Guideline
Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is likely to result in a high risk
- Date
- Status
- final
- Body
- Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- Reference
- WP248 rev.01 (Endorsement 1/2018)
What it is about
These guidelines of the former Article 29 Working Party explain when a DPIA is required. They list nine criteria for high risk, such as scoring, systematic monitoring, sensitive data, large scale and new technology. In most cases processing that meets two criteria requires a DPIA. The EDPB endorsed the text on 25 May 2018 (Endorsement 1/2018); it was adopted on 4 April 2017 and last revised on 4 October 2017.
What this means in practice
You test every new processing operation against the nine criteria. If criteria are met but you do not carry out a DPIA, you justify and document the reasons. A DPIA must contain the minimum content of Article 35(7): description, necessity, risks and measures. If a high residual risk remains you must consult the supervisory authority first (Article 36(1)).
The GDPR articles concerned
Source: EDPB, endorsed WP29 guideline pagechecked on 15 September 2026
Summary and practical reading by Praxikon. Not legal advice; the source prevails.
Connections
What connects to this development
Themes where this returns
The counterpart in the other law
Case law
- The Hague District Court cuts DPA fine on police for mobile camera cars without completed DPIA to 30,000 euros
2024-10-08 · status not established, Rechtbank Den Haag
Guidelines
- EDPB Template for Data Protection Impact Assessment
2026-04-14 · under consultation, European Data Protection Board (EDPB)
- Consultation on the draft list of processing operations for which no DPIA is required (Dutch DPA)
2026-06-24 · under consultation, Autoriteit Persoonsgegevens (AP)
- Decision on the list of processing operations for which a DPIA is mandatory (Dutch DPA)
2019-11-27 · in force, Autoriteit Persoonsgegevens (AP)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 02/2025 on processing of personal data through blockchain technologies
2026-07-07 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines on Automated individual decision-making and Profiling for the purposes of Regulation 2016/679
2018-05-25 · final, Article 29 Working Party, bekrachtigd door de European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines
- 150,000 euro fine for ICS for missing DPIA on digital identity checks
2023-12-18 · final, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: EU-wide DPIA lists, template and methodology (Articles 35, 57, 64 and 70 GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Cyprus Presidency tables negotiating mandate, Coreper vote of 26 June 2026 cancelled
2026-06-22 · under negotiation, Raad van de Europese Unie, Antici-groep (vereenvoudiging) en Coreper
- Commission publishes Digital Omnibus proposal COM(2025) 837
2025-11-19 · proposal, Europese Commissie
Analysis6 of 7
- AI DPIA: when it's required + free template (2026)
2026-03-23
- EU AI Act Article 26: deployer obligations explained
2026-03-21
- DPIA vs FRIA: 5 key differences, when you need both, plus a free FRIA template (2026)
2025-08-05
- AI Act regulator inspection: which documents must your organisation be able to show?
2026-07-07
- What is FRIA? Fundamental rights impact assessment explained (EU AI Act)
2026-02-28
- EU AI Act in the public sector: 2025 government guide
2025-06-16