Skip to content
Topic Contested in court

DPIA

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Data Protection Impact Assessment - systematic evaluation of processing risks

289 linked items 10 Laws9 Case Law110 Guidance85 Enforcement41 News

Overview

23 sources · Jul 23, 2026

Legal Framework

The DPIA obligation is anchored in Article 35 GDPR, which requires controllers to assess processing risks before they begin, and flows into Article 36 GDPR when residual risk remains high. The core trigger is risk-based: a DPIA is mandatory where processing is "likely to result in a high risk to the rights and freedoms of natural persons." Three specific situations in Article 35(3) always require one: automated decision-making with legal or similarly significant effects, large-scale processing of special categories under Article 9 or Article 10, and large-scale systematic monitoring of publicly accessible areas.

"the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"
— GDPR Art. 35(1)

The DPO plays a central role: under Article 35(2), the controller must seek the DPO's advice, and under Article 39(1)(c), the DPO must both advise on and monitor the DPIA's execution. Supervisory authorities are required under Article 35(4) to publish lists of processing operations subject to mandatory DPIA, giving controllers a concrete reference point. Where the completed DPIA shows unmitigated high risk, Article 36(1) requires prior consultation with the supervisory authority before processing can proceed.

Key Developments

Courts are actively testing the thresholds of "large scale" and "systematic monitoring." The Raad van State addressed both concepts in a parking-enforcement case, finding that license-plate-based parking data collection did not trigger a DPIA:

"Ook gaat het hier niet om grootschalige verwerking die een DPIA zou 'triggeren'."
Raad van State, r.o. 5.5

The court compared the processing to ANPR-equipped scan vehicles and found the scale insufficient, illustrating that not all public-space data collection meets the Article 35(3)(c) threshold. Meanwhile, the Rechtbank Gelderland's e-screener ruling exposed a structural problem: where multiple parties dispute controller status, the DPIA obligation can fall through the cracks entirely, as neither the minister nor the korpschef accepted responsibility for the processing at issue.

On the enforcement side, the EDPB's breach-notification guidelines confirm that a well-conducted DPIA serves as a foundational risk assessment that can accelerate breach response, though it may not capture the specificity of an actual incident.

Status of the Debate

This topic is contested in court. The core obligation under Article 35 is settled, but its boundaries — particularly what constitutes "large scale" and "systematic monitoring" — are actively litigated. The Regulation does not define "large scale," leaving courts and supervisory authorities to develop criteria incrementally. The Raad van State's approach of comparing processing against known DPIA-list examples (like scan vehicles) offers one methodology, but no uniform judicial standard has emerged. The publication of national DPIA lists under Article 35(4) provides partial clarity, yet divergence across Member States persists. A CJEU ruling on the scope of "large scale" or "systematic monitoring" would resolve the open question definitively.

Practical Guidance

  • Screen against all three Article 35(3) triggers first: automated decision-making, special-category data at scale, and systematic public-area monitoring. If any applies, a DPIA is mandatory — do not rely solely on the risk-based threshold.
  • Consult your DPO early: Article 35(2) requires seeking DPO advice during the DPIA, not after. The DPO's role under Article 39(1)(c) extends to monitoring implementation, so involve them from scoping onward.
  • Check the relevant supervisory authority's published list: Article 35(4) lists provide a concrete compliance benchmark. If your processing appears on the list, a DPIA is required regardless of your own risk assessment.
  • Plan for prior consultation as a contingency: If the DPIA identifies high residual risk after mitigation, Article 36 requires consultation with the supervisory authority — build the potential eight-week timeline (extendable by six) into your project schedule.
  • Establish clear controller attribution: The e-screener case demonstrates that disputed controller status can undermine DPIA compliance. Document data-responsibility allocations in processing agreements before processing begins.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 10
Art. 35(2) The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. GDPR Art. 35(3) A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: GDPR Art. 35(4) The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data … GDPR Art. 35(5) The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessmen… GDPR art 35 Data protection impact assessment GDPR Apr 2016 art 36 Prior consultation GDPR Apr 2016 rec 94 Recital 94 — prior consultation high risk processing GDPR Apr 2016 rec 95 Recital 95 — processor assistance with DPIA and prior consultation GDPR Apr 2016 rec 90 Recital 90 — data protection impact assessment requirements GDPR Apr 2016 rec 93 Recital 93 — member state data protection impact assessment GDPR Apr 2016 rec 92 Recital 92 — broader scope data protection impact assessment GDPR Apr 2016 rec 84 Recital 84 — high risk data protection impact assessment GDPR Apr 2016 rec 89 Recital 89 — abolition of general notification obligation GDPR Apr 2016 rec 91 Recital 91 — high risk processing requiring impact assessment GDPR Apr 2016
Case Law 9
¶3 Recitals 1, 2, 26, 33, 37 and 96 of Directive 2016/680 are worded as follows: ‘(1) The protection of natural persons in relation to the processing of … JH v Policejní prezidium ¶15 Paragraphs 1, 3 and 10 of Article 35 of that regulation, which is entitled ‘Data protection impact assessment’, provides as follows: ‘1. Where a type … Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora ¶64 The second ground of invalidity mentioned by the referring court alleges that Regulation 2019/1157 was adopted without a data protection impact assess… Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora ¶35 Article 17a(1) of the ZZLD provides: ‘In supervising the processing of personal data by a court in the performance of its functions as a judicial auth… Judgment of the Court (First Chamber) of 30 April 2025.#Inspektorat kam Visshia sadeben savet.#Requests for a preliminary ruling from the Sofiyski rayonen sad.#References for a preliminary ruling – Rule of law – Judicial independence – Second subparagraph of Article 19(1) TEU – Effective legal protection in the fields covered by Union law – Judicial body competent to propose the initiation of disciplinary proceedings against judges, public prosecutors and investigating magistrates, with a view t 61/22 Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora Court of Justice of the European Union Mar 2024 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 453/21 Judgment of the Court (Sixth Chamber) of 9 February 2023.#X-FAB Dresden GmbH & Co. KG v FC.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 38(3) – Data protection officer – Prohibition on dismissing data protection officer for performing his or her tasks – Requirement for functional independence – National legislation prohibiting Court of Justice of the European Union Feb 2023 Federal Administrative Court BVwG - W258 2227269-1/39E Federal Administrative Court Dec 2024 Supreme Court Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data Supreme Court May 2026 55/24 Judgment of the General Court (First Chamber, Extended Composition) of 10 September 2025.#Meta Platforms Ireland Ltd v European Commission.#Digital services – Regulation (EU) 2022/2065 – Commission decision determining the amount of the supervisory fee for 2023 – Article 43(3) to (5) of Regulation 2022/2065 – Article 4(2) of Delegated Regulation (EU) 2023/1127 – Method for calculating the number of average monthly active recipients – Temporal adjustment of the effects of an annulment.#Case T-55/ General Court Sep 2025 Austrian Administrative Supreme Court VwGH - VwGH Ro 2025/04/0007-7 Austrian Administrative Supreme Court Jun 2026 Court of Appeal Amsterdam Amsterdam Court of Appeal: Controller may reject watermarked ID copy for verification Court of Appeal Amsterdam Apr 2024 National Court Spanish court reviews DPA decision on KFC Spain website privacy information and DPO National Court Jul 2026
Guidance 110
§131 The fact that a breach could happen and go undetected for so long and the fact that, in a longer time, social engineering could have been used for alt… Guidelines 01/2021 §11 This can be ensured under the monitoring and review requirement of a DPIA, which is required for processing operations likely to result in a high risk… Guidelines 9/2022 on personal data breach notification under GDPR §35 Once the controller has become aware, a notifiable breach must be notified without undue delay, and where feasible, not later than 72 hours. During th… Guidelines 9/2022 on personal data breach notification under GDPR §104 It should be noted that assessing the risk to people’s rights and freedoms as a result of a breach has a different focus to the risk considered in a D… Guidelines 9/2022 on personal data breach notification under GDPR 62024 on the draft list of the latvian sa on pro Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) EDPB Apr 2024 012019 on the draft list of the european data protection Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725) EDPB Jul 2019 on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 72020 on the draft list of the competent supervisory Opinion 7/2020 on the draft list of the competent supervisory authority of France regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Apr 2020 112019 on the draft list of the competent supervisory Opinion 11/2019 on the draft list of the competent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Jul 2019 Show 90 more →
Enforcement 85
Garante per la protezione dei dati personali (Italy) Italian DPA: Vasto municipality breached transparency duties over traffic cameras Garante per la protezione dei dati personali (Italy) Jun 2026 AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met Garante per la protezione dei dati personali (Italy) May 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Calabrian agency for location tracking of remote workers Garante per la protezione dei dati personali (Italy) Jul 2026 Spanish Data Protection Authority (aepd) Aena, S.M.E., S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Nov 2025 Garante per la protezione dei dati personali (Italy) Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful Garante per la protezione dei dati personali (Italy) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 Spanish Data Protection Authority (aepd) Aena, een klein en middelgroot bedrijf (KMO), S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Spanish Data Protection Authority (aepd) Nov 2025 NL French Data Protection Authority (CNIL) Company: Non-compliance with general data processing principles French Data Protection Authority (CNIL) Dec 2025 Persónuvernd (Island) Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive Persónuvernd (Island) Jul 2026 Garante per la protezione dei dati personali (Italy) Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Garante per la protezione dei dati personali (Italy) Jun 2026 Italian Data Protection Authority (Garante) Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Mar 2026 Italian Data Protection Authority (Garante) Comune di Nave: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Dec 2025 Croatian Data Protection Authority (azop) Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Croatian Data Protection Authority (azop) Nov 2025 NL Data Protection Authority of Ireland Departement of Social Security: Insufficient legal basis for data processing Data Protection Authority of Ireland Jun 2025 AEPD (Spain) AEPD sanctions 23andMe for security failures in credential-stuffing breach AEPD (Spain) Oct 2025 Show 65 more →
News 41
Autoriteit Persoonsgegevens Dutch DPA requests responses to list of DPIA exemptions Autoriteit Persoonsgegevens Jun 2026 Government Short: “ Government Mar 2026 European Data Protection Board Making GDPR compliance easier through new initiatives: a key focus of the EDPB work programme 2026-2027 European Data Protection Board Feb 2026 Government Fiche. Government Jan 2026 ICO ICO: How can Privacy Enhancing Technologies help with data protection compliance? ICO Nov 2025 Government Fact Sheet Government Jan 2026 ICO ICO: How can privacy-enhancing technologies contribute to compliance with data protection legislation? ICO Nov 2025 EDPB Help make GDPR compliance easy for organisations: what templates would be helpful for you? Provide your feedback EDPB Nov 2025 EDPB Help organizations comply with GDPR regulations: what templates would be useful to you? Please provide your feedback. EDPB Nov 2025 ICO ICO: How can privacy-enhancing technologies contribute to compliance with data protection legislation? ICO Nov 2025 EDPB Helping organizations comply with GDPR regulations: which templates would be useful for you? Provide your feedback. EDPB Nov 2025 European Digital Rights Migrant smuggling laws: European Commission found in breach of transparency rules European Digital Rights Dec 2025 Electronic Frontier Foundation Operational Security (OPSEC) Trainings: A Review of 2025. Electronic Frontier Foundation Dec 2025 Electronic Frontier Foundation Statutory Damages: The Fuel of Copyright-based Censorship Electronic Frontier Foundation Jan 2026 European Digital Rights Laws regarding the smuggling of migrants: The European Commission has violated rules regarding transparency. European Digital Rights Dec 2025 Government Children's Rights Impact Assessment on Snapchat Government Sep 2025 Government Children's Rights Impact Assessment on Instagram Government Sep 2025 Government Children's Rights Impact Assessment on TikTok Government Sep 2025 EU News The competitive compass. EU News Apr 2025 EU News De competitieve kompas. EU News Apr 2025 NL Show 21 more →
Literature 32
Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 Pravo ta nauki IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION Pravo ta nauki Dec 2018 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ United Kingdom: Heading Towards Brexit but with a Data Protection Bill Implementing GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 Requirements Engineering Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements Requirements Engineering Jul 2024 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 International Journal of Population Data Science ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making International Journal of Population Data Science Feb 2021 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 Direito TI GDPR - General Data Protection Regulation Direito TI May 2018 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Spain: Preparations for a New Law on Data Protection to Implement the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 Show 12 more →
Tools 2
CNIL CNIL PIA software (privacy impact assessment tool) CNIL Jul 2026 ICO ICO Data Protection Impact Assessment (DPIA) guidance and template ICO Jul 2026