Skip to content
Topic Contested in court

Privacy Impact Assessment

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Data protection impact assessments (DPIA)

277 linked items 10 Laws8 Case Law110 Guidance81 Enforcement37 News

Overview

23 sources · Jul 23, 2026

Legal Framework

The Data Protection Impact Assessment (DPIA) is governed primarily by Article 35 GDPR, which mandates that controllers assess high-risk processing before it begins. The core trigger is whether the processing, considering its nature, scope, context, and purposes, is likely to produce high risk to individuals' rights and freedoms.

"the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"
GDPR Art. 35

Article 35(3) identifies three categories where a DPIA is always required: automated decision-making with legal or similarly significant effects, large-scale processing of special categories of data under Article 9, and systematic large-scale monitoring of publicly accessible areas. The regulation does not define "large scale," but the preparatory materials point to processing at regional, national, or supranational level involving substantial quantities of personal data.

The controller—not the DPO—bears responsibility for conducting the DPIA. However, Article 35(2) requires the controller to seek the DPO's advice, and Article 39(1)(c) charges the DPO with advising on and monitoring the DPIA's performance. Where the DPIA reveals residual high risk despite mitigation measures, Article 36(1) GDPR requires prior consultation with the supervisory authority before processing may proceed.

Key Developments

The Raad van State has provided practical guidance on the thresholds for "large scale" and "systematic" monitoring. In a case involving licence plate parking, the court held that the processing did not trigger a DPIA, weighing the average population size and retention duration (48 hours versus 90 days) as factors:

"Ook gaat het hier niet om grootschalige verwerking die een DPIA zou 'triggeren'."
Raad van State, §5.5

The court compared the processing to scanning vehicles, concluding it did not rise to high risk. This signals that not all systematic data collection meets the DPIA threshold—scale and intensity matter.

DPIAs also serve a forward-looking function in breach response. The EDPB has noted that a pre-existing DPIA can accelerate breach risk assessment:

"a controller may already have an initial assessment of the potential risk that could result from a breach as part of a data protection impact assessment"
EDPB Guidelines 9/2022, §35

Status of the Debate

This topic is actively contested in court. The boundaries of "large scale" and "systematic monitoring" remain unsettled, with courts diverging on whether specific processing operations trigger the DPIA obligation. The Raad van State's parking decision illustrates how fact-specific the threshold inquiry is, while enforcement actions from the Italian Garante and Spanish AEPD show regulators pushing broader interpretations. What would resolve the open questions is clearer harmonisation through EDPB guidance or binding consistency decisions under Article 64 GDPR, particularly on what constitutes "large scale" outside obvious cases like nationwide surveillance.

Practical Guidance

  • Assess triggers early: Before launching any processing involving new technologies, automated decision-making, special category data, or public area monitoring, evaluate whether Article 35(3) categories apply. Document the assessment even if you conclude no DPIA is needed.
  • Engage the DPO from the outset: Article 35(2) makes DPO consultation mandatory when conducting a DPIA. Integrate the DPO's advice into the assessment record.
  • Scale and retention are decisive factors: As the Raad van State ruling demonstrates, population scope and data retention duration directly influence whether processing qualifies as "large scale." Keep these parameters proportionate.
  • Plan for prior consultation: If the DPIA identifies residual high risk after mitigation, Article 36 requires consulting the supervisory authority before processing begins—build this timeline into project planning.
  • Use the DPIA as a living document: The EDPB's breach guidelines confirm that a DPIA's risk assessment can inform breach notification decisions, making it a practical compliance tool beyond the initial processing decision.
Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 10
Art. 35(2) The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. GDPR Art. 35(3) A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: GDPR Art. 35(4) The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data … GDPR Art. 35(5) The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessmen… GDPR art 35 Data protection impact assessment GDPR Apr 2016 art 36 Prior consultation GDPR Apr 2016 rec 95 Recital 95 — processor assistance with DPIA and prior consultation GDPR Apr 2016 rec 94 Recital 94 — prior consultation high risk processing GDPR Apr 2016 rec 92 Recital 92 — broader scope data protection impact assessment GDPR Apr 2016 rec 84 Recital 84 — high risk data protection impact assessment GDPR Apr 2016 rec 93 Recital 93 — member state data protection impact assessment GDPR Apr 2016 rec 90 Recital 90 — data protection impact assessment requirements GDPR Apr 2016 rec 89 Recital 89 — abolition of general notification obligation GDPR Apr 2016 rec 91 Recital 91 — high risk processing requiring impact assessment GDPR Apr 2016
Case Law 8
¶3 Recitals 1, 2, 26, 33, 37 and 96 of Directive 2016/680 are worded as follows: ‘(1) The protection of natural persons in relation to the processing of … JH v Policejní prezidium ¶15 Paragraphs 1, 3 and 10 of Article 35 of that regulation, which is entitled ‘Data protection impact assessment’, provides as follows: ‘1. Where a type … Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora ¶64 The second ground of invalidity mentioned by the referring court alleges that Regulation 2019/1157 was adopted without a data protection impact assess… Judgment of the Court (Grand Chamber) of 21 March 2024.#RL v Landeshauptstadt Wiesbaden.#Request for a preliminary ruling from the Verwaltungsgericht Wiesbaden.#Reference for a preliminary ruling – Regulation (EU) 2019/1157 – Strengthening the security of identity cards of EU citizens – Validity – Legal basis – Article 21(2) TFEU – Article 77(3) TFEU – Regulation (EU) 2019/1157 – Article 3(5) – Obligation for Member States to include two fingerprints in interoperable digital formats in the stora ¶35 Article 17a(1) of the ZZLD provides: ‘In supervising the processing of personal data by a court in the performance of its functions as a judicial auth… Judgment of the Court (First Chamber) of 30 April 2025.#Inspektorat kam Visshia sadeben savet.#Requests for a preliminary ruling from the Sofiyski rayonen sad.#References for a preliminary ruling – Rule of law – Judicial independence – Second subparagraph of Article 19(1) TEU – Effective legal protection in the fields covered by Union law – Judicial body competent to propose the initiation of disciplinary proceedings against judges, public prosecutors and investigating magistrates, with a view t 293/12 Digital Rights Ireland Ltd v Minister for Communications CJEU Apr 2014 Federal Administrative Court BVwG - W258 2227269-1/39E Federal Administrative Court Dec 2024 453/21 Judgment of the Court (Sixth Chamber) of 9 February 2023.#X-FAB Dresden GmbH & Co. KG v FC.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 38(3) – Data protection officer – Prohibition on dismissing data protection officer for performing his or her tasks – Requirement for functional independence – National legislation prohibiting Court of Justice of the European Union Feb 2023 Supreme Court Supreme Court upholds €300,000 fine against INPS for GDPR violations in COVID bonus data Supreme Court May 2026 55/24 Judgment of the General Court (First Chamber, Extended Composition) of 10 September 2025.#Meta Platforms Ireland Ltd v European Commission.#Digital services – Regulation (EU) 2022/2065 – Commission decision determining the amount of the supervisory fee for 2023 – Article 43(3) to (5) of Regulation 2022/2065 – Article 4(2) of Delegated Regulation (EU) 2023/1127 – Method for calculating the number of average monthly active recipients – Temporal adjustment of the effects of an annulment.#Case T-55/ General Court Sep 2025 Austrian Administrative Supreme Court VwGH - VwGH Ro 2025/04/0007-7 Austrian Administrative Supreme Court Jun 2026 Court of Appeal Amsterdam Amsterdam Court of Appeal: Controller may reject watermarked ID copy for verification Court of Appeal Amsterdam Apr 2024 National Court Spanish court reviews DPA decision on KFC Spain website privacy information and DPO National Court Jul 2026
Guidance 110
§131 The fact that a breach could happen and go undetected for so long and the fact that, in a longer time, social engineering could have been used for alt… Guidelines 01/2021 §11 This can be ensured under the monitoring and review requirement of a DPIA, which is required for processing operations likely to result in a high risk… Guidelines 9/2022 on personal data breach notification under GDPR §35 Once the controller has become aware, a notifiable breach must be notified without undue delay, and where feasible, not later than 72 hours. During th… Guidelines 9/2022 on personal data breach notification under GDPR 62024 on the draft list of the latvian sa on pro Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) EDPB Apr 2024 guidelines on personal data breach notification under gdpr Guidelines 9/2022 on personal data breach notification under GDPR EDPB Apr 2023 guidelines on examples regarding personal data breach notification Guidelines 01/2021 EDPB Jan 2022 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 012019 on the draft list of the european data protection Recommendation 01/2019 on the draft list of the European Data Protection Supervisor regarding the processing operations subject to the requirement of a data protection impact assessment (Article 39.4 of Regulation (EU) 2018/1725) EDPB Jul 2019 guidelines on codes of conduct and monitoring bodies Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679 EDPB Jun 2019 guidelines on the calculation of administrative fines under the gdpr Guidelines 04/2022 on the calculation of administrative fines under the GDPR EDPB May 2023 guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 guidelines on relevant and reasoned objection under regulation 2016679 Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679 EDPB Mar 2021 guidelines on processing of personal data through video devices Guidelines 3/2019 on processing of personal data through video devices EDPB Jan 2020 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 29 working party guidelines on transparency under regulation 2016679 Article 29 Working Party - Guidelines on transparency under Regulation 2016/679 EDPB Apr 2018 on processing of personal data through blockchain technologies Guidelines on processing of personal data through blockchain technologies EDPB Jul 2026 052021 on the interplay between the application of article 3 and the Guidelines 05/2021 on the Interplay between the application of Article 3 and the provisions on international transfers as per Chapter V of the GDPR EDPB Feb 2023 guidelines on restrictions under article 23 gdpr Guidelines 10/2020 on restrictions under Article 23 GDPR EDPB Oct 2021 guidelines on the targeting of social media users Guidelines 8/2020 on the targeting of social media users EDPB Apr 2021 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 guidelines on the interplay of the second payment services directive and the gdpr Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR EDPB Dec 2020 guidelines on consent Guidelines 05/2020 on consent under Regulation 2016/679 EDPB May 2020 032020 on the processing of data concerning health for the purpose Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak EDPB Apr 2020 Show 90 more →
Enforcement 81
AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: Vasto municipality breached transparency duties over traffic cameras Garante per la protezione dei dati personali (Italy) Jun 2026 UODO (Poland) UODO (Poland) - DKN.5131.12.2022 UODO (Poland) Jun 2026 Garante per la protezione dei dati personali (Italy) Italian DPA finds GDPR applies to US-based Character.AI service Garante per la protezione dei dati personali (Italy) Jul 2026 Garante per la protezione dei dati personali (Italy) Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met Garante per la protezione dei dati personali (Italy) May 2026 UODO (Poland) UODO (Poland) - DKN.5131.5.2025 UODO (Poland) May 2026 Spanish Data Protection Authority (aepd) Aena, een klein en middelgroot bedrijf (KMO), S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Spanish Data Protection Authority (aepd) Nov 2025 NL Garante per la protezione dei dati personali (Italy) Italian Garante sanctions Calabrian agency for location tracking of remote workers Garante per la protezione dei dati personali (Italy) Jul 2026 Spanish Data Protection Authority (aepd) Aena, S.M.E., S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Nov 2025 HDPA (Greece) HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens HDPA (Greece) May 2026 Persónuvernd (Island) Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive Persónuvernd (Island) Jul 2026 Garante per la protezione dei dati personali (Italy) Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Garante per la protezione dei dati personali (Italy) Jun 2026 French Data Protection Authority (CNIL) Company: Non-compliance with general data processing principles French Data Protection Authority (CNIL) Dec 2025 Italian Data Protection Authority (Garante) Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Mar 2026 Italian Data Protection Authority (Garante) Comune di Nave: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Dec 2025 AEPD (Spain) AEPD sanctions 23andMe for security failures in credential-stuffing breach AEPD (Spain) Oct 2025 Data Protection Authority of Ireland Departement of Social Security: Insufficient legal basis for data processing Data Protection Authority of Ireland Jun 2025 Italian Data Protection Authority (Garante) Gemeente Curtarolo: Onvoldoende wettelijke basis voor de verwerking van gegevens. Italian Data Protection Authority (Garante) Oct 2025 NL Spanish Data Protection Authority (aepd) SIDECU, S.A.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Jun 2025 Show 61 more →
News 37
Autoriteit Persoonsgegevens Dutch DPA requests responses to list of DPIA exemptions Autoriteit Persoonsgegevens Jun 2026 Government Short: “ Government Mar 2026 European Data Protection Board Making GDPR compliance easier through new initiatives: a key focus of the EDPB work programme 2026-2027 European Data Protection Board Feb 2026 Government Fact Sheet Government Jan 2026 Government Fiche. Government Jan 2026 ICO ICO: How can Privacy Enhancing Technologies help with data protection compliance? ICO Nov 2025 ICO ICO: How can privacy-enhancing technologies contribute to compliance with data protection legislation? ICO Nov 2025 EDPB Helping organizations comply with GDPR regulations: which templates would be useful for you? Provide your feedback. EDPB Nov 2025 EDPB Help make GDPR compliance easy for organisations: what templates would be helpful for you? Provide your feedback EDPB Nov 2025 ICO ICO: How can privacy-enhancing technologies contribute to compliance with data protection legislation? ICO Nov 2025 EDPB Help organizations comply with GDPR regulations: what templates would be useful to you? Please provide your feedback. EDPB Nov 2025 European Digital Rights Migrant smuggling laws: European Commission found in breach of transparency rules European Digital Rights Dec 2025 Electronic Frontier Foundation Statutory Damages: The Fuel of Copyright-based Censorship Electronic Frontier Foundation Jan 2026 European Digital Rights Laws regarding the smuggling of migrants: The European Commission has violated rules regarding transparency. European Digital Rights Dec 2025 Government Children's Rights Impact Assessment on Snapchat Government Sep 2025 Government Children's Rights Impact Assessment on Instagram Government Sep 2025 Government Children's Rights Impact Assessment on TikTok Government Sep 2025 EU News De competitieve kompas. EU News Apr 2025 NL EU News The competitive compass. EU News Apr 2025 EU News het Competitive Compass EU News Apr 2025 NL Show 17 more →
Literature 29
Computer law & security review If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation Computer law & security review Jan 2026 Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 SSRN Electronic Journal The EU General Data Protection Regulation (GDPR): Five Years After and the Future of Data Privacy Protection in Review SSRN Electronic Journal Jan 2023 Pravo ta nauki IMPACT OF GDPR ON UKRAINIAN PERSONAL DATA PROTECTION LEGISLATION Pravo ta nauki Dec 2018 Bankarstvo GDPR: A new challenge for personal data protection Bankarstvo Jan 2017 International Journal of Population Data Science ‘Leading by Science’ through Covid-19: the GDPR Automated Decision-Making International Journal of Population Data Science Feb 2021 European Data Protection Law Review Differential Privacy and the GDPR European Data Protection Law Review Jan 2019 Direito TI GDPR - General Data Protection Regulation Direito TI May 2018 Requirements Engineering Understanding the GDPR from a requirements engineering perspective—a systematic mapping study on regulatory data protection requirements Requirements Engineering Jul 2024 Journal of Information Technology Building data management capabilities to address data protection regulations: Learnings from EU-GDPR Journal of Information Technology Jan 2023 Journal of Data Protection Privacy Artificial intelligence in a privacy-concerned world: Automated decision-making and the GDPR Journal of Data Protection Privacy Sep 2020 Jurnal Ilmu Hukum, Humaniora dan Politik Perlindungan Hukum terhadap Inferred data dalam Automated Decision-Making: Studi Perbandingan GDPR dan UU PDP Jurnal Ilmu Hukum, Humaniora dan Politik May 2026 Awang Long Law Review PROTECTION OF DATA SUBJECT RIGHTS IN THE TRANSFER OF PERSONAL DATA BETWEEN DATA CONTROLLERS IN INDONESIA: A COMPARATIVE ANALYSIS OF THE PDP LAW AND THE EU GDPR Awang Long Law Review Jan 2026 MaRBLe Between Privacy Protection and Data Progression - The GDPR in the Context of People Analytics MaRBLe Oct 2018 Journal of Data Protection Privacy Are you ready for the applied GDPR? Journal of Data Protection Privacy Jul 2018 Journal of Data Protection Privacy The impact of the GDPR on background screening in the UK Journal of Data Protection Privacy Feb 2018 SSRN Electronic Journal The General Data Protection Regulation (GDPR): A Landmark in Privacy Law SSRN Electronic Journal Jan 2025 Journal of Data Protection Privacy GDPR: Valuing data, assessing risk and consent services Journal of Data Protection Privacy Jul 2018 Comparative Law Review General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens? Comparative Law Review Feb 2018 Journal of Data Protection Privacy General Data Protection Regulation (GDPR) ambiguity, national diversity and data protection officer certification: Implementing Art. 39(1) GDPR in France, Italy, Luxembourg and Spain Journal of Data Protection Privacy Sep 2021 Show 9 more →
Tools 2
CNIL CNIL PIA software (privacy impact assessment tool) CNIL Jul 2026 ICO ICO Data Protection Impact Assessment (DPIA) guidance and template ICO Jul 2026