Article 35
Data Protection Impact Assessment
GDPR · Regulation (EU) 2016/679 · Last verified August 2026
Objective
Assess high-risk processing before it begins, describing necessity, proportionality, risks to people, and measures that address those risks.
Points of focus
- Screen new processing for likely high risk
- Assess necessity, proportionality, and impacts on people
- Consult the DPO and revisit the assessment when risk changes
Implementation notes
Put DPIA screening in product intake for sensitive data, monitoring, AI, and large-scale profiling; block release on unresolved high risks and link mitigations to engineering acceptance criteria. Operationalize screen new processing for likely high risk in ticketing, IdP, or GRC workflows with named owners — not only in a static policy PDF. Retain dpia screening criteria and completed assessment with reviewer identity, population scope, dates, and remediation outcomes auditors can sample. A recurring failure mode is that a dpia is completed after launch as a documentation exercise Revisit after material architecture, vendor, data-flow, or leadership changes and document the decision.
Audit tip: Sample dpia screening criteria and completed assessment with dates and named reviewers. Be ready to walk through how you detect and correct: a dpia is completed after launch as a documentation exercise
Evidence auditors typically request:
- DPIA screening criteria and completed assessment
- Architecture, data-flow, and threat analysis attached to the DPIA
- Approved mitigations and post-launch review
Common gaps
- A DPIA is completed after launch as a documentation exercise
- The assessment scores only company breach cost and not effects on individuals
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 35 | This control |
| SOC 2 | CC3.2, CC6.1 | Trust Services Criteria evidence may support accountability, but does not establish GDPR lawfulness. |
| ISO 27001 | A.5.34, A.8.10 | ISO privacy and security controls can implement parts of this duty when mapped to processing. |
| HIPAA | 164.308(a)(1) | HIPAA overlap depends on whether the same data is both ePHI and GDPR personal data. |
Primary sources
- EUR-Lex GDPR Article 35: Regulation (EU) 2016/679, Article 35 — Data Protection Impact Assessment