Data Protection Impact Assessment (Article 35 GDPR)
When a data protection impact assessment is mandatory, how it is carried out step by step, and how a company organizes those involved. An overview of Articles 35 and 36 GDPR, covering the process, the risk assessment, and the allocation of roles.
The data protection impact assessment is the statutorily prescribed procedure by which a controller identifies and assesses, in advance, the risks that a particularly intrusive processing operation poses to the data subjects, and reduces those risks by means of remedial measures (Article 35 GDPR). It gives expression to the risk-based approach of the GDPR and is at the same time an instrument by which the controller ensures and demonstrates compliance with the Regulation.
Key takeaways
- Mandatory only where the processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1) GDPR). Whether such a risk exists is clarified in advance by the threshold analysis.
- It must be carried out before the start of the processing, while the project is still at the planning stage.
- The minimum content comprises four building blocks: the description, the assessment of necessity and proportionality, the assessment of the risks, and the remedial measures (Article 35(7) GDPR).
- Where a high risk remains despite the remedial measures, the supervisory authority must be consulted prior to the processing (Article 36 GDPR).
- Responsibility remains with the controller; the data protection officer merely advises (Article 35(2) GDPR). A failure to carry out the assessment, or carrying it out incorrectly, is subject to administrative fines (Article 83(4)(a) GDPR).
1. What the data protection impact assessment achieves
1.1 Purpose and legal nature
The data protection impact assessment is directed at processing operations that are particularly risky for the rights and freedoms of natural persons. For these, the law requires a forward-looking examination of the possible consequences, followed by the selection and implementation of risk-mitigating remedial measures. It is therefore both an obligation to minimize risk and a procedure for ensuring and demonstrating compliance with the GDPR (Recital 84 GDPR).
The addressee of the obligation is the controller (Article 4(7) GDPR). The obligation cannot be shifted onto the data protection officer: the latter is to be involved and provides advice, but bears no responsibility for the content and the outcome (Article 35(2) GDPR).
1.2 Risk-based approach: not for every processing operation
A data protection impact assessment does not have to be carried out for every processing operation, but only where the processing is likely to result in a high risk (Article 35(1) GDPR). Whether this threshold is reached is clarified by the controller in advance in a documented threshold analysis. The details of when an assessment is required, of the statutory examples, and of the lists maintained by the supervisory authorities are dealt with on the sub-page Necessity.
1.3 Timing: before the start of the processing
The data protection impact assessment must be carried out in advance and therefore before the processing is taken up. Because several units are involved (the business unit, data protection, information security and, where applicable, the employee representative body and the supervisory authority), it must be begun with sufficient lead time while the project is still at the planning stage. It is not a one-off act, but accompanies the project and may require individual steps to be repeated where new remedial measures are determined.
2. The process at a glance
The minimum content laid down in Article 35(7) GDPR can be translated into three phases and a concluding report. In practice, a six-step procedure that operationalizes the statutory building blocks has proven effective.
Steps 1 to 6 are not strictly linear: where excessive risks are identified in step 4, steps 2 to 5 must be run through again once the remedial measures have been determined, this time on the assumption that those measures are implemented. The full process, including the risk assessment, is described on the sub-page Carrying out the assessment.
3. Consequences of an omitted or deficient data protection impact assessment
An infringement exists both where a required data protection impact assessment is not carried out and where it is not carried out properly. Both may be sanctioned by an administrative fine (Article 83(4)(a) GDPR) and may give rise to a claim for damages on the part of the data subject (Article 82 GDPR). Because the documentation of the threshold analysis forms part of the duty of accountability (Article 5(2) GDPR), the outcome must also be recorded where the examination concludes that no assessment is required.
4. Structure of this chapter
Necessity
Threshold analysis, statutory examples, positive and negative lists of the supervisory authorities, exemptions.
Carrying out the assessment
The six steps, risk assessment using a matrix, the report, review, and consultation of the supervisory authority (Article 36).
Internal organization within the company
Roles and responsibilities: business unit, data protection officer, contributing units, data subjects, processors.
Article 35 GDPR
Statutory text on the data protection impact assessment.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Liability of the Data Protection Officer
Liability of the data protection officer: no compensation under Article 82 GDPR, tort liability towards data subjects, internal liability of the internal and the external data protection officer, criminal and administrative fine responsibility, as well as limitation of liability and documentation.
Necessity of a data protection impact assessment
When is a DPIA mandatory? Threshold analysis under Article 35 GDPR with examples: the statutory examples in paragraph 3, the nine criteria for assessing the risk, the mandatory list of the German supervisory authorities, case examples, and the exemptions under paragraphs 5 and 10.