Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Article 35 (DPIA)
Resources
🇫🇷 FR 🇬🇧 EN 🇳🇱 NL
EU Legal Reference⚖️ GDPR Regulatory Text⚖️ Binding Legal Force

Article 35 GDPR : Criteria and Methodology of the DPIA

Official EU Regulation (EU) 2016/679 legal analysis · Controlled official sources

⚡ In 30 seconds:

Article 35 GDPR and WP248 Guidelines require a Data Protection Impact Assessment (DPIA) whenever processing is likely to result in a high risk to the rights and freedoms of natural persons.

1. The Statutory Framework of the DPIA (Art. 35 GDPR)

A Data Protection Impact Assessment (DPIA) is mandatory where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons (Art. 35.1), taking into account its nature, scope, context, and purposes.

Article 35(3) specifies three statutory processing categories for which a DPIA is strictly required as a matter of law:

  • a) Systematic and extensive evaluation of personal aspects (Art. 35.3.a) : Profiling and automated processing producing legal effects or similarly significantly affecting the individual.
  • b) Large-scale processing of special categories or criminal data (Art. 35.3.b) : Health data, biometric data, genetic data (Art. 9) or personal data relating to criminal convictions and offences (Art. 10).
  • c) Systematic monitoring of a publicly accessible area on a large scale (Art. 35.3.c) : Extensive video surveillance, connected monitoring devices in public spaces.

2. The 9 EDPB/WP29 Criteria & High-Risk Assessment Doctrine

European guidelines WP248 rev.01 (endorsed by the EDPB) clarify high-risk evaluation through 9 operational screening criteria:

  • 1. Evaluation or scoring (profiling, behavioural prediction)
  • 2. Automated decision-making with legal or similar significant effect
  • 3. Systematic monitoring of data subjects
  • 4. Sensitive data or data of a highly personal nature
  • 5. Data processed on a large scale
  • 6. Matching or combining datasets from distinct processing operations
  • 7. Data concerning vulnerable data subjects (children, employees, patients)
  • 8. Innovative use or applying new technological or organisational solutions (AI, biometric recognition)
  • 9. Processing preventing data subjects from exercising a right or using a service/contract

As a general rule, meeting at least two criteria indicates that a full DPIA is legally required. However, this is not a rigid arithmetic rule: in certain high-impact contexts, meeting a single criterion may suffice to trigger mandatory DPIA obligations. If the residual risk remains high after implementing protective measures, the controller must consult the supervisory authority prior to processing (Art. 36).

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
🇪🇺 WP29 / EDPB Guidelines
Guidelines on Data Protection Impact Assessment (DPIA) (WP248 rev.01)

AIPD / DPIA (Art. 35), 9 critères de risque élevé, forte présomption dès 2 critères (ou 1 critère à fort impact)

Consult official source →

Associated Operational Micro-Tools

🔎
Art. 35 GDPR
DPIA Check (WP248 Criteria)

Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.

Launch interactive tool →

See Also in the Legal Framework

Article 6 GDPR Official Text

Article 6 GDPR: The Six Lawful Grounds for Lawful Processing

Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...

View document
EDPB Guidelines 03/2026 EDPB Doctrine

EDPB Guidelines 03/2026: Web Scraping for Generative AI

Legal analysis of EDPB Guidelines 03/2026 (Draft Version 1.0 open for consultation until 30 Oct 2026): lawful grounds fo...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-08-23 Last modified: 2026-08-23

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice