Definition
A data-protection review, required before putting a generative-AI system into use, that documents what personal data the system uses, how that data flows, and what risks it creates. Regulators are beginning to enforce this as a condition of lawful AI adoption, including in the first AI-related data-breach findings.
Why it matters
Running a DPIA up front is now a defensively important step: failing to do so is the exact gap regulators call out first when a GenAI project suffers a data breach.