[LT-06]
The DPIA Vendor Assessment Requirement
GDPR Article 35 requires Data Protection Impact Assessments for processing likely to result in high risk to individuals' rights and freedoms. Large-scale processing of personal data (Article 35(3)(b)) falls within this requirement. When an organization deploys an anonymization tool for large-scale PII processing, the DPIA must evaluate the tool as a data processor under GDPR Article 28.
Article 28 requires that data processors provide "sufficient guar...