Skip to main content
Praxikon

Direct answer · GDPR

What must a DPIA contain at a minimum?

Short answer

A DPIA contains at least four elements (Article 35(7)): a systematic description of the envisaged processing operations and the purposes, an assessment of necessity and proportionality, an assessment of the risks to the rights and freedoms of data subjects, and the measures envisaged to address those risks. The advice of the data protection officer is sought (Article 35(2)).

Direct answer · GDPR

What a DPIA must contain

A DPIA contains at least (Article 35(7)): a systematic description of the envisaged processing operations and the purposes, including, where applicable, the legitimate interest pursued; an assessment of the necessity and proportionality of the processing in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks, including safeguards and security measures. The advice of the data protection officer is sought (Article 35(2)).

Articles

Guidelines and decisions

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist