Back to the hub

GDPR Article 35: when do you need a data protection impact assessment (DPIA)?

A data protection impact assessment (DPIA) is required under GDPR Article 35 before any processing likely to result in a high risk to individuals. It is required in particular for large-scale automated decisions with significant effects, large-scale special category or criminal data, and large-scale systematic monitoring of a public area.

Applies to: Controllers planning processing that is likely to result in a high risk to the rights and freedoms of individuals.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

A data protection impact assessment, or DPIA, is the written exercise GDPR asks you to run before you start processing that could put people at high risk. Article 35 sets out when it is mandatory and what it must contain. The short version is that a DPIA is not required for everything, but when it is required and you skip it, that is itself a breach.

When is a DPIA required under GDPR Article 35?

Article 35(1) requires a DPIA where a type of processing, in particular one using new technologies, is likely to result in a high risk to the rights and freedoms of individuals, taking into account the nature, scope, context, and purposes of the processing. The test is forward-looking: you assess the risk before processing begins, not after something goes wrong.

The three cases in the official text

Article 35(3) names three situations that require a DPIA in particular. The first is a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal or similarly significant effects. The second is processing on a large scale of special categories of data under Article 9(1), or of personal data relating to criminal convictions and offences under Article 10. The third is systematic monitoring of a publicly accessible area on a large scale. Supervisory authorities also publish their own lists of processing that always requires a DPIA, so check your regulator's list alongside the statute.

What a DPIA must contain

Article 35(7) sets the minimum content: a systematic description of the processing operations and their purposes; an assessment of the necessity and proportionality of the processing in relation to those purposes; an assessment of the risks to the rights and freedoms of individuals; and the measures envisaged to address the risks, including safeguards, security measures, and mechanisms to protect personal data. If you use a processor, its Article 28 data processing agreement should require it to help you produce this.

What happens after the assessment

If the DPIA shows a high residual risk that you cannot mitigate, Article 36 requires you to consult your supervisory authority before processing. Where you have a data protection officer, Article 35(2) says you must seek their advice. Keeping your Article 30 records of processing current makes the screening step faster. The GDPR compliance hub shows how these obligations connect.

Next step

Most teams get stuck on the screening question: which activities actually need a DPIA. The free 2-minute Obligation Scan flags whether GDPR applies to your business and points to the high-risk processing that triggers Article 35, so you can run assessments where they are required rather than guessing.

Compliance checklist

  • Screen new or changed processing for high risk before it starts (Article 35(1)).
  • Check the three Article 35(3) cases and your supervisory authority's published DPIA list.
  • Where required, describe the processing and assess its necessity and proportionality (Article 35(7)).
  • Assess the risks to individuals and record the measures that reduce them.
  • Consult your DPO, and consult the supervisory authority if a high residual risk remains (Articles 35(2) and 36).

Sources

Last verified: 2026-07-22

Informational, not legal advice.