When is a DPIA required?
According to Article 35(1) of the GDPR, a Data Protection Impact Assessment (DPIA) is required when a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The assessment must be carried out prior to the processing taking place. The purpose of a DPIA is to systematically analyse, identify, and minimise the data protection risks of a project or system before it goes live.
New technologies and context: The requirement is particularly focused on new technologies because they often involve unknown or untested risks. However, it is not just about the technology itself; you must also consider the nature, scope, context, and purposes of the processing. If you are uncertain whether a DPIA is required, the EDPB guidelines recommend carrying one out as a best practice, as it demonstrates accountability and compliance.
The three specific triggers in Article 35(3)
Article 35(3) explicitly lists three scenarios where a DPIA is strictly mandatory. If your processing operations fall into any of these categories, you cannot bypass the requirement:
- Systematic and extensive profiling: A systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person (Article 35(3)(a)).
- Large-scale processing of sensitive data: Processing on a large scale of special categories of data referred to in Article 9(1) (such as health data, biometric data, race, or religion), or of personal data relating to criminal convictions and offences referred to in Article 10 (Article 35(3)(b)).
- Systematic monitoring of a publicly accessible area: A systematic monitoring of a publicly accessible area on a large scale, such as widespread CCTV surveillance in public spaces (Article 35(3)(c)).
Supervisory Authority Lists: In addition to these three scenarios, Article 35(4) requires national supervisory authorities to establish and make public a list of the kind of processing operations which are subject to the requirement for a DPIA. Controllers should always consult the specific list published by their relevant national data protection authority to check for additional mandatory triggers.
Master DPIA and GDPR Requirements
Practise for your GDPR / DPO certification exam with questions covering Article 35 in depth, including real-world scenarios on when a DPIA is triggered.
Start free Try 30 questions free — AI-powered explanations included.Who is responsible for the DPIA?
The data controller is ultimately responsible for ensuring that the DPIA is carried out. While the practical task of drafting the assessment may be delegated to a project team, an external consultant, or a data processor, the legal obligation and accountability rest solely with the controller.
Furthermore, Article 35(2) dictates that the controller must seek the advice of the data protection officer (DPO), where designated, when carrying out a DPIA. The DPO's role is advisory—they monitor the performance of the DPIA and provide guidance on risk mitigation—but they do not bear the responsibility for the DPIA's conclusions or the decision to proceed with the processing. (For more on the DPO's role, see our guide on when a DPO is required).
What must a DPIA include?
Under Article 35(7), a DPIA must contain at least a systematic description of the processing, an assessment of necessity and proportionality, an assessment of risks, and the measures to mitigate those risks. Specifically, the assessment shall contain:
- A systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller.
- An assessment of the necessity and proportionality of the processing operations in relation to the purposes.
- An assessment of the risks to the rights and freedoms of data subjects.
- The measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned.
Frequently asked questions
Who is responsible for carrying out a DPIA?
Under the GDPR, the data controller is legally responsible for ensuring a DPIA is carried out. While the controller may assign the actual drafting process to another party (such as a processor or external consultant), the controller remains accountable for the assessment and its outcomes (Article 35(1)).
What role does the Data Protection Officer (DPO) play in a DPIA?
The controller must seek the advice of the data protection officer (DPO), where designated, when carrying out a DPIA (Article 35(2)). The DPO advises on whether to conduct a DPIA, what methodology to follow, and whether the conclusions are appropriate, but the ultimate decision-making remains with the controller.
What must be included in a DPIA?
According to Article 35(7), a DPIA must contain at least four elements: a systematic description of the envisaged processing operations and their purposes; an assessment of the necessity and proportionality of the processing; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks and demonstrate compliance.
Do I need to consult the supervisory authority?
You only need to consult your local supervisory authority (prior consultation) if your DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk (Article 36(1)). If your measures successfully reduce the risk to an acceptable level, prior consultation is not required.