Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Data Protection Impact Assessment (DPIA) (Art. 35)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 43/54 Part 5 — Operational Obligations & Sanctions Advanced Reviewed 2026-08-23

Data Protection Impact Assessment (DPIA) (Art. 35)

A DPIA is legally mandatory prior to processing whenever technologies or operations are likely to result in a high risk to the rights and freedoms of natural persons. The EDPB WP248 guidelines establi

Open in interactive reader
⚖️ Mandatory Prior Assessment 📋 EDPB Guidelines WP248 (9 Criteria)

Data Protection Impact Assessment (DPIA) (Art. 35)

⚡ In 30 seconds

Under Article 35, where a type of processing—in particular using new technologies—is likely to result in a high risk to the rights and freedoms of natural persons, the controller must, prior to processing, carry out a Data Protection Impact Assessment (DPIA). Article 35(3) specifically mandates DPIAs for systematic profiling, large-scale sensitive data, and public area monitoring.

DPIA Core Step Assessment Requirement Deliverable
1. Description Systematic description of operations and legitimate purposes. Data flow diagrams, asset architectures, legal basis justification.
2. Necessity & Proportionality Assessment of necessity and proportionality against Article 5 principles. Minimisation analysis, retention justification, transparency checks.
3. Risk Assessment Evaluation of origin, nature, particularity, and severity of risks to individuals. Risk matrix (likelihood × severity) covering confidentiality, integrity, availability.
4. Mitigating Measures Technical and organizational safeguards designed to reduce residual risk. Encryption protocols, IAM policies, contractual guarantees.
⚡ Key Takeaways
  • The controller must seek the advice of the Data Protection Officer (DPO) when carrying out a DPIA (Art. 35.2).
  • Where feasible, views of data subjects or their representatives must be sought (Art. 35.9).
  • National DPAs maintain binding lists of processing types requiring mandatory DPIAs (blacklists).
⚠️ Common Pitfall

Failing to consult the supervisory authority (Art. 36) when an assessment concludes that residual risks remain high.

🛠️ In Practice

Utilize open-source tools like the CNIL PIA software to standardize risk modeling across project managers.

⚖️ Official Sources: Art. 35 & 36 GDPR · Recitals 84, 89–93 · WP29 Guidelines on DPIA (WP248) ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Mandatory prior risk assessment before launching high-risk processing operations.
  • EDPB 9 high-risk criteria: automated evaluation/scoring, sensitive data, systematic monitoring, AI.
  • Prior consultation with the DPA (Art. 36) is mandatory if residual risks remain unmitigated.

⚠ Common pitfall: Treating a DPIA as a static checklist after deployment rather than an iterative risk-management exercise during design.

→ Actionable practice: Systematically screen new digital projects against the 9 WP248 criteria to determine if a full DPIA is legally required.

← Record of Processing Activities (RoPA) (Art. 30) Data Protection Officer (DPO) (Art. 37–39) →