Data Protection Impact Assessments (DPIAs) and Prior Consultation
GDPR Articles 35 and 36 form the core of the Regulation's risk-based accountability framework, operationalising the principles established across several foundational articles.
Principles of processing — the bedrock of lawful, fair, and transparent data handling.
Responsibility of the controller — accountability obligations placed on organisations.
Data Protection by Design and by Default — embedding privacy into systems from the outset.
Security of Processing — technical and organisational measures to protect personal data.
Requires organisations to identify, assess, and mitigate risks to individuals before high-risk processing begins.
Establishes a mechanism requiring consultation with a supervisory authority when residual high risks remain despite mitigation efforts.
Article 35 requires a controller to perform a DPIA whenever processing is likely to result in a high risk, involves new technologies, affects the rights and freedoms of natural persons, or creates significant privacy, ethical, social, economic, or discrimination risks.
Evaluating how processing affects individuals' reasonable expectations of privacy and data control.
Assessing whether processing meets all applicable GDPR obligations, including lawful basis and data subject rights.
Examining broader societal impacts including fairness, autonomy, and freedom from discrimination.
Documenting organisational and technical safeguards as evidence of accountability under Articles 5(2) and 24.
A DPIA is mandatory where processing is "likely to result in a high risk to the rights and freedoms of natural persons." Article 35(3) provides explicit examples of processing operations that always require a DPIA.
Educational technology platforms monitoring student performance trigger DPIA requirements due to vulnerability considerations.
Employee keystroke monitoring, screen capture technology, and productivity analytics generally require a DPIA.
Payroll processing and basic benefits administration are generally low risk.
Customer contact databases and basic sales communications typically require no DPIA.
Office visitor logs retained briefly usually require no DPIA.
Article 35(7) mandates specific elements that every DPIA must contain. These components ensure a thorough, defensible, and accountable assessment of processing activities.
The DPIA must evaluate risks including those identified in Recital 75:
Must identify controls to reduce residual risk to acceptable levels:
Where a DPO exists, Article 35(2) requires the controller to seek DPO advice. DPO recommendations must be documented, and any management decisions departing from those recommendations must be formally justified.
When appropriate, Article 35(9) encourages consultation with affected parties to strengthen DPIA defensibility:
Review should occur when any of the following change:
Article 36 acts as a regulatory safeguard when high risks remain, mitigation measures cannot adequately reduce those risks, and processing is intended to proceed despite significant residual risk. In such cases, the supervisory authority must be consulted before processing begins.
Perform a comprehensive DPIA under Article 35 identifying all risks to rights and freedoms.
Implement all feasible safeguards, technical controls, and organisational measures to reduce risk.
Evaluate whether residual risk remains high after all mitigation efforts. The focus is residual risk, not initial risk.
If residual risk remains high and processing is to proceed, prior consultation with the supervisory authority is mandatory.
Nationwide deployment with continuous biometric identification, real-time public surveillance, and high civil liberties impact. Even with strong controls, residual risk remains substantial.
Automated evaluation of citizens with significant effects on rights, and risk of exclusion and discrimination.
Massive special-category data processing, AI-driven predictive outcomes, and cross-organisational data sharing.
The key distinction is whether mitigation measures have genuinely reduced residual risk to an acceptable level, or whether significant risk to rights and freedoms persists despite best efforts.
Responsibilities of controllers and processors involved in the processing.
Processing purposes, methods, and the safeguards implemented.
Full DPIA documentation and DPO contact details.
Any further information requested by the supervisory authority.
Upon consultation, authorities may exercise significant powers:
Articles 35 and 36 do not operate in isolation. They intersect with a broad network of GDPR provisions spanning controller obligations, data subject rights, supervisory authority powers, and governance mechanisms.

The following cross-cutting controls support compliance with Articles 35 and 36 across the enterprise. Each control addresses a specific dimension of the DPIA and prior consultation framework.
Mature organisations treat DPIAs as multi-dimensional instruments, not compliance tick-boxes:
The strongest DPIAs demonstrate full traceability across the entire processing lifecycle:
In advanced GDPR programmes, Articles 35 and 36 function as the bridge between legal compliance, enterprise risk management, cybersecurity, AI governance, and digital ethics.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
GDPR Articles 35 & 36