EU Privacy Law EU/EEA

GDPR Data Protection Impact Assessment: When Required and How to Conduct One

When GDPR Article 35 makes a DPIA mandatory, the required content, and a step-by-step method for running assessments that stand up to regulator review.

Regulation

GDPR, Articles 35 and 36

Max Penalty

EUR 10 million or 2% of global annual turnover for DPIA failures

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 35 requires a DPIA before any processing likely to result in a high risk to individuals, and names three mandatory cases: systematic profiling with significant effects, large-scale special category processing, and large-scale public monitoring.
  • Each supervisory authority publishes a blacklist of operations that always require a DPIA under Article 35(4); check the list for your lead authority.
  • A DPIA must describe the processing, assess necessity and proportionality, evaluate risks, and set out mitigations (Article 35(7)).
  • If residual risk stays high after mitigations, Article 36 requires consulting the supervisory authority before processing starts.
  • Skipping a required DPIA is independently fineable at up to EUR 10 million or 2% of global turnover.

A data protection impact assessment is the GDPR’s structured method for identifying and mitigating risks before high-risk processing begins. Article 35 makes it mandatory in defined situations, Article 35(7) fixes the minimum content, and Article 36 adds a duty to consult the regulator when risk cannot be mitigated. Regulators treat a missing DPIA as evidence that the organization never considered the people affected.

RegulationGDPR, Articles 35 and 36
Max penaltyEUR 10M or 2% of global turnover (Art. 83(4))
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

When a DPIA is required

Article 35(3) names three always-required cases: systematic and extensive automated evaluation of people (including profiling) that produces legal or similarly significant effects, large-scale processing of special category or criminal conviction data, and systematic monitoring of publicly accessible areas at large scale.

Beyond those, the Article 29 Working Party’s nine criteria (endorsed by the EDPB) define “likely high risk”: scoring or predicting, automated decisions with significant effects, systematic monitoring, sensitive data, large scale, matched or combined datasets, vulnerable subjects, innovative technology, and processing that blocks people from rights or services. Two or more criteria generally means do the DPIA. National authorities also publish binding blacklists under Article 35(4); several include employee monitoring, biometric identification, and location tracking.

The method

  1. Describe the processing. Data categories, sources, flows, recipients, retention, and the technology involved. A data flow diagram catches risks prose misses.
  2. Test necessity and proportionality. Could the purpose be achieved with less data, shorter retention, or less intrusive means? Document the alternatives you rejected and why.
  3. Assess risks to individuals. Not risks to the company. Work through what could go wrong for the people whose data is processed: discrimination, financial loss, distress, loss of control.
  4. Define mitigations. Pseudonymization, access restriction, retention limits, transparency measures. Assign owners and dates; a DPIA with unowned mitigations is a wish list.
  5. Conclude on residual risk. If it remains high, trigger Article 36 prior consultation before going live.
  6. Review on change. A DPIA is versioned documentation, not a one-time gate. Revisit when purposes, vendors, or technology change.

Common failures

The recurring audit findings are predictable: DPIAs written after the system launched, risk registers that only consider security breaches while ignoring fairness and transparency harms, and assessments signed off without the DPO’s documented advice. The fix for all three is procedural: make the DPIA a required artifact in project intake, before procurement or build.

If your project involves AI, our AI impact assessment guide covers combining a DPIA with EU AI Act obligations. And for the website-facing portion of any project, a free scan documents current tracker behavior, useful baseline evidence for the processing description.

Frequently Asked Questions

When is a DPIA mandatory under GDPR?

Whenever processing is likely to result in a high risk to individuals (Article 35(1)), and always in the three named cases: systematic and extensive profiling with legal or similar effects, large-scale processing of special category or criminal data, and systematic large-scale monitoring of publicly accessible areas.

Who conducts the DPIA, and what is the DPO's role?

The controller is responsible. Where a DPO is appointed, Article 35(2) requires the controller to seek the DPO's advice, and the DPO monitors the DPIA's performance. The DPO advises; the controller decides and owns the outcome.

What must a DPIA contain?

The Article 35(7) minimum: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the measures envisaged to address those risks.

Do I need a new DPIA for AI tools?

Usually yes. AI systems that profile people, process data at scale, or use novel technologies hit the WP29 high-risk criteria. High-risk systems under the EU AI Act may additionally need a fundamental rights impact assessment; the two can be run together.

What happens if residual risk remains high?

Article 36 prior consultation: submit the DPIA to your supervisory authority before starting. The authority has 8 weeks, extendable by 6, to respond, and can prohibit the processing. In practice this is rare because most projects mitigate risk below the threshold.

Regulatory Crosswalk

UK GDPRQuebec Law 25 PIAEU AI Act FRIA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.