Article 35 of the GDPR: Data Protection Impact Assessment (DPIA)
Article 35 of the GDPR Explained
A DPIA is notably required in the following cases:
- Large-scale processing of sensitive or highly personal data;
- Systematic monitoring of publicly accessible areas;
- Extensive data cross-referencing, profiling, automated scoring…
A DPIA includes:
- A description of the processing and its purposes;
- An assessment of necessity and proportionality;
- An assessment of risks to rights and freedoms;
- The measures envisaged to mitigate these risks.
Why this article is important for your GDPR compliance
The DPIA enables anticipation of legal, ethical, and technical risks, and demonstration of compliance. It is required in many cases and constitutes a pillar of the GDPR's risk-based approach.
GDPR Article 35: Application Examples
- A local authority implements a video surveillance system: a DPIA is mandatory;
- A bank launches a credit scoring application: the impact assessment is carried out;
- An HR platform uses artificial intelligence to sort applications: it documents the risks via a DPIA.
Related Resources
Accelerate Your Compliance in a Few Clicks
Thanks to our all-in-one solution, you can accelerate and ensure your compliance with ease:
- Automate your compliance with our GDPR software
- Supported or outsourced by our DPO experts
- Raise your teams' awareness with our GDPR training e-learning
Assess your situation in 15 minutes with our free, no-obligation GDPR self-assessment.
How to comply with Article 35 of the GDPR