Privacy Impact Assessment
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Data protection impact assessments (DPIA)
Overview
23 sources · Jul 23, 2026Legal Framework
The Data Protection Impact Assessment (DPIA) is governed primarily by Article 35 GDPR, which mandates that controllers assess high-risk processing before it begins. The core trigger is whether the processing, considering its nature, scope, context, and purposes, is likely to produce high risk to individuals' rights and freedoms.
"the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"
— GDPR Art. 35
Article 35(3) identifies three categories where a DPIA is always required: automated decision-making with legal or similarly significant effects, large-scale processing of special categories of data under Article 9, and systematic large-scale monitoring of publicly accessible areas. The regulation does not define "large scale," but the preparatory materials point to processing at regional, national, or supranational level involving substantial quantities of personal data.
The controller—not the DPO—bears responsibility for conducting the DPIA. However, Article 35(2) requires the controller to seek the DPO's advice, and Article 39(1)(c) charges the DPO with advising on and monitoring the DPIA's performance. Where the DPIA reveals residual high risk despite mitigation measures, Article 36(1) GDPR requires prior consultation with the supervisory authority before processing may proceed.
Key Developments
The Raad van State has provided practical guidance on the thresholds for "large scale" and "systematic" monitoring. In a case involving licence plate parking, the court held that the processing did not trigger a DPIA, weighing the average population size and retention duration (48 hours versus 90 days) as factors:
"Ook gaat het hier niet om grootschalige verwerking die een DPIA zou 'triggeren'."
— Raad van State, §5.5
The court compared the processing to scanning vehicles, concluding it did not rise to high risk. This signals that not all systematic data collection meets the DPIA threshold—scale and intensity matter.
DPIAs also serve a forward-looking function in breach response. The EDPB has noted that a pre-existing DPIA can accelerate breach risk assessment:
"a controller may already have an initial assessment of the potential risk that could result from a breach as part of a data protection impact assessment"
— EDPB Guidelines 9/2022, §35
Status of the Debate
This topic is actively contested in court. The boundaries of "large scale" and "systematic monitoring" remain unsettled, with courts diverging on whether specific processing operations trigger the DPIA obligation. The Raad van State's parking decision illustrates how fact-specific the threshold inquiry is, while enforcement actions from the Italian Garante and Spanish AEPD show regulators pushing broader interpretations. What would resolve the open questions is clearer harmonisation through EDPB guidance or binding consistency decisions under Article 64 GDPR, particularly on what constitutes "large scale" outside obvious cases like nationwide surveillance.
Practical Guidance
- Assess triggers early: Before launching any processing involving new technologies, automated decision-making, special category data, or public area monitoring, evaluate whether Article 35(3) categories apply. Document the assessment even if you conclude no DPIA is needed.
- Engage the DPO from the outset: Article 35(2) makes DPO consultation mandatory when conducting a DPIA. Integrate the DPO's advice into the assessment record.
- Scale and retention are decisive factors: As the Raad van State ruling demonstrates, population scope and data retention duration directly influence whether processing qualifies as "large scale." Keep these parameters proportionate.
- Plan for prior consultation: If the DPIA identifies residual high risk after mitigation, Article 36 requires consulting the supervisory authority before processing begins—build this timeline into project planning.
- Use the DPIA as a living document: The EDPB's breach guidelines confirm that a DPIA's risk assessment can inform breach notification decisions, making it a practical compliance tool beyond the initial processing decision.