Data protection impact assessment (DPIA)

Data protection glossary · 1 minute read

The data protection impact assessment is a structured risk analysis for processing operations that are likely to result in a high risk to data subjects.

When is a DPIA mandatory?

It is mandatory, for example, for large-scale monitoring or the processing of sensitive data. The outcome is a set of documented measures that reduce the risk to an acceptable level.

The GDPR cites as typical examples the systematic evaluation of personal aspects with significant effects, for example through profiling, large-scale processing of special categories and systematic large-scale monitoring of publicly accessible areas. The German supervisory authorities have also published a list of processing operations for which a DPIA must always be carried out.

Content and procedure

  • systematic description of the processing and its purposes
  • assessment of necessity and proportionality
  • assessment of the risks to data subjects
  • planned measures to address the risks

The data protection officer must be involved. If a high risk remains despite the measures, the supervisory authority must be consulted before processing begins.

Art. 35 GDPR
Obligation, triggers and minimum content of the data protection impact assessment.
Art. 36 GDPR
Prior consultation of the supervisory authority.
Art. 35(4) GDPR
Supervisory authorities' lists of processing operations requiring a DPIA.

Last updated: September 2026

Questions about this topic?

Dr. Georg Schröder, LL.M. · Managing Director, Lawyer, Data Protection Officer

Book a consultation

In 20 minutes you will know where you stand.

We clarify where action is needed on data protection, AI and information security - and what you should do next.