A Data Protection Impact Assessment (DPIA) is a structured process required by GDPR Article 35 for evaluating privacy risks before high-risk processing begins. A DPIA is required when using new technologies, processing sensitive personal data at scale, systematically monitoring publicly accessible areas, or profiling individuals for automated decision-making. The process documents the processing purpose, assesses necessity and proportionality, identifies risks to data subjects, and records the measures taken to address them. If risks cannot be adequately mitigated, the data protection authority must be consulted first. For website operators, deploying behavioral advertising systems or session-recording heatmap tools commonly triggers the DPIA requirement.