EU-wide · Article 35 GDPR

When is a Data Protection Impact Assessment (DPIA) required under the GDPR?

Grounded in the primary source (EUR-Lex) and EDPB guidance · Stand: 08/2026

When must a company conduct a Data Protection Impact Assessment (DPIA)? Many organisations struggle to determine whether their new project or software requires a formal risk assessment. The General Data Protection Regulation (GDPR) sets out specific triggers for this obligation. Under Article 35, a DPIA is mandatory when the envisaged processing is "likely to result in a high risk to the rights and freedoms of natural persons". In this guide, we break down exactly when a DPIA is required, what the specific triggers are, and who is responsible for carrying it out.

Key facts at a glance

Relevant Article
Article 35 of the GDPR
Mandatory trigger
When processing is likely to result in a high risk to the rights and freedoms of individuals, particularly using new technologies.
Specific cases
Systematic and extensive profiling, large-scale processing of special categories of data (Article 9) or criminal data (Article 10), and systematic monitoring of a publicly accessible area on a large scale.
Who is responsible
The data controller must carry out the DPIA, seeking the advice of the Data Protection Officer (DPO).

On this page

  1. When is a DPIA required?
  2. The three specific triggers in Article 35(3)
  3. Who is responsible for the DPIA?
  4. What must a DPIA include?
  5. FAQ

When is a DPIA required?

According to Article 35(1) of the GDPR, a Data Protection Impact Assessment (DPIA) is required when a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons. The assessment must be carried out prior to the processing taking place. The purpose of a DPIA is to systematically analyse, identify, and minimise the data protection risks of a project or system before it goes live.

New technologies and context: The requirement is particularly focused on new technologies because they often involve unknown or untested risks. However, it is not just about the technology itself; you must also consider the nature, scope, context, and purposes of the processing. If you are uncertain whether a DPIA is required, the EDPB guidelines recommend carrying one out as a best practice, as it demonstrates accountability and compliance.

The three specific triggers in Article 35(3)

Article 35(3) explicitly lists three scenarios where a DPIA is strictly mandatory. If your processing operations fall into any of these categories, you cannot bypass the requirement:

  1. Systematic and extensive profiling: A systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person (Article 35(3)(a)).
  2. Large-scale processing of sensitive data: Processing on a large scale of special categories of data referred to in Article 9(1) (such as health data, biometric data, race, or religion), or of personal data relating to criminal convictions and offences referred to in Article 10 (Article 35(3)(b)).
  3. Systematic monitoring of a publicly accessible area: A systematic monitoring of a publicly accessible area on a large scale, such as widespread CCTV surveillance in public spaces (Article 35(3)(c)).

Supervisory Authority Lists: In addition to these three scenarios, Article 35(4) requires national supervisory authorities to establish and make public a list of the kind of processing operations which are subject to the requirement for a DPIA. Controllers should always consult the specific list published by their relevant national data protection authority to check for additional mandatory triggers.

Master DPIA and GDPR Requirements

Practise for your GDPR / DPO certification exam with questions covering Article 35 in depth, including real-world scenarios on when a DPIA is triggered.

Start free Try 30 questions free — AI-powered explanations included.

Who is responsible for the DPIA?

The data controller is ultimately responsible for ensuring that the DPIA is carried out. While the practical task of drafting the assessment may be delegated to a project team, an external consultant, or a data processor, the legal obligation and accountability rest solely with the controller.

Furthermore, Article 35(2) dictates that the controller must seek the advice of the data protection officer (DPO), where designated, when carrying out a DPIA. The DPO's role is advisory—they monitor the performance of the DPIA and provide guidance on risk mitigation—but they do not bear the responsibility for the DPIA's conclusions or the decision to proceed with the processing. (For more on the DPO's role, see our guide on when a DPO is required).

What must a DPIA include?

Under Article 35(7), a DPIA must contain at least a systematic description of the processing, an assessment of necessity and proportionality, an assessment of risks, and the measures to mitigate those risks. Specifically, the assessment shall contain:

Frequently asked questions

Who is responsible for carrying out a DPIA?

Under the GDPR, the data controller is legally responsible for ensuring a DPIA is carried out. While the controller may assign the actual drafting process to another party (such as a processor or external consultant), the controller remains accountable for the assessment and its outcomes (Article 35(1)).

What role does the Data Protection Officer (DPO) play in a DPIA?

The controller must seek the advice of the data protection officer (DPO), where designated, when carrying out a DPIA (Article 35(2)). The DPO advises on whether to conduct a DPIA, what methodology to follow, and whether the conclusions are appropriate, but the ultimate decision-making remains with the controller.

What must be included in a DPIA?

According to Article 35(7), a DPIA must contain at least four elements: a systematic description of the envisaged processing operations and their purposes; an assessment of the necessity and proportionality of the processing; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks and demonstrate compliance.

Do I need to consult the supervisory authority?

You only need to consult your local supervisory authority (prior consultation) if your DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk (Article 36(1)). If your measures successfully reduce the risk to an acceptable level, prior consultation is not required.

Primary sources

This guide summarises the GDPR for study and general information. It is not legal advice. For a binding interpretation always consult the official text on EUR-Lex, your competent supervisory authority, or a qualified data protection lawyer.