# O5.1 Implement privacy and data protection impact assessments prior roll-out

{% tabs %}
{% tab title="Risk" %}
[SV2 Weak rule of law](https://safedpi.gitbook.io/safeguards/universal-dpi-safeguards-framework/risks)

[RS1 Privacy Vulnerability ](https://safedpi.gitbook.io/safeguards/universal-dpi-safeguards-framework/risks/risks-to-safety)
{% endtab %}

{% tab title="Life Cycle Stage" %}
[L1 Conception and Scoping ](https://safedpi.gitbook.io/safeguards/universal-dpi-safeguards-framework/life-cycle-stages)
{% endtab %}

{% tab title="Principle" %}
[O5 Ensure data protection during use](https://safedpi.gitbook.io/safeguards/universal-dpi-safeguards-framework/principles/operational-principles/o5-ensure-data-protection-during-use)
{% endtab %}
{% endtabs %}

## Practices

> * Run comprehensive assessments to identify privacy and data protection needs for different users.
> * Ensure legal framework are in place before roll-out of DPI.

## Resources

<table data-view="cards"><thead><tr><th></th><th></th><th></th></tr></thead><tbody><tr><td></td><td><mark style="color:yellow;"><strong>Case Study</strong></mark></td><td>Coming soon..</td></tr><tr><td></td><td><mark style="color:yellow;"><strong>References</strong></mark></td><td><a href="https://csrc.nist.gov/Projects/risk-management/about-rmf">GDPR, Risk Management Framework (RMF) of NIST</a></td></tr></tbody></table>
