DPIA, LIA, TIA and DIA
The four privacy reports, what triggers each, and why none of them depends on memory.
Triggered, not remembered
All four reports arise from criteria on the processing activity. You do not decide whether you need a DPIA: you describe the activity and the platform answers. That changes the nature of the work — from remembering to reviewing.
DPIA — when it is required
The Brazilian regulator's high-risk rule combines two sets. Specific criteria: sensitive data, emerging technology, automated decisions, or public-area surveillance. General criteria: large scale or effects on rights. One from each side is enough to make the processing high-risk and the DPIA required.
There are two softer triggers as well. Legitimate interest as the legal basis requires a DPIA because the regulator may request it at any time. And an explicit regulator request, recorded on the activity, also requires it. When more than one trigger applies, high-risk wins the reading — it describes the situation better.
LIA — the three-part test
Whenever the legal basis is legitimate interest, the regulator expects the three-part test: purpose (is the interest legitimate?), necessity (is this the least intrusive way to achieve it?), and balancing (do the data subject's rights override it?), plus the safeguards that tip the balance. The platform's LIA is that checklist, and the suggested outcome comes from it — proceed or revisit.
TIA and DIA
The TIA is triggered by international data transfer. The DIA is required when the activity makes or supports high-impact automated decisions — the trigger reuses the same automated-decision criterion that already feeds the DPIA, rather than asking you to tick the same box twice. Its reference is AI governance: the NIST AI RMF and the EU AI Act.