Skip to main content
Praxikon

Guideline

Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk

Date
Status
final
Body
Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
Reference
WP248 rev.01 (Endorsement 1/2018)

What it is about

These guidelines of the former Article 29 Working Party explain when a DPIA is required. They list nine criteria for high risk, such as scoring, systematic monitoring, sensitive data, large scale and new technology. In most cases processing that meets two criteria requires a DPIA. The EDPB endorsed the text on 25 May 2018 (Endorsement 1/2018); it was adopted on 4 April 2017 and last revised on 4 October 2017.

What this means in practice

You test every new processing operation against the nine criteria. If criteria are met but you do not carry out a DPIA, you justify and document the reasons. A DPIA must contain the minimum content of Article 35(7): description, necessity, risks and measures. If a high residual risk remains you must consult the supervisory authority first (Article 36(1)).

The GDPR articles concerned

Source: EDPB, endorsed WP29 guideline pagechecked on 15 September 2026

Summary and practical reading by Praxikon. Not legal advice; the source prevails.

Connections

What connects to this development

Guidelines

Legislation in motion