GDPR Recital 90: Data Protection Impact Assessement

In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.

Source text: EUR-Lex, Official Journal consolidated HTML (CELEX 32016R0679). Recital short titles are editorial labels from gdpr-info.eu editorial short titles (not official). Cross-checked against gdpr-info.eu (independent reproduction).