DPIA
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Data Protection Impact Assessment - systematic evaluation of processing risks
Overview
23 sources · Jul 23, 2026Legal Framework
The DPIA obligation is anchored in Article 35 GDPR, which requires controllers to assess processing risks before they begin, and flows into Article 36 GDPR when residual risk remains high. The core trigger is risk-based: a DPIA is mandatory where processing is "likely to result in a high risk to the rights and freedoms of natural persons." Three specific situations in Article 35(3) always require one: automated decision-making with legal or similarly significant effects, large-scale processing of special categories under Article 9 or Article 10, and large-scale systematic monitoring of publicly accessible areas.
"the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"
— GDPR Art. 35(1)
The DPO plays a central role: under Article 35(2), the controller must seek the DPO's advice, and under Article 39(1)(c), the DPO must both advise on and monitor the DPIA's execution. Supervisory authorities are required under Article 35(4) to publish lists of processing operations subject to mandatory DPIA, giving controllers a concrete reference point. Where the completed DPIA shows unmitigated high risk, Article 36(1) requires prior consultation with the supervisory authority before processing can proceed.
Key Developments
Courts are actively testing the thresholds of "large scale" and "systematic monitoring." The Raad van State addressed both concepts in a parking-enforcement case, finding that license-plate-based parking data collection did not trigger a DPIA:
"Ook gaat het hier niet om grootschalige verwerking die een DPIA zou 'triggeren'."
— Raad van State, r.o. 5.5
The court compared the processing to ANPR-equipped scan vehicles and found the scale insufficient, illustrating that not all public-space data collection meets the Article 35(3)(c) threshold. Meanwhile, the Rechtbank Gelderland's e-screener ruling exposed a structural problem: where multiple parties dispute controller status, the DPIA obligation can fall through the cracks entirely, as neither the minister nor the korpschef accepted responsibility for the processing at issue.
On the enforcement side, the EDPB's breach-notification guidelines confirm that a well-conducted DPIA serves as a foundational risk assessment that can accelerate breach response, though it may not capture the specificity of an actual incident.
Status of the Debate
This topic is contested in court. The core obligation under Article 35 is settled, but its boundaries — particularly what constitutes "large scale" and "systematic monitoring" — are actively litigated. The Regulation does not define "large scale," leaving courts and supervisory authorities to develop criteria incrementally. The Raad van State's approach of comparing processing against known DPIA-list examples (like scan vehicles) offers one methodology, but no uniform judicial standard has emerged. The publication of national DPIA lists under Article 35(4) provides partial clarity, yet divergence across Member States persists. A CJEU ruling on the scope of "large scale" or "systematic monitoring" would resolve the open question definitively.
Practical Guidance
- Screen against all three Article 35(3) triggers first: automated decision-making, special-category data at scale, and systematic public-area monitoring. If any applies, a DPIA is mandatory — do not rely solely on the risk-based threshold.
- Consult your DPO early: Article 35(2) requires seeking DPO advice during the DPIA, not after. The DPO's role under Article 39(1)(c) extends to monitoring implementation, so involve them from scoping onward.
- Check the relevant supervisory authority's published list: Article 35(4) lists provide a concrete compliance benchmark. If your processing appears on the list, a DPIA is required regardless of your own risk assessment.
- Plan for prior consultation as a contingency: If the DPIA identifies high residual risk after mitigation, Article 36 requires consultation with the supervisory authority — build the potential eight-week timeline (extendable by six) into your project schedule.
- Establish clear controller attribution: The e-screener case demonstrates that disputed controller status can undermine DPIA compliance. Document data-responsibility allocations in processing agreements before processing begins.