Conduct a GDPR Data Protection Impact Assessment from code, data flows, and processing purposes — identify high-risk processing, document mitigations, ROPA (records of processing activities). Use when EU users are involved and you're starting new processing, or when an audit asks for the DPIA you don't have.