DPIA
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Data Protection Impact Assessment - systematic evaluation of processing risks
Overview
27 sources · Sep 25, 2026Legal Framework
Article 35 GDPR establishes the Data Protection Impact Assessment obligation. It requires controllers to evaluate, before processing begins, the impact of processing operations likely to result in high risk to individuals' rights and freedoms.
"the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"
— GDPR Art. 35
Three categories under Article 35(3) mandatorily trigger a DPIA: (a) systematic and extensive automated profiling producing legal or similarly significant effects; (b) large-scale processing of Article 9 special categories or Article 10 criminal-offence data; (c) large-scale systematic monitoring of publicly accessible areas.
"A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of"
— GDPR Art. 35(3)
Article 35(2) requires controllers to seek DPO advice when conducting a DPIA, and Article 39(1)(c) confirms the DPO's advisory and monitoring role. Article 35(4) obliges supervisory authorities to publish lists of processing operations requiring a DPIA, with Article 64(1)(a) giving the EDPB competence to opine on those lists. Where the DPIA reveals high residual risk, Article 36(1) mandates prior consultation with the supervisory authority.
"The controller shall consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk."
— GDPR Art. 36(1)
Key Developments
The CJEU in RL v Landeshauptstadt Wiesbaden confirmed that the Article 35(1) obligation applies in particular to processing using new technologies, and that a DPIA is required at minimum for large-scale processing of special categories including biometric data. The Dutch Raad van State applied this in a 2026 ruling on license-plate parking, finding no DPIA was triggered because the processing was not "large scale" and retention periods were relatively short — even where data was held for 90 days rather than the 48 hours the municipality claimed.
Enforcement confirms a low tolerance for absent DPIAs. The Italian Garante fined Foodinho for failing to conduct a DPIA where a "considerable amount of data of different types relating to a significant number of data subjects" was processed. The Portuguese CNPD sanctioned the National Statistical Institute for lacking a DPIA for the census. The Garante similarly cited a Tuscan health authority for missing a DPIA on health data.
The EDPB has stressed that the Article 35(3) list is illustrative, not exhaustive:
Status of the Debate
This topic is contested and actively litigated. While the CJEU has confirmed the core triggers in Wiesbaden, national courts continue to dispute whether specific processing — particularly public-sector surveillance and parking systems — crosses the "high risk" or "large scale" threshold. The Raad van State rulings show that retention duration, population size, and comparators to other surveillance technologies all factor into the analysis, producing fact-sensitive outcomes that diverge across jurisdictions. No definitive CJEU ruling on the outer boundaries of "large scale" or "systematic monitoring" exists yet; a preliminary reference on those terms would resolve much of the current uncertainty.
Practical Guidance
- Conduct a DPIA before any processing involving new technologies, large-scale special-category data, or systematic public monitoring. Article 35(1)–(3) sets the floor; your supervisory authority's published list under Article 35(4) may add further triggers.
- Involve the DPO early. Article 35(2) requires seeking DPO advice, and Article 39(1)(c) obliges the DPO to advise and monitor the DPIA's execution.
- Scale the DPIA to risk. A single DPIA can cover similar processing operations, but each distinct high-risk activity requires its own assessment.
- If residual risk remains high after mitigation, consult the supervisory authority before processing under Article 36(1). Prepare the Article 36(3) documentation in advance.
- Review the DPIA when processing changes. Article 35(10) requires periodic reassessment when risk evolves.
why this is here
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment
This provision is the central legal basis for the DPIA obligation, defining when it is triggered and what it entails.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk
The article triggers supervisory consultation based on a DPIA finding, but does not establish the DPIA obligation itself. It supports the DPIA topic by referencing its role in determining the consultation duty.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
You should perform a case-by-case assessment (eg, through a data protection impact assessment (DPIA))
The document mentions DPIA as a method for evaluating PETs' appropriateness, but it does not provide guidance on conducting a DPIA itself, making it supporting rather than core.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
Enter risk factor
The document is structured around identifying risk factors, which is central to a DPIA, though it does not explicitly name a DPIA.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
Nothing of this type on this topic.
This is the top of each pile — all 120 Guidance · all 92 Enforcement · all 49 Literature · all 37 News