Learn the legal criteria and categories of processing that require mandatory DPIA.
The GDPR establishes that DPIA is mandatory when processing is likely to result in high risk. There are 3 situations that automatically trigger this obligation.
Article 35(3)(a)
Systematic and extensive evaluation of personal aspects, including profile definition for analysis or prediction related to professional performance, economic situation, health, preferences or interests.
Article 35(3)(b)
Large-scale processing of special categories of data (Art. 9) or data relating to criminal convictions and offences (Art. 10).
Article 35(3)(c)
Systematic monitoring of publicly accessible areas on a large scale (video surveillance, facial recognition, etc.).
The European Data Protection Board defined 9 additional criteria to assess whether processing results in high risk.
National Supervisory Authorities have identified specific categories of processing that require mandatory DPIA regardless of case-by-case analysis.
Answer these questions to determine if your data processing requires mandatory DPIA.
There are situations where, despite high-risk criteria, DPIA may not be mandatory or can be simplified.
If national legislation authorizes and specifically regulates processing (with its own risk assessment), full DPIA may be waived, but risk documentation is required.
Compliance with an approved code of conduct or certification by the Supervisory Authority may exempt or simplify DPIA requirements.
If a previous risk assessment (earlier DPIA) concludes that processing presents no high risk, automatic repetition is not necessary.
Failure to conduct mandatory DPIA results in significant administrative fines.
Supervisory Authorities have competence to impose fines for breach of Article 35 (mandatory DPIA) and Article 36 (prior consultation).
Determined that DPIA is mandatory? Learn how to proceed.
Learn the structured methodology and 7 essential steps for a complete and documented DPIA.
Explore specific examples: video surveillance, biometrics, AI, health, geolocation and others.
Audiqcer offers complete DPIA conducting, reviewing and training services for your organisation.
Contact us for a personalised initial assessment of your situation.
Briefly describe your data processing context to receive personalised recommendations.