Privacy risk assessment & DPIA under GDPR Art. 35
A Data Protection Impact Assessment (DPIA) is the GDPR's structured way to find and reduce privacy risk before you launch processing (European Commission — when is a DPIA required). It is mandatory under Article 35 whenever processing is "likely to result in a high risk to the rights and freedoms of natural persons." For most small sites it isn't triggered, but it is the single most important document when you build profiling, large-scale sensitive-data, or monitoring features. Your data inventory tells you which activities to screen.
1. When a DPIA is mandatory (Art. 35(3))
A DPIA is required at least when processing involves:
- (a) Systematic, extensive evaluation based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based;
- (b) Large-scale processing of special-category data (Art. 9) or criminal-offence data (Art. 10); or
- (c) Systematic monitoring of a publicly accessible area on a large scale.
National supervisory authorities also publish "blacklists" of processing that always require a DPIA and "whitelists" that don't (Art. 35(4)–(5)).
2. The EDPB nine-criteria screen
The EDPB's DPIA guidelines (WP248) list nine risk criteria; meeting two or more usually means a DPIA is required (one may be enough in some cases) (EDPB — DPIA guidelines):
- Evaluation or scoring (profiling, predicting)
- Automated decision-making with legal/significant effects
- Systematic monitoring
- Sensitive data or highly personal data
- Data processed on a large scale
- Matching or combining datasets
- Data concerning vulnerable subjects
- Innovative use or new technology
- Processing that prevents data subjects from exercising a right
3. What the DPIA must contain (Art. 35(7))
- A systematic description of the processing and its purposes (including any legitimate interest).
- An assessment of necessity and proportionality against the purpose.
- An assessment of the risks to individuals' rights and freedoms.
- The measures to address those risks — safeguards, security, and compliance mechanisms.
Consult your DPO where one is designated (Art. 35(2)), and seek the views of affected individuals where appropriate (Art. 35(9)). If residual risk stays high after mitigations, you must run prior consultation with the supervisory authority before processing (Art. 36).
4. Treat it as a living tool
A DPIA is not a one-off form. Run it before processing, review it when the risk changes (new data, new tech, new purpose), and keep it tied to your RoPA (GDPR.eu — Art. 35; GloCert DPIA guide). It pairs naturally with your breach prevention plan: the same risks you assess are the ones a breach would realise.
Decision-support note. PrivScan can surface likely high-risk signals — large-scale trackers, sensitive-data collection points, and monitoring patterns — to help you decide whether a DPIA is warranted, and returns a prioritized checklist. It screens; it does not perform the DPIA or replace a DPO's sign-off.