GDPR Articles 35 & 36

Data Protection Impact Assessments (DPIAs) and Prior Consultation

Foundational Context

GDPR Articles 35 and 36 form the core of the Regulation's risk-based accountability framework, operationalising the principles established across several foundational articles.

Article 5

Principles of processing — the bedrock of lawful, fair, and transparent data handling.

Article 24

Responsibility of the controller — accountability obligations placed on organisations.

Article 25

Data Protection by Design and by Default — embedding privacy into systems from the outset.

Article 32

Security of Processing — technical and organisational measures to protect personal data.

Article 35 — Proactive Risk Assessment

Requires organisations to identify, assess, and mitigate risks to individuals before high-risk processing begins.

Article 36 — Regulatory Escalation

Establishes a mechanism requiring consultation with a supervisory authority when residual high risks remain despite mitigation efforts.

Article 35 GDPR — Data Protection Impact Assessment

Purpose & Scope

Article 35 requires a controller to perform a DPIA whenever processing is likely to result in a high risk, involves new technologies, affects the rights and freedoms of natural persons, or creates significant privacy, ethical, social, economic, or discrimination risks.

Privacy Impacts

Evaluating how processing affects individuals' reasonable expectations of privacy and data control.

Legal Compliance

Assessing whether processing meets all applicable GDPR obligations, including lawful basis and data subject rights.

Human Rights Implications

Examining broader societal impacts including fairness, autonomy, and freedom from discrimination.

Governance Controls

Documenting organisational and technical safeguards as evidence of accountability under Articles 5(2) and 24.

Legal Threshold for Triggering a DPIA

A DPIA is mandatory where processing is "likely to result in a high risk to the rights and freedoms of natural persons." Article 35(3) provides explicit examples of processing operations that always require a DPIA.

1

Systematic & Extensive Profiling

  • Automated decision-making and credit scoring
  • Insurance underwriting and employment screening
  • AI-based hiring systems and behavioural advertising
2

Large-Scale Special Category Data

  • Health, biometric, and genetic data
  • Religious beliefs and political opinions
  • Criminal offence information
3

Large-Scale Public Area Monitoring

  • CCTV networks and smart city surveillance
  • Facial recognition systems
  • Intelligent transportation monitoring

Situations Commonly Requiring DPIAs

AI & Machine Learning

  • Predictive analytics
  • Generative AI systems
  • Employee monitoring AI
  • Customer behaviour prediction

Behavioural Profiling

  • Browsing and purchase history
  • Location information
  • Third-party data enrichment
  • Extensive combined profiling

Internet of Things (IoT)

  • Smart home audio data
  • Motion and occupancy data
  • Continuous environmental monitoring

Children's Data, Workplace Monitoring & Exemptions

Likely DPIA Triggers

Children's Data

Educational technology platforms monitoring student performance trigger DPIA requirements due to vulnerability considerations.

Workplace Monitoring

Employee keystroke monitoring, screen capture technology, and productivity analytics generally require a DPIA.

Where a DPIA May Not Be Required

Routine HR Administration

Payroll processing and basic benefits administration are generally low risk.

Standard CRM Operations

Customer contact databases and basic sales communications typically require no DPIA.

Limited Internal Administration

Office visitor logs retained briefly usually require no DPIA.

Required DPIA Components

Article 35(7) mandates specific elements that every DPIA must contain. These components ensure a thorough, defensible, and accountable assessment of processing activities.

Processing Description

  • Detailed data flows and processing purposes
  • Systems and stakeholders involved
  • Data lifecycle mapping

Necessity Assessment

  • Why is the processing needed?
  • Can the objective be achieved differently?
  • Is all collected data necessary?

Proportionality Assessment

  • Is processing excessive?
  • Is collection minimised?
  • Are retention periods justified?

Rights, Freedoms, Mitigation & the DPO's Role

Rights and Freedoms Risk Assessment

The DPIA must evaluate risks including those identified in Recital 75:

Discrimination

Identity Theft

Financial Harm

Reputational Harm

Surveillance Impacts

Loss of Autonomy

Chilling Effects

Service Exclusion

Mitigation Measures

Must identify controls to reduce residual risk to acceptable levels:

  • Safeguards and organisational controls
  • Technical controls
  • Governance mechanisms

Role of the Data Protection Officer

Where a DPO exists, Article 35(2) requires the controller to seek DPO advice. DPO recommendations must be documented, and any management decisions departing from those recommendations must be formally justified.

Stakeholder Consultation & Continuous DPIA Review

Article 35(9) — Stakeholder Consultation

When appropriate, Article 35(9) encourages consultation with affected parties to strengthen DPIA defensibility:

Affected Individuals

Employee Representatives & Works Councils

Patient Groups

Consumer Representatives

Article 35(11) — Continuous Review

Review should occur when any of the following change:

  • Technologies change
  • Processing purposes change
  • Vendors change
  • Risk profiles change
  • Data categories expand

Article 36 GDPR — Prior Consultation

Article 36 acts as a regulatory safeguard when high risks remain, mitigation measures cannot adequately reduce those risks, and processing is intended to proceed despite significant residual risk. In such cases, the supervisory authority must be consulted before processing begins.

Step 1 — Conduct DPIA

Perform a comprehensive DPIA under Article 35 identifying all risks to rights and freedoms.

Step 2 — Apply Mitigation

Implement all feasible safeguards, technical controls, and organisational measures to reduce risk.

Step 3 — Assess Residual Risk

Evaluate whether residual risk remains high after all mitigation efforts. The focus is residual risk, not initial risk.

Step 4 — Consult Supervisory Authority

If residual risk remains high and processing is to proceed, prior consultation with the supervisory authority is mandatory.

Prior Consultation — Examples in Practice

Likely Requiring Prior Consultation

National Facial Recognition Programme

Nationwide deployment with continuous biometric identification, real-time public surveillance, and high civil liberties impact. Even with strong controls, residual risk remains substantial.

AI-Based Social Scoring

Automated evaluation of citizens with significant effects on rights, and risk of exclusion and discrimination.

National Health Analytics Platform

Massive special-category data processing, AI-driven predictive outcomes, and cross-organisational data sharing.

Not Requiring Prior Consultation

The key distinction is whether mitigation measures have genuinely reduced residual risk to an acceptable level, or whether significant risk to rights and freedoms persists despite best efforts.

Prior Consultation — Information & Supervisory Authority Powers

Information Controllers Must Provide

01

Responsibilities

Responsibilities of controllers and processors involved in the processing.

02

Processing Details

Processing purposes, methods, and the safeguards implemented.

03

DPIA Documentation

Full DPIA documentation and DPO contact details.

04

Additional Information

Any further information requested by the supervisory authority.

Supervisory Authority Powers

Upon consultation, authorities may exercise significant powers:

  • Issue recommendations
  • Require additional safeguards
  • Prohibit proposed processing
  • Require design modifications
  • Impose compliance obligations

GDPR Articles Intersecting with Articles 35 & 36

Articles 35 and 36 do not operate in isolation. They intersect with a broad network of GDPR provisions spanning controller obligations, data subject rights, supervisory authority powers, and governance mechanisms.

Twenty Governance & Technical Controls — Part I

Controls 1–5

The following cross-cutting controls support compliance with Articles 35 and 36 across the enterprise. Each control addresses a specific dimension of the DPIA and prior consultation framework.

1

Formal DPIA Governance Framework

  • Enterprise DPIA policy
  • Defined risk methodology
  • Executive accountability
2

Processing Activity Inventory

  • Comprehensive Article 30 records
  • System inventory integration
  • Data flow cataloguing
3

DPIA Trigger Screening Process

  • Automated screening questionnaires
  • Project initiation checkpoints
  • Procurement integration
4

Privacy-by-Design Architecture Reviews

  • Mandatory privacy review before deployment
  • Design-stage risk identification
5

Data Classification Framework

  • Sensitivity-based categorisation
  • Risk-weighted controls

Twenty Governance & Technical Controls — Part II

Controls 6–10

Data Minimisation Controls

  • Attribute reduction
  • Collection limitation
  • Purpose-based restrictions

Purpose Limitation Enforcement

  • Purpose tagging
  • Technical segregation
  • Use-case authorisation

Lawful Basis Validation Controls

  • Processing purpose mapping
  • Legal basis verification

Identity & Access Management

  • Least privilege principle
  • Role-based access control
  • Privileged access monitoring

Multi-Factor Authentication

  • Administrative access protection
  • Remote access security

Twenty Governance & Technical Controls — Part III

Controls 11–15
1

Encryption Controls

  • Encryption at rest
  • Encryption in transit
  • Key management governance
2

Pseudonymisation Framework

  • Tokenisation
  • Re-identification controls
  • Separation of identity data
3

Data Retention & Disposal

  • Automated deletion
  • Retention schedules
  • Secure destruction verification
4

Vendor Risk Management

  • Processor due diligence
  • Security assessments
  • Contractual GDPR obligations
5

AI & Algorithmic Accountability

  • Explainability assessments
  • Bias testing and fairness evaluations
  • Model governance reviews

Twenty Governance & Technical Controls — Part IV

Controls 16–20

Continuous Risk Monitoring

  • Residual risk tracking
  • Risk register integration
  • Control effectiveness reviews

Security Monitoring & Detection

  • SIEM monitoring
  • Threat detection
  • Audit logging

Data Subject Rights Enablement

  • DSAR workflows
  • Erasure mechanisms
  • Rectification and objection management

Independent Privacy Assurance

  • Internal audits and external assessments
  • Control testing
  • DPIA quality reviews

Supervisory Authority Escalation

  • Residual risk decision criteria
  • Article 36 consultation workflow
  • Regulatory engagement playbooks
  • Executive approval before high-risk processing

Advanced Points

What Mature Organisations Understand

Mature organisations treat DPIAs as multi-dimensional instruments, not compliance tick-boxes:

Governance Instruments

Architecture Review Mechanisms

Ethics Assessments

Accountability Evidence

Regulatory Defensibility Artefacts

The Gold Standard — DPIA Traceability Chain

The strongest DPIAs demonstrate full traceability across the entire processing lifecycle:

Processing Purpose & Lawful Basis

Risk Identification & Control Selection

Residual Risk Determination & Executive Acceptance

Supervisory Authority Consultation (where necessary)

In advanced GDPR programmes, Articles 35 and 36 function as the bridge between legal compliance, enterprise risk management, cybersecurity, AI governance, and digital ethics.

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.