GDPR DPIA: When Is a Data Protection Impact Assessment Required? (2026)

By Recording Law Editorial Team21 min read
GDPR DPIA: When Is a Data Protection Impact Assessment Required? (2026)

Frequently Asked Questions

When is a DPIA required under GDPR?

A DPIA is required under Article 35(1) when processing is likely to result in a high risk to the rights and freedoms of natural persons, particularly when using new technologies. Article 35(3) makes DPIAs mandatory in three cases: systematic automated profiling with legal or similarly significant effects; large-scale processing of special-category or criminal-offence data; and large-scale systematic monitoring of publicly accessible areas. Controllers must also check their national supervisory authority's published blacklist. When two or more of the EDPB's nine high-risk criteria are met, the EDPB position under WP248 is that a DPIA should be conducted.

Who is responsible for carrying out a DPIA?

The controller is legally responsible for conducting the DPIA. Article 35(2) requires the controller to consult its designated Data Protection Officer during the assessment if one has been appointed, but the DPO's role is advisory: responsibility for the DPIA's accuracy and completeness remains with the controller. Processors must assist controllers under Article 28(3)(f), but they cannot assume the controller's legal responsibility. Controllers cannot contract out of the DPIA obligation by engaging a third-party vendor, though they may use external expertise to support the process.

What happens if a controller does not carry out a required DPIA?

Failure to carry out a required DPIA is an infringement of Article 35 subject to administrative fines under Article 83(4) of up to 10 million euros, or 2% of total worldwide annual turnover, whichever is higher. Beyond the direct fine, the absence of a DPIA is evidence of a failure to implement appropriate technical and organisational measures under Article 24(1) and a failure to demonstrate compliance with Article 5(2). Supervisory authorities conducting inspections or handling complaints routinely identify missing DPIAs as a compliance gap, and their absence can transform a single infringement into a broader finding of systemic accountability failure.

Is a DPIA mandatory for CCTV surveillance?

Large-scale systematic monitoring of publicly accessible areas using CCTV falls within the mandatory DPIA trigger in Article 35(3)(c). Whether a specific installation meets the large-scale and systematic thresholds depends on the facts: a single camera inside a small retail unit monitored manually during trading hours is unlikely to require a DPIA, whereas a network of cameras across a large public space with automated analytics and extended retention periods plainly does. Controllers should also check their national supervisory authority's blacklist. Where the CCTV system incorporates facial recognition or biometric analysis, Article 35(3)(a) and (b) will also be engaged.

What is prior consultation under Article 36 GDPR?

Prior consultation is the process by which a controller must notify and consult its competent supervisory authority before beginning processing that, even after applying all reasonable mitigating measures, retains a high residual risk to data subjects. The obligation under Article 36(1) applies when the DPIA confirms that residual high risk cannot be adequately reduced. The controller must submit the completed DPIA, a description of the processing, the safeguards in place, and DPO contact details. The supervisory authority has up to eight weeks to respond, with a possible six-week extension for complex operations. The authority may advise, issue warnings, or prohibit the processing if it considers the operation would violate the GDPR.

Does a DPIA need to be submitted to the supervisory authority?

Not routinely. A DPIA is an internal accountability document that the controller prepares and retains. Submission is required only in two situations: when prior consultation under Article 36 is triggered because the DPIA reveals unmitigable residual high risk; and when a supervisory authority exercises its inspection or investigation powers and requests to review the DPIA. Controllers should therefore treat DPIAs as documents that may be requested by authorities at any time and ensure they are detailed, well-documented, and up to date.

Can one DPIA cover multiple processing operations?

Yes. Article 35(1) refers to a 'type of processing operation,' and Recital 92 confirms that a DPIA may address a set of similar processing operations that present similar high risks. A single DPIA covering a platform that processes data in multiple comparable ways is acceptable, provided the assessment addresses the specific risks associated with each distinct activity. Similarly, public authorities establishing shared processing infrastructure and multiple controllers in the same industry deploying a common technology may carry out a single DPIA, subject to each controller reviewing the shared assessment for its own specific context.

How often must a DPIA be reviewed?

Article 35(11) requires controllers to review the DPIA 'at least when there is a change of the risk represented by processing operations.' There is no fixed calendar interval in the GDPR text, but WP248 recommends setting a review schedule when the DPIA is completed, with typical intervals of one to two years for moderate-risk operations. Any material change in processing (including new data types, a significant scale increase, new technology, a new purpose, new recipient countries, or a change in the legal or regulatory context) should trigger an interim review. Controllers should record the scheduled review date in the DPIA document itself.

What is the EDPB guidance document on DPIAs?

The primary EDPB guidance is WP248rev.01, 'Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk for the purposes of Regulation 2016/679.' It was adopted by the Article 29 Working Party on 4 April 2017, revised on 4 October 2017, and endorsed by the EDPB at its first plenary in May 2018. WP248 sets out the nine criteria for high risk, recommends that controllers conduct a DPIA when two or more criteria are met, describes what a DPIA must contain, and explains the relationship between the DPIA and prior consultation. The full document is available from the EDPB website at edpb.europa.eu.

Do the GDPR DPIA rules apply to processors as well as controllers?

The legal obligation to conduct a DPIA rests on the controller, not the processor. However, Article 28(3)(f) requires that the data processing agreement include a provision under which the processor assists the controller in ensuring compliance with Articles 32 to 36, which expressly includes the DPIA and prior consultation obligations. In practice, processors must provide controllers with information about their data flows, sub-processors, and security architecture. Processors who design products likely to be used for high-risk processing are increasingly expected to produce pre-built DPIA documentation or privacy impact assessment templates as part of their product offering.

Sources and References

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation), Article 35 (Data protection impact assessment)(eur-lex.europa.eu)
  2. Regulation (EU) 2016/679, Article 36 (Prior consultation)(eur-lex.europa.eu)
  3. Regulation (EU) 2016/679, Recitals 84, 89, 90, 91, 92, 93(eur-lex.europa.eu)
  4. Article 29 Working Party (WP29), Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk, WP248rev.01 (adopted 4 October 2017, endorsed by EDPB May 2018)(ec.europa.eu)
  5. European Data Protection Board, Endorsement of WP29 Guidelines, EDPB First Plenary (25-26 May 2018)(edpb.europa.eu)
  6. Court of Justice of the European Union, Case C-131/12, Google Spain SL and Google Inc. v. Agencia Espanola de Proteccion de Datos (AEPD) and Mario Costeja Gonzalez, Grand Chamber, 13 May 2014(eur-lex.europa.eu)
  7. Court of Justice of the European Union, Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems (Schrems II), Grand Chamber, 16 July 2020(eur-lex.europa.eu)
  8. European Data Protection Board, Article 35(4) List of Processing Operations Requiring a DPIA: national supervisory authority lists(edpb.europa.eu)
  9. Information Commissioner's Office (UK GDPR), Data Protection Impact Assessments(ico.org.uk)
  10. Commission nationale de l'informatique et des libertes (CNIL), La liste des traitements pour lesquels une AIPD est requise (French DPA DPIA blacklist)(cnil.fr)
Share: