Guide · GDPR
When is a DPIA required? GDPR Article 35 in full, with the three cases it names
A DPIA is required before any processing that is likely to result in a high risk to people's rights and freedoms, and GDPR Article 35(3) names three cases where that is always so. They are automated evaluation that drives decisions with legal or similarly significant effects, large-scale processing of special-category or criminal-offence data, and large-scale systematic monitoring of a publicly accessible area.
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.
The figure behind it
Article 36(2) gives the supervisory authority up to 8 weeks from your request to give written advice on a high-risk processing plan, extendable by a further 6 weeks for complex processing. Source: Regulation (EU) 2016/679, Article 36(2), EUR-Lex text as held by Rekvira (corpus of 2 September 2026)
Everything quoted below came back from Rekvira's tools on 24 September 2026, from the EUR-Lex text of the GDPR (Regulation (EU) 2016/679). The UK GDPR keeps the same article numbers.
What does Article 35 actually require?
The duty sits in the first paragraph and has three parts: a trigger (processing likely to result in a high risk), an addressee (the controller, not the processor) and a moment (prior to the processing). The same paragraph lets one assessment cover "a set of similar processing operations that present similar high risks", so you do not need a separate DPIA for every instance of the same system.
Article 35 has 11 paragraphs. Only some of them are duties on you; the rest are addressed to regulators or to Member States.
| Paragraph | Who it binds | What it says, in short |
|---|---|---|
| 35(1) | Controller | Assess before processing that is likely to be high-risk |
| 35(2) | Controller | Seek the DPO's advice, where one is designated |
| 35(3) | Controller | Three cases where a DPIA is always required |
| 35(4), (5), (6) | Supervisory authority | Lists of operations that need one, or do not |
| 35(7) | Controller | The four minimum contents |
| 35(8) | Whoever assesses | Approved codes of conduct count in the assessment |
| 35(9) | Controller | Seek data subjects' views "where appropriate" |
| 35(10) | Member States | Exemption where a law already carried out the assessment |
| 35(11) | Controller | Review when the risk changes |
read_unit call below (11 paragraph pinpoints returned). Summaries are ours; the article text is linked above.When is a DPIA always required?
Article 35(3) is the part people search for. It is a floor, not the full list: "in particular" means other high-risk processing still needs an assessment.
"A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale." (Article 35(3))
The Regulation does not define "large scale" in an article. Recital 91 gives the reading the legislator had in mind: operations that "aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a large number of data subjects". The same recital names monitoring of public areas "especially when using optic-electronic devices", which is CCTV in plain English.
How do you decide for everything else?
One workable order, with the paragraph behind each step:
- Is the operation on your regulator's list? Article 35(4) obliges every supervisory authority to publish one. Use the list of the authority that supervises you (in the UK the ICO's, in Ireland the Data Protection Commission's).
- Is it on a "no DPIA needed" list? Article 35(5) allows one but does not require it, so check whether your authority has published one.
- Does it fall under Article 35(3)? If yes, you need one, whatever the lists say.
- Is high risk still likely? Weigh "the nature, scope, context and purposes of the processing" (Article 35(1)). New technology, large numbers and sensitive data push the answer towards yes.
- Record the reasoning either way. A screening that ends in "no DPIA" is the evidence you will be asked for.
What must the assessment contain?
Article 35(7) sets a minimum of four elements. A template that lacks any of them is not a DPIA under the Regulation, however long it is.
| Element | Article 35(7) wording |
|---|---|
| Description | "a systematic description of the envisaged processing operations and the purposes of the processing" |
| Necessity | "an assessment of the necessity and proportionality of the processing operations in relation to the purposes" |
| Risks | "an assessment of the risks to the rights and freedoms of data subjects" |
| Measures | "the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data" |
What if the risk is still high after your measures?
Then Article 36 applies, and it has a clock. You consult the supervisory authority before processing starts, and you send it the DPIA itself along with the purposes, the safeguards and your DPO's contact details (Article 36(3)).
8 weeks
for the regulator's written advice after your request (Article 36(2))
+6 weeks
extension the regulator may add for complex processing, notified within one month
11
paragraphs in Article 35, six of them duties on the controller
read_unit on 24 September 2026.Does the EU AI Act change this?
It points back to it: a deployer of a high-risk AI system must use the provider's instructions (the Article 13 information) to carry out its GDPR DPIA:
"Where applicable, deployers of high-risk AI systems shall use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment under Article 35 of Regulation (EU) 2016/679 or Article 27 of Directive (EU) 2016/680." (EU AI Act, Article 26(9))
Article 26 sits in Chapter III of the AI Act. After Regulation (EU) 2026/1744 its application date for Annex III systems is 2 December 2027. The GDPR duty does not wait for that date; it applies now. When the AI Act article starts to apply, the deployer's DPIA simply gets a second, AI-specific input. The role split behind this is in EU AI Act obligations by role.
Recorded run
The question:When is a DPIA required under the GDPR, and what must it contain?
list_regulations()Confirm the GDPR is loaded and read its
data_as_of.search_regulation(regulation="gdpr", query="when is a data protection impact assessment required")Let the corpus rank the passages for the reader's own question.
"Article 35(3)" ranked first of the 10 passages on the first page for the question as typed.
read_unit(regulation="gdpr", kind="article", number="35")Read Article 35 whole, not a search excerpt.
The whole article in 11 pinpointed paragraphs, including "the controller shall, prior to the processing, carry out an assessment"
read_unit(regulation="gdpr", kind="article", number="36")What happens when the assessment still shows high risk: prior consultation.
"within period of up to eight weeks of receipt of the request for consultation" and "That period may be extended by six weeks"
read_unit(regulation="gdpr", kind="recital", number="91")The recital that explains 'large scale' and the examples the legislator had in mind.
verify_citation(regulation="gdpr", citation="Article 35(1)", quote="the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data")Check the pinpoint and the exact sentence before quoting it.
Quote found: the Article 35(1) sentence quoted at the top of this page is the held text.
search_regulation(regulation="eu-ai-act", query="deployer data protection impact assessment Article 35")Where the AI Act sends a deployer back to the GDPR DPIA.
The AI Act search put the AI Act's own "Article 35" (notified bodies) above "Article 26(9)": a reason to read the unit, not trust a rank.
read_unit(regulation="eu-ai-act", pinpoint="Article 26(9)")Read the AI Act bridge to Article 35 in full.
"deployers of high-risk AI systems shall use the information provided under Article 13"
Real calls to Rekvira’s production server, captured 24 September 2026. Corpus as of 24 September 2026.
Limits
Rekvira returns the text of the Regulation with its pinpoint and the date of the text. It does not tell you whether your processing is high-risk; that judgement, and the DPIA itself, stay with the controller and the DPO. National lists under Article 35(4) and UK-specific ICO guidance are not in the corpus.
Do this in your assistant
Read GDPR Article 35 and Article 36 with Rekvira. For a processing operation I will describe,
tell me which paragraph of Article 35(3), if any, it falls under, quote the words that match,
and list the four elements Article 35(7) requires, each with its pinpoint.Paste this into Claude, ChatGPT, Cursor or any MCP client connected to https://mcp.rekvira.com/mcp. No account is needed to start.Install steps for each client
Start with the keyless trial.
No account, no API key, and free during the beta.
https://mcp.rekvira.com/mcp