Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DPIA consultation with DPO data subjects and processors

DPIA Consultation: DPO Advice and Data Subject Views 2026

DPIA consultation is the part of a data protection impact assessment that turns a desk exercise into a genuine check. Article 35 of the GDPR does more than ask a controller to describe risks; it requires the controller to seek the advice of the data protection officer where one is designated, and, where appropriate, to seek the views of the people affected or their representatives. Assessments that skip this stage tend to reflect the project team’s assumptions and miss what people affected by the processing would tell them.

This guide explains who to consult in a DPIA, what the GDPR says about each group, how to carry out the consultation and how to record it.

What the GDPR says about DPIA consultation

Article 35(2) requires the controller to seek the advice of the data protection officer, where designated, when carrying out a DPIA. Article 35(9) provides that, where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations. Article 28(3)(f) requires processors to assist the controller in ensuring compliance with the obligations under Articles 32 to 36, which includes helping with DPIAs. You can read the text of Article 35 on the GDPR text site.

Separately, Article 36 requires consultation with the supervisory authority before processing where the DPIA shows high residual risk. That is a different step; see our guide to DPIA prior consultation. This article covers the earlier internal and stakeholder consultation.

Who to consult in a DPIA consultation

PartyBasisWhat they add
Data protection officerArticle 35(2), mandatory where designatedIndependent advice on necessity, risk, measures and whether to proceed
Data subjects or representativesArticle 35(9), where appropriateHow the processing will be experienced; concerns not seen internally
Processors and suppliersArticle 28(3)(f)Technical details, security measures, sub-processors
Information securityGood practiceThreats, controls and residual technical risk
Business owner and project teamGood practicePurposes, alternatives and feasibility
Legal and complianceGood practiceLawful basis, sector rules and international transfers

Seeking the DPO’s advice

The DPO’s role in a DPIA is to advise and to monitor its performance, not to carry it out or to accept the risk. The guidelines of the Article 29 Working Party on DPOs, endorsed by the EDPB, state that the controller should seek the DPO’s advice on matters such as whether to carry out a DPIA, which methodology to use, whether to carry it out in-house or outsource it, what safeguards to apply, and whether the assessment has been correctly done and its conclusions comply with the GDPR. Those topics make a useful agenda.

Give the DPO the draft early enough to change the outcome, not on the day before launch. Record the advice, and where you decide not to follow it, record the reasons. Documenting that reasoning is the position the guidelines recommend. The DPO should be able to report to the highest level of management if disagreement persists.

Asking data subjects for their views

The phrase “where appropriate” gives some discretion, but it does not mean the duty can be ignored. Consultation is most appropriate where the processing is novel, intrusive or affects large or vulnerable groups. It may be less practical where the processing is routine, low risk or the people cannot easily be identified. If you decide not to consult, record why. Reasons such as commercial confidentiality or security of operations are recognised in the article itself, but should be specific, not a blanket excuse.

Methods for consulting data subjects

  • Surveys. Quick and scalable; test understanding and comfort with the proposed use.
  • Interviews and focus groups. Provide depth and uncover concerns that surveys miss.
  • Representatives. Works councils, trade unions, customer panels and consumer or patient groups can speak for many people.
  • Prototype testing. Show a real version of the notice and consent screens and watch how people react.
  • Pilot with feedback. A limited rollout with a clear way to raise concerns.

Explain what you plan to do in plain language, ask open questions, and be clear about how the answers will be used. Make sure that consulting does not itself create risk, for instance by disclosing confidential plans or collecting more personal data than is needed.

Involving processors and suppliers

Processors often hold the technical facts you need: where data is stored, who has access, how it is encrypted, what sub-processors exist and what logging is in place. Ask them for information in writing, and check that their contract requires assistance with the DPIA. Where they are unable or unwilling to give details, record that as a risk. Our guide to third-party risk assessment explains how to test supplier claims.

Free DPIA template and tool

Does this processing need a DPIA, and what would it say?

Screen the processing against Article 35 and the nine WP248 criteria, describe it, test necessity and proportionality, rate the risks to the people concerned and record the DPO's advice and sign-off. Free, with findings and the Article 36 check.

Start the free DPIA →  or  View premium report sample

Internal experts and the project team

Security specialists can identify threats and evaluate controls, legal staff can confirm the lawful basis and transfer position, and the business owner can explain purposes and alternatives. A short workshop with these people brings out assumptions and disagreements early. Use it to challenge each risk rating and measure, and to agree owners and dates. The value of the exercise depends on candour, so include people who will question the plan.

Timing the consultation

Consultation works best at two points. Early, when the purposes and design options are still open, views can change what is built. Later, on a draft of the assessment, views test whether the risks and measures are right. Plan both in the project timeline, and set aside time for responses. A DPIA that is sent for advice on the last day before launch cannot be changed without delay, and reviewers will feel pressed to approve. Our overview of the DPIA process and the guide on when a DPIA is required help you decide when the process starts.

Keep the consultation proportionate. A small, low-risk change may only need a short exchange with the DPO and security, while a large public-facing system may need weeks of engagement with representatives.

Recording the DPIA consultation

For each consultation, record who was asked, when and how, what they said, what you did in response and what you decided not to do and why. Keep it in the DPIA file as a short table. Where you consult individuals, take care with confidentiality and keep only the information you need. A clear record shows that the assessment was tested against other views and gives an auditor or regulator confidence that the process was real.

Link the consultation record to the risk and measures sections, so a reader can see which concerns led to which changes. Our DPIA residual risk guide shows how measures are turned into a final rating.

A hypothetical example of a DPIA consultation

The following is a hypothetical example invented for illustration. A university plans to use attendance data and library logins to flag students who may be at risk of dropping out. The project team drafts the DPIA and sends it to the DPO, who advises that the purpose is legitimate but that the plan to share flags with lecturers is disproportionate and that students should be told clearly. The team also runs two focus groups with students and consults the students’ union.

Students say they would accept support offers from a named advisor but not automated alerts to their teachers, and they worry about being labelled. The university revises the plan: flags go only to trained student support staff, students can opt out of proactive contact, the data used is reduced and a plain-language notice is written with student input. The DPIA records the DPO’s advice, the consultations and the changes, and the residual risk falls to medium.

Common mistakes in a DPIA consultation

Frequent problems include consulting the DPO after decisions are made, treating the DPO as the author or the risk owner, ignoring the advice without a written reason, skipping data subjects with no explanation, asking only friendly groups, failing to involve processors, not recording feedback and not acting on it, and consulting too late for the answers to change the design. Another is consulting the regulator when the real gap is a lack of internal challenge.

Templates for a DPIA consultation

A structured report makes it easy to show each consultation and its result. The DPIA Report and Workbook provides a report and workbook for describing the processing, recording consultation, assessing risks and documenting measures. Whichever tool you use, use the same headings for each DPIA so that consultation is captured in a consistent place.

DPIA consultation FAQ

Is DPIA consultation with the DPO mandatory?

Yes, where a DPO has been designated. Article 35(2) requires the controller to seek the DPO’s advice, and the advice and the decision taken should be recorded.

Must we ask data subjects for their views?

Article 35(9) requires it where appropriate. If you decide it is not appropriate, document the reasons, such as impracticality or the protection of security or commercial interests.

Can the DPO carry out the DPIA?

The controller is responsible for the DPIA. The DPO advises and monitors. Having the DPO complete it and also assess it would compromise independence.

What if we disagree with the DPO’s advice?

Record the advice and your reasons for not following it. Guidance recommends documenting the reasoning, and the DPO can raise the matter with senior management.

How is this different from prior consultation?

Prior consultation under Article 36 involves the supervisory authority when high residual risk remains. The consultation described here happens during the assessment, with the DPO, data subjects and others.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.