Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

When is a DPIA required: three mandatory cases, nine WP248 criteria and the two-criteria rule

When Is a DPIA Required? The Essential 2026 Guide to the 9 Criteria

When is a DPIA required? Under Article 35 of the GDPR, whenever a type of processing is likely to result in a high risk to the rights and freedoms of the people whose data it is, and always before that processing starts. The difficulty is the word “likely”: the regulation names only three cases outright and leaves the rest to judgment. This guide sets out every source you need to make that judgment and record it: the three mandatory cases, the nine criteria European regulators use, your authority’s own list, and the situations where a DPIA is not needed.

It is written for the person who has to answer the question for a new project, often in a hurry, and then defend the answer to an auditor or a regulator.

When is a DPIA required: three mandatory cases, nine WP248 criteria and the two-criteria rule
Overview of GDPR Article 35 DPIA requirements, criteria, and when a DPIA is needed.

The Legal Test: When Is a DPIA Required Under Article 35?

Article 35(1) requires the controller to carry out a data protection impact assessment “prior to the processing” where a type of processing, “in particular using new technologies”, and taking into account its nature, scope, context and purposes, is likely to result in a high risk to the rights and freedoms of natural persons. Three points in that sentence matter in practice:

  • It is a forecast, not a finding. You do not need to show that harm will happen, only that high risk is likely. The DPIA itself is where the risk gets measured.
  • It comes first. A DPIA written after launch is evidence that one was missed.
  • It is about people. The risk that counts is to the individuals concerned, not to the organization.

UK GDPR keeps the same wording, so the answer is the same in the UK and the EU.

Three Cases Where a DPIA Is Always Required

Article 35(3) names three kinds of processing that always need a DPIA:

  1. Systematic and extensive evaluation of people based on automated processing, including profiling, used for decisions that produce legal or similarly significant effects. Automated credit decisions and CV screening that rejects candidates are the classic examples.
  2. Large-scale processing of special category data (health, biometric, genetic, racial or ethnic origin, religion, sexual orientation, trade union membership, political opinions) or criminal offence data.
  3. Systematic monitoring of a publicly accessible area on a large scale, such as CCTV networks across public spaces.

If any one of these applies, the screening is over, and the answer to when is a DPIA required is simple: now, before the processing starts.

The Nine WP248 Criteria

For everything else, the Article 29 Working Party’s DPIA guidelines (WP248 rev.01), endorsed by the European Data Protection Board, give nine criteria that point to high risk:

CriterionWhat it coversTypical example
1. Evaluation or scoringProfiling and predicting, especially performance, finances, health, preferences, locationCredit or fraud scoring; behavioural profiles
2. Automated decisions with legal or similar effectDecisions made without meaningful human involvementAutomatic rejection of loan or job applications
3. Systematic monitoringObserving, monitoring or controlling peopleEmployee monitoring; tracking online behaviour
4. Sensitive or highly personal dataSpecial category and criminal data, plus location, financial data and private communicationsHealth apps; payment histories; messages
5. Large scaleNumber of people, volume of data, duration, geographical extentA national customer base
6. Matching or combining datasetsLinking data from different sources or purposes in unexpected waysEnriching customer records with third-party data
7. Vulnerable peopleAnyone with less power in the relationshipChildren, employees, patients, the elderly
8. Innovative technologyNew technology, or a new use of existing technologyAI, biometrics, connected devices
9. Preventing a right or a serviceProcessing that decides whether someone can use a service or enter a contractScreening that decides access to credit or insurance

The Two-Criteria Rule

The guidelines say that in most cases, processing meeting two of the criteria will require a DPIA, and that the more criteria are met, the more likely the processing is to be high risk. They also say a single criterion can be enough in some cases, and that where it is unclear whether a DPIA is required, one should be done. The ICO takes the same line.

So the practical answer to when is a DPIA required is: at two criteria, assume yes; at one, think hard and record why; at none, record the screening anyway.

Your Supervisory Authority’s List

Article 35(4) requires each supervisory authority to publish a list of processing that always needs a DPIA in its country, and Article 35(5) allows it to publish a list that does not. Check the list for every country where you operate. The ICO’s list for the UK, for example, adds ten types of processing, including innovative technology, denial of service, large-scale profiling, biometric and genetic data, data matching, invisible processing, tracking, targeting children or other vulnerable people, and processing where a breach could put someone’s physical safety at risk. The ICO explains each one in its guidance on when a DPIA is needed.

When a DPIA Is Not Required

The WP248 guidelines list the situations where a DPIA is not needed:

  • the processing is not likely to result in a high risk;
  • it is very similar in nature, scope, context and purposes to processing that already has a DPIA, which can be relied on;
  • it was checked by a supervisory authority before May 2018 under the conditions that still apply;
  • it has a legal basis in EU or member state law that already included a general impact assessment (Article 35(10));
  • it is on the authority’s list of processing that does not need one.

Even then, the screening decision and the reasons for it should be written down. “We looked and decided no DPIA was needed, because…” is itself evidence of accountability.

Worked Examples: When Is a DPIA Required?

ProcessingCriteria metDPIA?
Telematics and in-cab cameras in company vansScoring, monitoring, highly personal data, employees, new technologyYes
Loyalty app tracking shoppers in storeProfiling, monitoring, location data, large scale, combined datasetsYes
AI tool that shortlists job applicantsEvaluation, automated decisions, preventing access to a jobYes
Monthly email newsletter to subscribersNoneNo; record the screening
New HR system for existing staff recordsEmployees (one criterion)Borderline; a DPIA is good practice

Our DPIA example walks through the first of these from screening to sign-off.

How to Record the Screening

Whatever the answer, write the screening down. A short record is enough, but it should cover:

  • the processing, its purpose and the owner;
  • whether any Article 35(3) case applies;
  • whether the processing is on your authority’s list;
  • which of the nine criteria are met, with a sentence on each;
  • the verdict (required, recommended or not required) and the reasoning;
  • the DPO’s advice, the date and who decided.

That record answers the question an auditor or regulator will ask first: how did you decide when is a DPIA required for this processing? It also gives you a baseline, so that when the processing changes you can see which criteria have moved. Keep screenings with your records of processing activities so the two stay in step.

Existing Processing and Reviews

A DPIA is not a one-off. Article 35(11) expects a review at least when the risk represented by the processing changes, and processing that did not need a DPIA when it started can need one after a change: a new purpose, new data, a new technology or a new group of people. Build the screening question into your change process, not only into new projects.

What Happens If You Skip It

Failing to carry out a required DPIA is an infringement of Article 35 in its own right, whether or not anything goes wrong. Under Article 83(4) it falls in the tier of fines of up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. Regulators have also treated a missing DPIA as an aggravating factor when something does go wrong.

Frequently Asked Questions

Who decides whether a DPIA is required?

The controller. Where a data protection officer is designated, their advice should be sought, and it is good practice to record it in the screening.

Is a DPIA required for every new system?

No. The short answer to when is a DPIA required is: only where high risk is likely. But every new system that processes personal data should be screened, and the screening recorded.

Does a processor have to carry out the DPIA?

No. The DPIA is the controller’s duty, but Article 28(3)(f) requires processors to assist the controller with it.

How is this different from a privacy risk assessment?

A privacy risk assessment covers all of your processing; a DPIA covers one high-risk operation in depth. Our comparison of privacy risk assessment vs DPIA explains how they fit together. For the method, see our full DPIA guide.

If you are still asking when is a DPIA required for your own project, our free DPIA template starts with exactly this screening, gives you the verdict and records your reasoning, then takes you through the rest of the DPIA if one is needed. For the policies and records around it, see the GDPR Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.