# Data protection impact assessment 35(8) — GDPR — provision context

> Focused context for a single provision (35(8)), curated from overview.legal on 2026-08-22. Canonical: https://overview.legal/laws/gdpr/art-35#par-8
> Verify against the official text (EUR-Lex / wetten.overheid.nl) before relying on it.

Part of **Data protection impact assessment** (GDPR, full article: https://overview.legal/laws/gdpr/art-35).

## Provision text

### 35(8)

Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment.


## Topics on this provision

- **Privacy Impact Assessment** — https://overview.legal/topics/privacy-impact-assessment
  Data protection impact assessments (DPIA)
- **DPIA** — https://overview.legal/topics/dpia
  Data Protection Impact Assessment - systematic evaluation of processing risks

## Cited by (exact-provision citations)

- **Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679** (guidance) — https://overview.legal/posts/38051
- **EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro** (guidance) — https://overview.legal/posts/125823

---
Generated by overview.legal · https://overview.legal/laws/gdpr/art-35#par-8 · 2026-08-22
