DPIA prior consultation is the step most teams forget exists until a risky project is already scheduled for launch. If a data protection impact assessment shows that processing would still carry a high risk to individuals after you have applied every reasonable safeguard, Article 36 of the GDPR requires you to consult your supervisory authority before you start. Missing that step can turn a well-run assessment into a compliance failure.
This guide explains when prior consultation is triggered, when it is not, what to send, how long the authority has to respond and how to build the step into your project plan so it does not derail a launch.
Free gap assessment
Could you demonstrate GDPR compliance today?
Score yourself against what a supervisory authority actually asks for, free — the records, not the policy.
Run the free GDPR gap assessment → or View premium report sample
When DPIA prior consultation is required under Article 36
Article 36(1) sets a narrow trigger. You must consult the supervisory authority when a DPIA under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate it. In practice, the test is about residual risk: after you apply your technical and organizational measures, is the risk to individuals still high?
That distinction matters. A DPIA that finds high risk and then reduces it to an acceptable level through encryption, minimization, access controls, human review or shorter retention does not trigger consultation. A DPIA that finds high risk where no reasonable measure brings it down does. Consultation is therefore a last resort for genuinely difficult processing, not a routine step for every assessment. If you are unsure whether you need the assessment itself, start with our guide on when a DPIA is required.
| Situation after the DPIA | Consult the authority? |
|---|---|
| Risk is low or medium after safeguards | No. Record the outcome and proceed |
| Risk was high but safeguards reduce it to acceptable | No. Document the reasoning and residual rating |
| Risk remains high despite all reasonable safeguards | Yes. Consult before processing starts |
| You cannot agree whether residual risk is high | Escalate to the DPO and senior management, and consider consulting |
What to send in a DPIA prior consultation
Article 36(3) lists the information the controller must give the authority. Prepare it as a single pack so the authority does not have to ask for basics before starting its review.
- Roles and responsibilities. Who is controller, joint controller and processor, particularly where the processing involves a group of undertakings.
- Purposes and means. What the processing is for and how it will work.
- Safeguards. The measures you have put in place to protect individuals’ rights and freedoms.
- DPO contact details. Where you have appointed a data protection officer.
- The DPIA itself. The full completed assessment, not a summary.
- Anything else requested. The authority can ask for more, so be ready to respond quickly.
Write a short cover note that states plainly why you believe residual risk remains high and which specific questions you want advice on. Authorities respond better to a focused request than to a bundle of documents with no explanation. Our DPIA example and DPIA template show the level of detail a strong assessment contains.
The DPIA prior consultation timeline
Under Article 36(2), the authority has up to eight weeks from receipt of the request to give written advice. It can extend that period by a further six weeks, depending on the complexity of the processing, and must tell you about the extension and the reasons within one month of receiving the request. The periods can be suspended while the authority waits for information it has asked you for.
That means a full consultation can take several months, so build it into project planning from the start. Consultation happens before processing begins, so a launch date that assumes no consultation will slip. If your DPIA is likely to end with residual high risk, tell the project sponsor early and plan for the authority’s response window.
You can read the provision itself on the GDPR Article 36 text on gdpr-info.eu. The UK GDPR contains an equivalent provision, so check current ICO guidance if the processing falls under UK law.
A practical rule is to add the full response window to your project schedule whenever the DPIA is still open at the design stage, then remove it if the assessment concludes that safeguards work. It is far cheaper to plan for a consultation you do not need than to explain a missed launch date to the board because you discovered the requirement too late.
A 7-step process for DPIA prior consultation
- Finish the DPIA properly. Consultation depends on a complete assessment of necessity, proportionality and risk.
- Apply every reasonable safeguard. Re-score the risk after each measure.
- Record the residual rating. Show your reasoning if you judge it high.
- Get the DPO’s advice. Article 35(2) requires you to seek it, and record what the DPO said.
- Escalate to senior management. They decide whether to redesign, drop the processing or consult.
- Submit the consultation pack. Send the information listed above with a clear cover note.
- Apply the advice. Update the DPIA, implement changes and keep evidence of what you did.
Consider redesign before you consult
Consultation is not a failure, but it costs time and invites scrutiny, so test whether a redesign removes the problem. Common options include collecting fewer categories of data, pseudonymizing earlier in the pipeline, adding meaningful human review to automated decisions, limiting the group of individuals affected, shortening retention or adding an opt-out. Record each option you considered and why you accepted or rejected it. That record helps both your own decision and the authority’s review.
A hypothetical example
Imagine a health-technology company planning to combine wearable-device readings with clinical records to predict emergency admissions and share risk scores with insurers. The DPIA finds that the processing involves special category data, large-scale profiling and a real prospect of individuals being refused cover on the basis of a prediction they cannot see or challenge. The team tries minimization, pseudonymization, a strict purpose limit and a human review step, but the insurer-facing use still carries a high residual risk that no measure adequately removes. That is a case for DPIA prior consultation, and the team should also ask whether the insurer-facing use is worth keeping at all.
Documenting your decision either way
Whether you consult or not, record the decision. If you do not consult, write down why the residual risk is acceptable, who agreed and when. If you do consult, keep the submission pack, the authority’s questions and responses, and the changes you made afterwards. Regulators and auditors both look for a clear trail that shows the judgment was deliberate. A file note that says only “no consultation needed” with no reasoning is far weaker than a paragraph explaining the residual rating and the safeguards behind it.
What happens after the authority responds
The authority may provide advice, suggest changes or, if it considers the processing would breach the GDPR, use its wider powers. Treat the response as input to your DPIA: update the assessment, implement the recommended measures and record your decisions. If the authority’s view differs from yours, document how you resolved the difference. Keep the whole exchange in your project file, because it forms part of your evidence of accountability if the processing is ever reviewed.
Common mistakes with DPIA prior consultation
- Consulting too early. If safeguards could still reduce the risk, finish them first.
- Consulting too late. Starting the processing before the consultation ends defeats the point.
- Sending a summary instead of the DPIA. The full assessment is required.
- Ignoring the DPO. Their advice should be sought and recorded.
- Underestimating the timeline. Plan for the full response window, plus time to act on the advice.
- Treating a risky rating as a formality. Residual risk needs a reasoned judgment, not a default label.
Prepare a DPIA that stands up to consultation
A consultation is only as strong as the DPIA behind it. The DPIA Report and Workbook gives you a structured report covering screening, the necessity test, risks to individuals, measures and sign-off, with a live workbook you can use for your own processing. For the wider picture, start with our overview of the DPIA process.
DPIA prior consultation FAQ
Is prior consultation required for every DPIA?
No. It applies only when the DPIA shows that processing would still carry a high risk after the measures you can take to mitigate it.
How long does the supervisory authority have to respond?
Up to eight weeks from receipt of the request, extendable by six weeks for complex processing. The periods can be suspended while the authority waits for information from you.
Can we start processing while the consultation is ongoing?
The consultation is meant to happen before processing begins, so plan your launch around it. Starting early undermines the purpose of the step and risks enforcement action.
Who decides whether residual risk is high?
The controller decides, after seeking the DPO’s advice. Record the reasoning, because the authority and any later reviewer will expect to see how you reached the conclusion.
Does the authority approve or reject the processing?
The authority gives written advice and may use its wider powers if it considers the processing would infringe the GDPR. Treat the advice seriously and record how you applied it.