the caption to this article, the report shall contain, at a minimum, a description of the types of data collected, the methodology used for the collection and assurance of information security, and the controller's analysis of measures, safeguards and risk mitigation mechanisms adopted.