Article 35 GDPR : Criteria and Methodology of the DPIA
Article 35 GDPR and WP248 Guidelines require a Data Protection Impact Assessment (DPIA) whenever processing is likely to result in a high risk to the rights and freedoms of natural persons.
1. The Statutory Framework of the DPIA (Art. 35 GDPR)
A Data Protection Impact Assessment (DPIA) is mandatory where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons (Art. 35.1), taking into account its nature, scope, context, and purposes.
Article 35(3) specifies three statutory processing categories for which a DPIA is strictly required as a matter of law:
- a) Systematic and extensive evaluation of personal aspects (Art. 35.3.a) : Profiling and automated processing producing legal effects or similarly significantly affecting the individual.
- b) Large-scale processing of special categories or criminal data (Art. 35.3.b) : Health data, biometric data, genetic data (Art. 9) or personal data relating to criminal convictions and offences (Art. 10).
- c) Systematic monitoring of a publicly accessible area on a large scale (Art. 35.3.c) : Extensive video surveillance, connected monitoring devices in public spaces.
2. The 9 EDPB/WP29 Criteria & High-Risk Assessment Doctrine
European guidelines WP248 rev.01 (endorsed by the EDPB) clarify high-risk evaluation through 9 operational screening criteria:
- 1. Evaluation or scoring (profiling, behavioural prediction)
- 2. Automated decision-making with legal or similar significant effect
- 3. Systematic monitoring of data subjects
- 4. Sensitive data or data of a highly personal nature
- 5. Data processed on a large scale
- 6. Matching or combining datasets from distinct processing operations
- 7. Data concerning vulnerable data subjects (children, employees, patients)
- 8. Innovative use or applying new technological or organisational solutions (AI, biometric recognition)
- 9. Processing preventing data subjects from exercising a right or using a service/contract
As a general rule, meeting at least two criteria indicates that a full DPIA is legally required. However, this is not a rigid arithmetic rule: in certain high-impact contexts, meeting a single criterion may suffice to trigger mandatory DPIA obligations. If the residual risk remains high after implementing protective measures, the controller must consult the supervisory authority prior to processing (Art. 36).
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →AIPD / DPIA (Art. 35), 9 critères de risque élevé, forte présomption dès 2 critères (ou 1 critère à fort impact)
Consult official source →Associated Operational Micro-Tools
Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.
See Also in the Legal Framework
Article 6 GDPR: The Six Lawful Grounds for Lawful Processing
Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...
EDPB Guidelines 03/2026: Web Scraping for Generative AI
Legal analysis of EDPB Guidelines 03/2026 (Draft Version 1.0 open for consultation until 30 Oct 2026): lawful grounds fo...