Skip to content

What Is a Data Protection Impact Assessment (DPIA)?

A data protection impact assessment identifies and reduces high risks before processing starts. Learn its triggers, contents, review and consultation rules.

Hands arrange a cream and olive paper pathway headed WHEN A DPIA BECOMES MANDATORY, with labels HIGH RISK PROCESSING, ARTICLE 35 GDPR and PRIOR CONSULTATION.
By AI Priority Map Editorial

Quick Answer: A data protection impact assessment (DPIA) is the controller's documented assessment of proposed personal-data processing likely to create high risk. It must be completed before processing starts. It describes the operation, tests necessity and proportionality, assesses risks and records safeguards. Unmitigated high residual risk requires prior consultation with the supervisory authority.1

Summary in a mind map

What Is a Data Protection Impact Assessment (DPIA)?
│
├─ Trigger
│  ├─ Likely high risk to people
│  ├─ Assessment takes place before processing
│  └─ Three Article 35 cases are explicit
│
├─ Minimum contents
│  ├─ Operations and purposes
│  ├─ Necessity and proportionality
│  ├─ Risks to rights and freedoms
│  └─ Measures, safeguards and evidence
│
├─ Consultation
│  ├─ Seek the DPO's advice if designated
│  ├─ Seek affected people's views where appropriate
│  └─ Consult the authority if high risk remains
│
└─ Lifecycle
   ├─ Review when represented risk changes
   ├─ EDPB template is optional
   └─ Controller remains responsible

The assessment comes before high-risk processing

A DPIA is a process for finding and reducing privacy risk before a proposed operation begins. Article 35(1) assigns the duty to the controller when a type of processing is likely to result in high risk to the rights and freedoms of natural persons. New technologies are an express consideration, but novelty is not itself the legal test.1

The timing matters. The controller assesses the envisaged operations prior to processing, while choices about purpose, data, access and safeguards can still change. A retrospective document describing a live system does not satisfy that sequence merely because it is labelled a DPIA.

“High risk” concerns possible effects on people, not only cybersecurity. A recruitment agency introducing automated CV screening should consider whether profiling, scale, sensitive information or significant effects make the processing likely to present high risk. The assessment then tests the whole proposed operation, not only the software.

Three triggers lead to four written elements

Article 35(3) says a DPIA is required in particular for three types of processing. These examples do not exhaust every situation covered by the broader high-risk test in Article 35(1).1

Express Article 35(3) caseWhat makes it distinct
Systematic and extensive evaluation of personal aspectsIt is based on automated processing, including profiling, and decisions produce legal or similarly significant effects
Large-scale special-category processingIt concerns Article 9(1) data on a large scale
Large-scale public-area monitoringIt systematically monitors a publicly accessible area on a large scale

An operation outside those descriptions can still require a DPIA if it is likely to result in high risk. Conversely, the presence of software or personal data alone does not prove that the threshold is met. The controller needs a reasoned screening decision.

The distinction between controller and processor also matters. The duty in Article 35 rests on the controller. Processors may still need to provide information and assistance. The controller-or-processor distinction should therefore be settled before ownership is assigned.

The written assessment has four minimum parts

Article 35(7) sets four minimum elements. First, the document systematically describes the proposed processing operations and their purposes. Where applicable, it also records the legitimate interest pursued by the controller. Second, it assesses whether the operations are necessary and proportionate to those purposes.1

Third, the DPIA assesses risks to data subjects' rights and freedoms. Fourth, it states the measures intended to address those risks, including safeguards, security measures and mechanisms that protect personal data and demonstrate compliance. The EDPB likewise describes safeguards, security measures and protection mechanisms as part of the assessment.1,2

A useful document connects each risk to a proposed treatment and supporting evidence. Generic security controls alone are incomplete. They omit the operation, purpose, necessity test and effects on people. A data-processing agreement may govern a processor relationship. It cannot replace the controller's DPIA.

Consult the officer and affected people while writing

Where a data protection officer has been designated, Article 35 requires the controller to seek that officer's advice when carrying out the DPIA. Where appropriate, the controller must also seek the views of data subjects or their representatives. That consultation is subject to protecting commercial or public interests and the security of processing.1

The controller remains accountable for the result. Advice and affected people's views inform the analysis. They do not transfer the legal duty. The assessment should record who was consulted, what they said and how their input affected the design.

High residual risk changes the next step

A completed DPIA does not permit the controller to proceed regardless of its conclusion. Article 36(1) requires prior consultation with the competent supervisory authority when the assessment indicates that processing would result in high risk in the absence of measures taken by the controller to mitigate that risk.1

The dividing line is residual risk after the proposed measures. If measures reduce risk sufficiently, the controller records that reasoning. The measures must then be implemented before launch. If high risk remains, the controller consults before processing. The authority can assess the proposed operation using the information required by Article 36.

Templates and enforcement

There is no mandatory universal form in the GDPR. On 14 April 2026, the EDPB adopted a DPIA template with predefined fields. The Board states that organisations are not obliged to use it.3

Choosing another format does not remove any minimum element. A controller must still cover the operations and purposes. It must assess necessity, proportionality and risks, then record risk treatments. A template provides consistency and prompts; it has no special legal status.

Skipping a required assessment carries enforcement exposure

Skipping a required assessment carries enforcement exposure. Article 83(4)(a) covers infringements of Articles 25 to 39. That group includes Article 35. The fine tier reaches EUR 10,000,000. For an undertaking, it can instead reach 2% of worldwide annual turnover in the preceding financial year, whichever is higher.1

Review the assessment when risk changes

Article 35 requires a review when necessary, at least when the risk represented by the processing changes. A material change to data sources, model purpose or scale may trigger review. Changes to the affected population or safeguards can do the same. Review follows changed risk, not a universal calendar interval.1

The broader GDPR accountability framework places review alongside records, responsibilities and evidence. Whether GDPR applies outside the Union remains a separate scope question. The guide to GDPR's territorial reach addresses that question.

A DPIA cannot supply a lawful basis or make disproportionate processing necessary. It cannot turn a processor into the controller. It is not a general approval certificate. Other GDPR duties continue to apply, and national law may affect the underlying processing.

The assessment also cannot replace prior consultation where high residual risk remains. Using the EDPB template does not prove the analysis is accurate. The controller must apply the proposed operation's facts and implement the measures supporting its conclusion.

What to do next

Screen the proposed operation before launch. If high risk is likely, assign the controller's owner, describe the operation and purposes, test necessity and proportionality, map risks to measures, consult the required people and record whether prior supervisory consultation is needed.

Frequently asked questions

When is a data protection impact assessment required?

A DPIA is required before processing where the proposed type of processing is likely to create a high risk to people's rights and freedoms. Article 35 specifically highlights certain automated evaluations, large-scale processing of special-category data and large-scale systematic monitoring of publicly accessible areas. The assessment must precede the processing.1

What must a DPIA contain?

At minimum, a DPIA must describe the proposed processing and its purposes, assess necessity and proportionality, assess risks to data subjects' rights and freedoms, and state the measures intended to address those risks. The measures include safeguards, security controls and mechanisms that protect personal data and demonstrate compliance.1,2

Must an organisation use the EDPB DPIA template?

No. The EDPB adopted a DPIA template on 14 April 2026, but expressly says organisations are not obliged to use it. The template offers predefined fields and a consistent route through the assessment. Any format is acceptable only if the resulting assessment covers the substantive requirements in Article 35.3,1

Who should be consulted during a DPIA?

The controller must seek the data protection officer's advice where one has been designated. Where appropriate, the controller must also seek the views of data subjects or their representatives, without prejudicing commercial or public interests or processing security. These consultations inform the assessment; responsibility remains with the controller.1

What happens if high residual risk remains?

If the DPIA shows that processing would result in high risk without measures sufficient to mitigate it, the controller must consult the competent supervisory authority before processing. Article 36 makes this prior consultation a separate step. Completing the assessment alone does not authorise the controller to accept an unresolved high risk.1

What is the fine for failing to carry out a required DPIA?

Article 83 places infringements of controller obligations under Articles 25 to 39, including Article 35, in the tier of administrative fines up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover from the preceding financial year, whichever is higher.1

Frequently Asked Questions

When is a data protection impact assessment required?
A DPIA is required before processing where the proposed type of processing is likely to create a high risk to people's rights and freedoms. Article 35 specifically highlights certain automated evaluations, large-scale processing of special-category data and large-scale systematic monitoring of publicly accessible areas. The assessment must precede the processing.[1]
What must a DPIA contain?
At minimum, a DPIA must describe the proposed processing and its purposes, assess necessity and proportionality, assess risks to data subjects' rights and freedoms, and state the measures intended to address those risks. The measures include safeguards, security controls and mechanisms that protect personal data and demonstrate compliance.[1][2]
Must an organisation use the EDPB DPIA template?
No. The EDPB adopted a DPIA template on 14 April 2026, but expressly says organisations are not obliged to use it. The template offers predefined fields and a consistent route through the assessment. Any format is acceptable only if the resulting assessment covers the substantive requirements in Article 35.[3][1]
Who should be consulted during a DPIA?
The controller must seek the data protection officer's advice where one has been designated. Where appropriate, the controller must also seek the views of data subjects or their representatives, without prejudicing commercial or public interests or processing security. These consultations inform the assessment; responsibility remains with the controller.[1]
What happens if high residual risk remains?
If the DPIA shows that processing would result in high risk without measures sufficient to mitigate it, the controller must consult the competent supervisory authority before processing. Article 36 makes this prior consultation a separate step. Completing the assessment alone does not authorise the controller to accept an unresolved high risk.[1]
What is the fine for failing to carry out a required DPIA?
Article 83 places infringements of controller obligations under Articles 25 to 39, including Article 35, in the tier of administrative fines up to EUR 10,000,000 or, for an undertaking, up to 2% of total worldwide annual turnover from the preceding financial year, whichever is higher.[1]

Sources

  1. 1.Regulation (EU) 2016/679 of the European Parliament and of the CouncilEUR-Lex · 2016
  2. 2.Secure personal dataEuropean Data Protection Board · 2026
  3. 3.Enhancing compliance and consistency: EDPB adopts DPIA templateEuropean Data Protection Board · 2026

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.