Skip to content
GDPR Recital 90 EN
LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this law. Contains: the full text of every article, recital and provision of this law. Everything links back to its source on overview.legal — legal information, not advice.

Recital 90 — data protection impact assessment requirements

In force — consolidated2016-05-04 · CELEX 02016R0679-20160504 · ELI ↗
Version history 2
  • 2016-05-04in force CELEX 02016R0679-20160504
  • 2016-04-27 CELEX 32016R0679

In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking into account the nature, scope, context and purposes of the processing and the sources of the risk. That impact assessment should include, in particular, the measures, safeguards and mechanisms envisaged for mitigating that risk, ensuring the protection of personal data and demonstrating compliance with this Regulation.

Related across sources

15625/2026 Cass.Civ. - 15625/2026 Istituto nazionale della previdenza sociale (INPS, the controller) is the Italian National Institute for Social Security. In 2021, the DPA fined the controller €300,000 for its… Supreme Court May 21, 2026 Privacy by Design & Default Privacy by Design DPIA
VwGH Ro 2025/04/0007-7 VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural The controller was an address publisher and direct advertising company that operated a data application to provide advertisers with personal data for targeted marketing measures.… Jun 24, 2026 Controllers Accountability Personal Data
Guidelines 1/2019 Codes of Conduct and Monitoring Bodies under Regulation 2016/679 Guidelines on codes of conduct and monitoring bodies Guidelines ·EDPB Jun 4, 2019 Accountability Codes of Conduct GDPR Article 5 Principles of Processing