77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
DPIA template according to Art. 35 GDPR: template, threshold, audit trail
Data Protection & Privacy

DPIA template according to Art. 35 GDPR: template, threshold, audit trail

10 July 202612 min readBy Lena Vogt
CIVAC

When a DPIA is mandatory, which components the sample must contain and how you can properly document the test in the CIVAC platform. Including threshold analysis, DSK list and supervisory authority consultation in accordance with Art. 36 GDPR.

A data protection impact assessment (DPIA) is always mandatory according to Art. 35 GDPR if a form of processing, especially when using new technologies, is likely to result in a high risk for the rights and freedoms of natural persons. The Data Protection Conference (DSK) has published a list of processing activities for which a DPIA must be carried out, such as scoring, biometric identification or comprehensive employee monitoring. Anyone who processes here without a documented assessment risks fines of up to 10 million euros according to Art. 83 Para. 4 GDPR or 2 percent of the global group turnover of the previous year, whichever is higher.

This article provides the structure of a reliable DPIA template, the threshold analysis as a preliminary stage, the obligation to consult the supervisory authority according to Art. 36 GDPR and a checklist on how to carry out the check in the compliance platform and Officer-as-a-Service from CIVAC are stored in an audit-proof manner. You will learn which nine minimum components a complete template includes, how to translate the WP248 criteria of the European data protection supervisory authorities into a threshold analysis and how to interlink the DPIA process with the processing register in accordance with Art. 30 GDPR and your organisation's risk register. In addition, we show how AI-specific requirements from the EU AI Act can be neatly integrated. The appointment certificate, signed, filed, verifiable.

Key Takeaways

  • According to Art. 35 GDPR, a DPIA is mandatory as soon as the threshold analysis meets two or more risk criteria of the EDPB guideline WP248 or the processing is on the DSK must-have list.
  • The template must contain a systematic description, necessity assessment, risk assessment and remedial measures in accordance with Art. 35 Para. 7 GDPR, otherwise the DPIA is considered formally incomplete.
  • If a high residual risk is identified, the supervisory authority must be consulted before processing begins, according to Art. 36 GDPR, otherwise there is a risk of a fine and a prohibition order.

When a DPIA is mandatory according to Art. 35 GDPR

The obligation to carry out a data protection impact assessment arises directly from Art. 35 Para. 1 GDPR. What is relevant is the forecast as to whether the planned processing is likely to pose a high risk to the rights and freedoms of the data subjects. Art. 35 Para. 3 GDPR gives three standard examples: systematic and comprehensive assessment of personal aspects such as profiling or scoring, extensive processing of special categories according to Art. 9 GDPR or criminal data according to Art. 10 GDPR, as well as systematic monitoring of publicly accessible areas. These three constellations trigger the DPIA obligation without the need for further assessment.

In addition, the data protection conference has published a so-called must-list, which includes, among other things, AI-supported applicant selection, biometric access controls, location data processing in the employee context, extensive employee monitoring and credit scoring. With the guidelines WP248 (EDPB, formerly Art. 29 Group), the EU data protection supervisory authorities have developed nine criteria, two of which already trigger a DPIA obligation. These criteria are binding assessment standards in supervisory practice.

In practice, this means: Every new processing, every new system and every change of service provider must first be checked using a threshold value analysis. This preliminary stage is itself a documentation requirement and belongs in the processing directory according to Art. 30 GDPR. The external data protection officer advises on the assessment, but responsibility lies with the management in accordance with Art. 24 GDPR. Anyone who skips the threshold analysis will not be able to provide the proof of risk assessment required later and will already fail at the formal hurdle of accountability in accordance with Article 5 (2) GDPR. In supervisory practice, the lack of a threshold value analysis alone regularly leads to formal complaints because it follows that the person responsible does not carry out a systematic risk assessment of its processing landscape.

Threshold analysis as a preliminary stage of DPIA

The threshold analysis answers a single question: Is there likely to be a high risk and does this need to be followed by a full DPIA? It is not an official term of the GDPR, but has established itself as a binding intermediate step in supervisory practice. The Data Protection Conference recommends querying the nine WP248 criteria in a structured manner: evaluation or scoring, automated decision-making with legal consequences, systematic monitoring, sensitive data or highly personal data, extensive processing, linking of data sets, data of vulnerable persons such as children or patients, innovative use of new technologies and processing that prevents those affected from exercising their rights. Each criterion must be supported with concrete examples and not just answered with yes or no.

If processing meets at least two of these criteria, the high risk is considered indicated and the DPIA becomes mandatory. The threshold analysis itself should be filed as a short, dated form, ideally with versioning, author and approval by the data protection officer. The CIVAC platform has a template in the workspace that is directly linked to the processing directory and automatically creates an audit trail. Every change is logged, every evaluator is identified, every release is stored with a time stamp.

It is important to differentiate: A negative threshold analysis on the grounds that it is standard processing is risky if the processing is on the DSK must-have list. The following applies here: If in doubt, carry out the DPIA. The effort required for a lean DPIA with adequately documented measures is typically 8 to 16 person-hours, but the value of proof in a supervisory audit is high. The appointment certificate, signed, filed, verifiable also applies to the threshold analysis itself, because it is part of the accountability obligation according to Art. 5 Para. 2 GDPR and can be requested at any time by the supervisory authority according to Art. 58 Para. 1 lit. a GDPR.

Mandatory components of a DPIA template

Art. 35 Para. 7 GDPR defines four minimum components that every DPIA must contain. First: a systematic description of the planned processing operations and the processing purposes, including the legitimate interests pursued by the controller. Second: an assessment of the necessity and proportionality of the processing operations in relation to the purpose. Third: an assessment of the risks to the rights and freedoms of the data subjects. Fourth: the remedial measures planned to address the risks, including guarantees, safeguards and procedures to ensure the protection of personal data and to provide evidence of compliance with the GDPR.

A robust template is therefore divided into at least nine sections: master data of the processing with controller and joint controller according to Art. 26 GDPR, legal basis according to Art. 6 or Art. 9 GDPR, data flow description with source systems and recipients, Group of those affected and data categories, recipients and third country transfer with guarantees according to Chapter V GDPR, technical-organisational measures according to Art. 32 GDPR, risk analysis with probability of occurrence and amount of damage, catalogue of measures with residual risk assessment and release note from management and the DSB.

The risk assessment is typically carried out in a matrix with the dimensions probability of occurrence (low, medium, high) and severity of the damage (low, medium, high, very high). This methodology is based on ISO/IEC 29134:2017 (Guidelines for Privacy Impact Assessment), which is also accepted as a technical reference by supervisory practice. In addition, the Data Protection Conference's Standard Data Protection Model (SDM) provides a structured evaluation framework with its seven guarantee objectives of data minimization, availability, integrity, confidentiality, transparency, intervenability and non-linkability. Anyone who clearly structures the DPIA template and links it to the 490 audit templates from the CIVAC workspace creates the basis for reproducible assessments and a coherent audit trail across all processing.

Those involved: DSB, department, processor, works council

The DPIA is the responsibility of the person responsible, i.e. the management. However, Article 35 Para. 2 GDPR requires you to seek the advice of the data protection officer if a DPO has been appointed. According to Article 39 Para. 1 lit. c GDPR, the DPO monitors the implementation of the DPIA, but does not carry it out himself. Responsibility remains with the department that plans and operates the processing. This separation of roles is important: If the DPO were to draw up the DPIA himself, he would be controlling himself, which can constitute a conflict of interest according to Art. 38 Paragraph 6 GDPR.

Processors according to Art. This obligation to provide support must be specifically regulated in the order processing contract, otherwise the controller cannot fully carry out the DPIA. In practice, it is advisable to have a clause that sets SLAs for the provision of this information approximately 10 working days after a written request.

The works council must also be involved in processing operations relating to employee data. According to Section 87 Paragraph 1 No. 6 BetrVG, the works council has a right of co-determination in the introduction and use of technical equipment intended to monitor the behaviour or performance of employees. The DPIA forms a central basis for argumentation in the negotiations on the works agreement and protects against later arbitration proceedings. Anyone who, as a Compliance Officer or DPO, uses the DPIA as a bridge document between data protection, IT, human resources and co-determination noticeably reduces friction and speeds up approvals. In group structures, the group works council also comes into play as soon as the processing involves several locations or companies.

Obligation to consult according to Art. 36 GDPR

If the DPIA shows that the processing has a high residual risk despite all remedial measures, the responsible supervisory authority must be consulted before starting the processing in accordance with Article 36 (1) GDPR. This obligation to consult is not a theoretical construct: the supervisory authorities in Germany regularly report in their activity reports on consultation procedures in which they make written recommendations within eight weeks in accordance with Article 36 (2) GDPR. The deadline may be extended by six weeks taking into account the complexity of the intended processing. Processing may not start during the consultation period.

According to Art. 36 Para. 3 GDPR, the consultation requires specific documents: description of the distribution of responsibilities between the controller, joint controller and processor, purposes and means of processing, measures and guarantees envisaged to protect the rights and freedoms of data subjects, contact details of the DPO, the DPIA itself and any other information that the supervisory authority requests. Anyone who goes into the consultation without a structured template is wasting time and signaling a lack of maturity.

In practice it has been shown that a clearly documented DPIA significantly reduces the likelihood of an obligation to consult because it breaks down residual risks through concrete measures. The consultation is escalation path, not standard path. The deadline begins when the risk assessment is known, i.e. from the day on which the DPIA documents the high residual risk. Anyone who skips the consultation and starts processing anyway violates Art. 36 GDPR and exposes themselves to fines according to Art. 83 Para. 4 GDPR as well as prohibition orders according to Art. 58 Para. 2 lit. f GDPR. There is also the reputational risk: Prohibition orders are sometimes public according to state law, which significantly increases the damage to image beyond the mere fine.

Common mistakes and how to avoid them

The supervisory authorities publish annual activity reports in which typical DPIA weaknesses are identified. First: the lack of threshold analysis. Many people in charge jump straight into the DPIA without documenting the trigger. Consequence: When asked, the risk forecast cannot be reproduced and the audit trail breaks down. Second: copy-paste DPIAs from the Internet that are not tailored to the specific processing. The data flow description remains generic, the measures read like a TOM glossary, the risk assessment appears interchangeable.

Third: forgetting the residual risk assessment. A DPIA that only identifies risks and measures but does not assess whether the measures are sufficient is incomplete. It is precisely this assessment that is the anchor for Art. 36 GDPR. Fourth: no versioning. Processing processes change, providers change, new sub-processors are added. A DPIA is a living document that must be reviewed at least annually and immediately in the event of significant changes. Without a version history, it is not possible to understand which evaluation version belongs to which processing version.

Fifth: the lack of a link to the processing directory in accordance with Art. 30 GDPR. DSFA and VVT belong together organizationally. If you keep both registers separately, you risk inconsistencies that will immediately become apparent in every audit. The CIVAC platform links DPIA, VVT, risk register and TOM documentation in one system. The auditor calls, the evidence is ready. A sixth, often underestimated weakness: no approval from management. The DPIA is a basis for decision-making, not just a DSB exercise. Without documented release, the formal conclusion of the procedure is missing, and in the fine procedure the management can no longer rely on a conscious risk decision, which has a more difficult effect when assessing according to Art. 83 Para. 2 GDPR.

Retention, audit trail and versioning

The GDPR itself does not specify a specific retention period for DPIAs. However, the accountability requirement under Article 5 (2) GDPR means that the DPIA must be retained for as long as the underlying processing continues, plus a reasonable period of time for possible subsequent requests from the supervisory authority. In practice, a retention period of at least three years after the end of processing is recommended, in regulated industries such as financial services or healthcare also five to ten years, coordinated with the respective sector-specific retention requirements from the HGB, AO and sectoral special laws.

The form of filing is crucial. A DPIA as a Word file on a personal drive does not satisfy accountability. What is required are: central storage with access control based on the need-to-know principle, version history, change log, link to the affected processing process and release workflow with documented decisions. The workspace of the CIVAC platform meets these requirements out of the box, including EU data residency and ISO/IEC 27001:2022-compliant access control with the 93 controls of the current standard.

A reliable audit trail documents: who created which version and when, who released it, what changes were made, when was the DPIA last reviewed, what follow-up measures were derived. In the case of an audit, this data is the difference between proper documentation and a formal complaint. In the case of group structures with shared responsibility in accordance with Art. 26 GDPR, the distribution of roles must also be stored in each DPIA version so that it remains traceable which person responsible has evaluated which processing step. In addition, it is recommended to cross-link to incidents from the data breach register in accordance with Art. 33 GDPR so that lessons learned can be incorporated into the next DPIA iteration in a structured manner and risk assessments can gradually become more concrete.

DPIA for AI systems and automated decisions

With the EU AI Act, additional obligations for AI systems have to be observed since August 2026. For high-risk AI systems within the meaning of Annex III of the AI ​​Act, in addition to the DPIA according to Art. 35 GDPR, a fundamental rights impact assessment (FRIA) according to Art. 27 AI Act is required as soon as the provider is a body under public law or private bodies perform public tasks. Both assessments overlap in content, but must be carried out legally separately because they address different protected interests: The DPIA focuses on personal data, the FRIA on the entire bundle of fundamental rights of those affected.

In the case of automated individual decisions in accordance with Art. 22 GDPR, such as scoring, credit rating or algorithmic applicant selection, the DPIA must be designed particularly carefully. What is required is: description of the logic of the automated decision, training and test data with proof of origin, bias assessment with metrics on protected attributes, human supervision with documented intervention procedures, the data subject's rights of challenge in accordance with Art. 22 Para. 3 GDPR and procedures for correcting incorrect decisions. The EDPB Guidelines on automated decisions (WP251) provide the methodological basis here and are mandatory reading for every DPO who accompanies AI processing.

Any person responsible for using AI-supported processing should start the DPIA early in the life cycle, ideally before model selection. A subsequent DPIA that is intended to justify an already productive system is methodologically questionable and rarely successful in supervisory practice. The CIVAC compliance platform provides an extended DPIA template for AI systems that brings together FRIA building blocks, model map, AI Act risk classification and GDPR assessment in one document. This creates an integrated audit trail from two obligations, which also meets the requirements of Art. 9 AI Act for the risk management system and can be consistently presented to notified bodies, market surveillance authorities and data protection supervisory authorities.

DPIA with CIVAC: Licence Workspace or appoint a representative

A DPIA is not a one-off document, but an ongoing process: threshold analysis, risk assessment, release, review, update. Anyone who operates this process in a fragmented tool landscape loses time and quality of evidence. CIVAC is a compliance platform and officer-as-a-service in one system: 490 ready-to-use audit templates, a linked processing directory, an audit-proof workspace with EU data residency and an ISO/IEC 27001:2022-compliant ISMS with 93 controls. Others run compliance like a filing cabinet. We run it like software.

Licence the workspace for your internal representatives, or have our representatives order it. In the first model, your data protection officer and the department receive the DPIA templates, the threshold analysis logic, the risk matrix and the audit trail in one interface, integrated into the processing directory and the risk register. In the second model, CIVAC takes over the appointment as an external data protection officer including an appointment certificate, reporting line to management and an SLA of 2 working days instead of the industry standard 2 to 6 weeks. The choice depends on your internal capacity, the complexity of your processing and the desired escalation speed.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We will respond within two working days with a specific recommendation as to whether a workspace licence or an external order is the quicker route to an audit-proof DPIA practice in your company. A short needs analysis with three questions about the processing landscape is also sent so that the first conversation becomes immediately substantive and does not get bogged down in discovery phases. If you already have a DPIA in progress, we will be happy to check it as a second opinion and provide a structured list of gaps with reference to Art. 35 Para. 7 GDPR, the DSK short papers and the relevant EDPB guidelines. This turns a formal obligation into a reliable control instrument for your entire processing landscape.

FAQ

When is a DPIA mandatory according to Art. 35 GDPR?

According to Article 35 Para. 1 GDPR, a DPIA is mandatory if the processing is likely to pose a high risk to the rights and freedoms of data subjects. The DSK must-have list specifies this, for example for scoring, biometric identification or extensive employee monitoring. If processing meets two or more of the nine WP248 criteria, the high risk is considered indicated.

What must a DPIA template contain at least according to Art. 35 Para. 7 GDPR?

Four mandatory building blocks: systematic description of processing and purposes, assessment of necessity and proportionality, assessment of risks to the rights and freedoms of data subjects, and planned remedies and guarantees. Supplemented by data flow description, recipient, third country transfer in accordance with Chapter V GDPR and a documented residual risk assessment with release note. Without these building blocks, the DPIA is considered formally incomplete and does not meet the requirements of accountability.

Who carries out the DPIA, the data protection officer or the department?

According to Art. 24 GDPR, the management is responsible, and the department that plans the processing is operationally responsible. The data protection officer advises in accordance with Art. 35 Para. 2 GDPR and monitors the process in accordance with Art. 39 Para. 1 lit. c GDPR, but does not carry out the DPIA himself. Processors are obliged to provide support in accordance with Article 28 Paragraph 3 Letter f of the GDPR.

When should the supervisory authority be consulted in accordance with Art. 36 GDPR?

Whenever the DPIA shows that a high residual risk remains despite all remedial measures. The consultation must take place before processing begins. In accordance with Article 36 (2) GDPR, the supervisory authority will respond in writing within eight weeks, extended by six weeks in complex cases. Processing operations that begin without consultation violate Art. 36 GDPR.

How often should a DPIA be reviewed and updated?

At least once a year and whenever there is a significant change in processing, such as a new service provider, new category of data, changed legal basis or new technology. According to Art. 35 Para. 11 GDPR, the DPIA is a living document. Versioning, change logs and documented reviews are mandatory in order to keep the audit trail complete and traceable throughout the entire processing lifecycle.

How does CIVAC support the creation of an audit-proof DPIA?

The CIVAC compliance platform delivers DPIA template, threshold analysis logic, ISO/IEC 29134:2017 risk matrix and a full audit trail in a workspace with EU data residency and ISO 27001:2022 compliant access control. As officers-as-a-service, our external data protection officers provide advice and implementation of the DPIA, including the appointment certificate and reporting line to the management. Response time: 2 business days instead of the industry standard 2 to 6 weeks.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles