Article 35: Data protection impact assessmentAI-relevant
Praxikon tracks Article 35 (Data protection impact assessment) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 35 govern?
Article 35 requires the controller to carry out a data protection impact assessment (DPIA) before starting a processing operation that is likely to result in a high risk to the rights and freedoms of people, in particular where new technologies are used (paragraph 1). Paragraph 3 names three situations in which such an assessment is always required: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significantly affect the person; large-scale processing of special categories of data (Article 9) or criminal data (Article 10); and systematic large-scale monitoring of publicly accessible areas. Paragraph 7 sets out the minimum content: a description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks, and the measures to address those risks. The article exists because the old general duty to notify the supervisory authority was abolished and replaced by a targeted approach for the genuinely risky processing operations (recital 89). In this way the GDPR forces you to think through and reduce the risks before you start, rather than after something has gone wrong (recital 90).
Key term: Data protection impact assessment (DPIA): an upfront study of the risks a processing operation poses to the people concerned, and of the measures to reduce those risks
Directly affects:controllerprocessordata protection officerdata subjectsupervisory authorityBoardmember state
Praxikon’s reading of the text and the recitals; the official text below prevails.
AI Act intersection
The DPIA is complementary to the AI Act: high-risk classification (Art. 6) often also requires a DPIA, and the FRIA (Art. 27) is the AI-specific equivalent.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
For every new or changed processing operation you assess whether it is likely to result in a high risk, and if so you complete a DPIA with the elements of paragraph 7 before you start. If, for example, you use an AI application that systematically and extensively profiles people and bases decisions on that profile that produce legal or similarly significant effects, you fall under paragraph 3(a). You seek the advice of your data protection officer (paragraph 2), ask data subjects for their views where appropriate (paragraph 9) and review the DPIA as soon as the risk changes (paragraph 11).
Processor
The article places the DPIA with the controller, but recital 95 expects you as processor to assist on request, for example with information on how you process and secure the data. If you adhere to an approved code of conduct under Article 40, that is taken into account in the assessment (paragraph 8).
Data Protection Officer
The controller must seek your advice when carrying out a DPIA (paragraph 2). You check whether the assessment contains the elements of paragraph 7 and whether the chosen measures genuinely address the risks to data subjects.
Data Subject
A DPIA is meant to protect your rights and freedoms before a processing operation starts. Where appropriate, the controller asks you or your representatives for your views on the intended processing (paragraph 9).
Compliance checklist
Related recitals
In order to enhance compliance with this Regulation where processing operations are likely to result in a high risk to the rights and freedoms of natural persons, the controller should be responsible ...
(89)Directive 95/46/EC provided for a general obligation to notify the processing of personal data to the supervisory authorities. While that obligation produces administrative and financial burdens, it d...
(90)In such cases, a data protection impact assessment should be carried out by the controller prior to the processing in order to assess the particular likelihood and severity of the high risk, taking in...
(91)This should in particular apply to large-scale processing operations which aim to process a considerable amount of personal data at regional, national or supranational level and which could affect a l...
(92)There are circumstances under which it may be reasonable and economical for the subject of a data protection impact assessment to be broader than a single project, for example where public authorities...
(93)In the context of the adoption of the Member State law on which the performance of the tasks of the public authority or public body is based and which regulates the specific processing operation or se...
(94)Where a data protection impact assessment indicates that the processing would, in the absence of safeguards, security measures and mechanisms to mitigate the risk, result in a high risk to the rights ...
(95)The processor should assist the controller, where necessary and upon request, in ensuring compliance with the obligations deriving from the carrying out of data protection impact assessments and from ...
Cross-references
Frequently asked questions
Connections
What connects to Article 35 GDPR
Themes where this returns
The counterpart in the other law
Case law
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag
Guidelines8 of 9
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP)
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB)
- Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
2019-11-27 · in force, Autoriteit Persoonsgegevens (AP)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Enforcement and fines
- 150,000 euro fine for ICS for missing DPIA on digital identity checks
2023-12-18 · final, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
Analysis6 of 7
- AI DPIA: when it's required + free template (2026)
2026-03-23
- EU AI Act Article 26: deployer obligations explained
2026-03-21
- DPIA vs FRIA: 5 key differences, when you need both, plus a free FRIA template (2026)
2025-08-05
- AI Act regulator inspection: which documents must your organisation be able to show?
2026-07-07
- What is FRIA? Fundamental rights impact assessment explained (EU AI Act)
2026-02-28
- EU AI Act in the public sector: 2025 government guide
2025-06-16