DPIA threshold assessment
Not every processing operation needs a data protection impact assessment — but skipping one where it is required breaches Art. 35 GDPR. This threshold assessment walks you through the three statutory cases in Art. 35(3) GDPR and the nine risk criteria of the EDPB guideline WP248 rev.01. You get a reasoned outcome you can keep as the record of your assessment.
No signup · runs in your browser · nothing you enter is transmitted
If one of these three cases applies, a DPIA is mandatory without any further assessment.
Indicators of a likely high risk within the meaning of Art. 35(1) GDPR. The guideline's rule of thumb: processing meeting two or more criteria will generally require a DPIA.
Tick everything that applies to the intended processing. The outcome appears here.
Under Art. 35(1) GDPR the controller must carry out a data protection impact assessment prior to the processing where a type of processing — in particular using new technologies — is likely to result in a high risk to the rights and freedoms of natural persons, taking into account the nature, scope, context and purposes of the processing. Art. 35(3) GDPR lists three cases in which a DPIA is required in any event; under Art. 35(4) GDPR the supervisory authorities additionally publish lists of processing operations subject to a mandatory DPIA. When carrying one out, Art. 35(2) GDPR requires the controller to seek the advice of the data protection officer, where one has been designated. If the assessment indicates a high risk that the controller cannot mitigate, the supervisory authority must be consulted prior to the processing under Art. 36 GDPR.
Orientation only — not legal advice. This tool reflects the cases listed in Art. 35(3) GDPR and the criteria of guideline WP248 rev.01; the threshold assessment remains a case-by-case decision of the controller. The mandatory lists of your competent supervisory authority under Art. 35(4) GDPR must be checked in addition and can make a DPIA compulsory even where this tool indicates no high risk.
Frequently asked
- When is a data protection impact assessment mandatory?
- Whenever the processing is likely to result in a high risk to the rights and freedoms of natural persons (Art. 35(1) GDPR). Art. 35(3) GDPR lists three cases where this is assumed without further analysis: a systematic and extensive evaluation of personal aspects serving as the basis for decisions producing legal effects or similarly significantly affecting the person; processing on a large scale of special categories of data under Art. 9(1) or of data relating to criminal convictions and offences under Art. 10; and systematic monitoring of a publicly accessible area on a large scale. On top of that come the lists published by supervisory authorities under Art. 35(4) GDPR. Infringements of Arts. 35 and 36 GDPR can be fined up to EUR 10 million or 2 % of total worldwide annual turnover under Art. 83(4)(a) GDPR.
- What is the "two criteria" rule of thumb?
- Guideline WP248 rev.01 of the Article 29 Working Party, endorsed by the European Data Protection Board, sets out nine criteria for processing likely to result in a high risk: evaluation or scoring; automated decision-making with legal or similarly significant effect; systematic monitoring; sensitive data or data of a highly personal nature; data processed on a large scale; matching or combining datasets; data concerning vulnerable data subjects; innovative use or applying new technological or organisational solutions; and processing that prevents data subjects from exercising a right or using a service or a contract. As a rule of thumb, processing meeting two or more of these criteria will generally require a DPIA. A single criterion can also suffice depending on the nature, scope, context and purposes of the processing.
- Do I have to document a negative outcome as well?
- Yes. Where the threshold assessment concludes that no DPIA is needed, that negative decision forms part of the accountability duty under Art. 5(2) GDPR: the controller must be able to demonstrate compliance, which includes the reasoning for not assuming a likely high risk. Record the date, the criteria examined, the reasoning and the involvement of the data protection officer — otherwise it is your word against the authority's in an inspection.
- When does the DPIA have to be carried out?
- Before the processing starts. Art. 35(1) GDPR requires the assessment to be carried out prior to the envisaged processing operations — it is a planning instrument, not a retrospective report. In practice that means before the rollout of a new system, before a new analysis goes live, before a new procedure is introduced. Where the risk or the processing changes materially, Art. 35(11) GDPR requires the DPIA to be reviewed.
- What is the role of the data protection officer?
- When carrying out a DPIA the controller must seek the advice of the data protection officer, where one has been designated (Art. 35(2) GDPR). Under Art. 39(1)(c) GDPR the DPO provides advice in relation to the data protection impact assessment and monitors its performance. The decision itself remains with the controller — where it departs from the DPO's advice, that should be documented with reasons.
- What if a high risk remains despite mitigation?
- Then the prior consultation under Art. 36 GDPR applies: the controller must consult the supervisory authority prior to the processing where the DPIA indicates that the processing would result in a high risk in the absence of measures to mitigate it. Under Art. 36(2) GDPR the authority responds within eight weeks; the period may be extended by six weeks. Until the response arrives the processing generally has to be put on hold — build that period into your project plan.