Skip to content
compliancebase
GDPRChapter IV — Data Protection Impact Assessment

Article 35

Data Protection Impact Assessment

GDPR · Regulation (EU) 2016/679 · Last verified August 2026

Objective

Assess high-risk processing before it begins, describing necessity, proportionality, risks to people, and measures that address those risks.

Points of focus

  • Screen new processing for likely high risk
  • Assess necessity, proportionality, and impacts on people
  • Consult the DPO and revisit the assessment when risk changes

Implementation notes

Put DPIA screening in product intake for sensitive data, monitoring, AI, and large-scale profiling; block release on unresolved high risks and link mitigations to engineering acceptance criteria. Operationalize screen new processing for likely high risk in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain dpia screening criteria and completed assessment with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a dpia is completed after launch as a documentation exercise Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.

Audit tip: Sample dpia screening criteria and completed assessment with dates and named reviewers. Be ready to walk through how you detect and correct: a dpia is completed after launch as a documentation exercise

Evidence auditors typically request:

  • DPIA screening criteria and completed assessment
  • Architecture, data-flow, and threat analysis attached to the DPIA
  • Approved mitigations and post-launch review

Common gaps

  • A DPIA is completed after launch as a documentation exercise
  • The assessment scores only company breach cost and not effects on individuals

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 35This control
SOC 2CC3.2, CC6.1Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness.
ISO 27001A.5.34, A.8.10ISO privacy and security controls can implement parts of this duty when mapped to processing.
HIPAA164.308(a)(1)HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data.

Primary sources

Frequently Asked Questions

Data Protection Impact Assessment applies to the systems and commitments in your GDPR scope. Translate the requirement into concrete operating workflows — screen new processing for likely high risk — with evidence stored where auditors and customers can sample it.

Lead with dpia screening criteria and completed assessment and pair it with architecture, data-flow, and threat analysis attached to the dpia. Samples should show who performed the control, when, against which population, and what changed as a result.

Teams often fail because a dpia is completed after launch as a documentation exercise Close the loop with dated operating records and test the control on a realistic production path.

Control operation can often be shared across SOC 2, ISO 27001, GDPR, and HIPAA — but each framework uses different vocabulary and accountability. Maintain an explicit crosswalk rather than assuming equivalence.

Review at least annually and after material product, vendor, or data-flow changes. High-risk or privileged paths may need quarterly sampling even when the criterion does not prescribe a cadence.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: August 2026 · Primary sources linked above