# Data protection impact assessment 35(11) — GDPR — provision context

> Focused context for a single provision (35(11)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-35#par-11
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Data protection impact assessment** (GDPR, full article: https://overview.legal/laws/gdpr/art-35).

## Provision text

### 35(11)

Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.


## Topics on this provision

- **Privacy Impact Assessment** — https://overview.legal/topics/privacy-impact-assessment
  Data protection impact assessments (DPIA)
- **DPIA** — https://overview.legal/topics/dpia
  Data Protection Impact Assessment - systematic evaluation of processing risks
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing

## Cited by (exact-provision citations)

- **Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria** (guidance) — https://overview.legal/posts/125965
- **Opinion 1/2022 on the draft decision of the Luxembourg Supervisory Authority regarding the GDPR – CARPA certification criteria** §34 (guidance, EDPB) — https://overview.legal/posts/125965

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-35#par-11 · 2026-08-22
