Direct answer · GDPR
What a DPIA must contain
A DPIA contains at least (Article 35(7)): a systematic description of the envisaged processing operations and the purposes, including, where applicable, the legitimate interest pursued; an assessment of the necessity and proportionality of the processing in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address those risks, including safeguards and security measures. The advice of the data protection officer is sought (Article 35(2)).
Articles
- Art. 35(7)(a) to (d) GDPR The four mandatory elements.
- Art. 35(2) GDPR Advice of the data protection officer.
Guidelines and decisions
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679 (Article 29 Working Party, WP248 rev.01, 2017-10-04)DPIA guidelines with criteria for an acceptable DPIA (Annex 2).
- EDPB Template for Data Protection Impact Assessment (European Data Protection Board (EDPB), EDPB Template [2026] for DPIA, versie 1.0 met explainer (aangenomen 10 maart 2026 voor publieke consultatie), 2026-04-14)EDPB template for a DPIA (consultation version).
