Skip to main content
Praxikon

Direct answer · GDPR

Must the organisation consult the supervisory authority if the DPIA shows a high residual risk?

Short answer

Yes. Where the DPIA indicates that the processing would result in a high risk without measures to mitigate it, the organisation consults the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens, before the processing starts (Article 36(1)). The supervisory authority provides written advice within eight weeks; that period may be extended by six weeks (Article 36(2)).

Direct answer · GDPR

Prior consultation after a DPIA

Yes. Where the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the organisation to mitigate the risk, it consults the supervisory authority, in the Netherlands the Autoriteit Persoonsgegevens, before the processing starts (prior consultation, Article 36(1)). The supervisory authority provides written advice within eight weeks; that period may be extended by six weeks (Article 36(2)).

For you to establish

  • Which measures have already been taken, and what risk remains after them?

Articles

  • Art. 36(1) GDPR Consultation before processing where a high risk has not been mitigated.
  • Art. 36(2) GDPR Advice within eight weeks, extendable by six weeks.

Guidelines and decisions

Read the article Check your own case General interpretation, not legal advice. The official source remains authoritative.

Check your own situation

Describe your system or project in the free case check and get a reasoned first assessment of, among other things, the DPIA obligation, Article 22 GDPR and the AI Act, with the source for every conclusion.

Go to the free case check
Zahed Ashkara, jurist and freelance AI & Privacy Consultant

Behind this page

Zahed Ashkara

Freelance AI & Privacy Consultant, jurist