Under the GDPR, the legally defined assessment is a Data Protection Impact Assessment (DPIA). A controller must complete one before processing likely to result in a high risk to individuals’ rights and freedoms. A general privacy impact assessment can be useful more broadly, but it does not replace Article 35 where that Article applies.
Screen before design is fixed
Article 35 expressly identifies:
- systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based;
- large-scale processing of Article 9 special-category data or Article 10 criminal-conviction data; and
- systematic monitoring of publicly accessible areas on a large scale.
Also check the relevant supervisory authority’s Article 35(4) list. The EDPB-endorsed guidance offers contextual criteria such as evaluation or scoring, automated decisions, systematic monitoring, sensitive data, large scale, matching datasets, vulnerable individuals, innovative technology, and processing that prevents people exercising a right or using a service. These are aids to a risk judgment, not a universal arithmetic rule that replaces Article 35 and authority lists.
Keep a screening record for both “DPIA required” and significant “not required” decisions. Re-screen after material changes.
Minimum DPIA content
Article 35(7) requires at least:
- a systematic description of envisaged processing and purposes, including legitimate interests where applicable;
- an assessment of necessity and proportionality in relation to those purposes;
- an assessment of risks to individuals’ rights and freedoms; and
- measures envisaged to address risks and demonstrate compliance, taking account of the rights and legitimate interests of individuals and others concerned.
This means a DPIA should not be only a security risk register. Consider discrimination, exclusion, loss of control, surveillance, chilling effects, financial harm, identity misuse, confidentiality, inability to exercise rights and other impacts on people.
A practical DPIA workflow
1. Establish scope and roles
Name the controller, joint controllers, processors, accountable owner, DPO involvement and assessment team. Define versions and system boundaries.
2. Describe processing
Document data sources, people and categories, purposes, logic, recipients, systems, locations, transfers, retention, access and the full lifecycle. Use diagrams where they clarify flows.
3. Test necessity and proportionality
For each purpose ask whether the processing and every data field are genuinely needed, whether a less intrusive approach can work, how lawful basis and transparency are addressed, and how rights, retention and processor controls operate.
4. Assess risk to people
Describe plausible events and consequences, affected groups, existing measures, and reasoned likelihood and severity. Avoid unsupported numerical precision. Treat vulnerable people and cumulative or irreversible effects explicitly.
5. Select and assign measures
Measures may include reducing data, changing defaults, limiting access, separating datasets, human review, stronger transparency, encryption, pseudonymisation, shorter retention, audit logging, testing or deciding not to proceed. Assign owners and due dates.
6. Consult and decide
Seek the DPO’s advice where one is appointed and record it. Article 35(9) says controllers shall, where appropriate, seek individuals’ or representatives’ views without prejudicing commercial/public interests or processing security. Management accepts, changes or stops the processing and records residual risk.
7. Prior consultation and review
If high residual risk would remain without measures to mitigate it, consult the supervisory authority before processing under Article 36. Review the DPIA when processing risk changes and at appropriate intervals.
About the 2026 EDPB template
In 2026 the EDPB published a DPIA template for public consultation and encouraged organisations to use and comment on it during that stage. As of this review, the EDPB page says the template will be finalised after consultation. It is therefore a useful current resource, but should not be described as already-final binding law or as eliminating applicable national requirements.
Common failures include completing the DPIA after launch, treating vendor documents as the controller’s assessment, listing controls without testing necessity, excluding non-security harms, and accepting high risk without evaluating Article 36.
Our data protection service supports DPIA facilitation and remediation while leaving accountable decisions with the controller. A GDPR audit can test whether screening and DPIA evidence match actual processing.
Sources and review
- Regulation (EU) 2016/679, Articles 35 and 36
- EDPB: DPIA and high-risk processing guidance (WP248 rev.01)
- EDPB: 2026 DPIA template public-consultation page
Reviewed on 8 August 2026. The 2026 template’s consultation status and Article 36’s high-residual-risk threshold are stated explicitly.
Ivana Ludiga, mag. iur., is an Associate at Vision Compliance focused on data protection, GDPR implementation, and regulatory advisory. She supports compliance projects for organizations across healthcare, financial services, and technology sectors.