Laws · GDPR ·art-36-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
The controller shall consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk.
How it connects
Cited by
- Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4)
- Guidelines 10/2020 on restrictions under Article 23 GDPR
- School in Skellefteå: Insufficient legal basis for data processing
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- Guidelines 01/2023 on Article 37 Law Enforcement Directive
All 8
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- Agentsia po vpisvaniyata v OL
Related across sources
C-453/21 X-FAB Dresden GmbH & Co. KG v FC In Case C-453/21, the CJEU addressed a preliminary reference from the Bundesarbeitsgericht concerning X-FAB Dresden GmbH & Co. KG's dismissal of its employee FC from the position… CJEU ·Sixth Chamber Feb 9, 2023 Processors Supervision Prior Consultation
Guidelines 07/2020 concepts of controller and processor in the GDPR Guidelines ·EDPB Jul 7, 2021 Controllers Processors IP Address
Guidelines 09/2020 relevant and reasoned objection under Regulation 2016/679 Guidelines ·EDPB Mar 9, 2021 Supervision Supervisory Authorities Prior Consultation
Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Oct 20, 2020 Privacy by Design & Default Privacy by Default Privacy by Design
Guidelines 3/2025 interplay between the DSA and the GDPR Guidelines ·EDPB Sep 17, 2026 Privacy by Design & Default Privacy by Design Personal Data
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark · DPIA Access Controls Prior Consultation