Data Protection HubIndividual TopicsData Protection Impact Assessment

Necessity of a data protection impact assessment

When is a DPIA mandatory? Threshold analysis under Article 35 GDPR with examples: the statutory examples in paragraph 3, the nine criteria for assessing the risk, the mandatory list of the German supervisory authorities, case examples, and the exemptions under paragraphs 5 and 10.

Before a data protection impact assessment (DPIA) is carried out, the question arises whether it is required at all. It is mandatory only where the processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1) GDPR). This preliminary examination is known as the threshold analysis. It must be conducted at an early stage and documented, including where it concludes that no data protection impact assessment is necessary.

Key takeaways

  • The obligation follows only from reading several paragraphs together: the general rule (paragraph 1), the statutory examples (paragraph 3) and the positive list of the supervisory authority (paragraph 4).
  • It is more efficient to reverse the order of examination: first the lists of the supervisory authorities, then the statutory examples, and only last the burdensome case-by-case assessment under paragraph 1.
  • The Article 29 Working Party lists nine criteria; as a rule, a data protection impact assessment is required where two of them are met.
  • The German supervisory authorities have identified 17 typical processing activities for which a data protection impact assessment must always be carried out (mandatory list).
  • Exemptions may follow from a negative list (paragraph 5) or from an impact assessment already carried out by the legislature (paragraph 10).
  • When in doubt, carry one out: the data protection impact assessment is also a useful instrument for complying with the GDPR.

1. The threshold analysis

1.1 Standard: likely to result in a high risk

What matters is a forecast. Taking into account the nature, scope, context and purposes of the processing, the processing must be likely to result in a high risk (Article 35(1), first sentence, GDPR). These four attributes must be considered cumulatively; often the high risk emerges only from their interaction, but in individual cases it may follow from a single attribute alone, for instance from the purpose pursued.

What must always be assessed is the risk to the data subjects, not the economic or legal risk to the company. Potential fines or damage to the controller's reputation or business are irrelevant at this point. What matters is the possible physical, material or non-material damage to the data subjects, such as discrimination, identity theft, financial loss or loss of control over their own personal data (Recital 75 GDPR).

1.2 The four attributes in detail

The threshold analysis examines the planned processing against four attributes. Each of them may increase the risk:

  • Nature of the processing. What does it involve in substance? Profiling, automated decisions, the processing of special categories of data or systematic monitoring all increase the risk. Example: the automated analysis of browsing and purchasing behavior for advertising purposes.
  • Scope of the processing. How many persons, how much data, over what period and across what territory (see 1.3)? Example: a nationwide customer database with millions of records weighs more heavily than a local customer list.
  • Context of the processing. Does it take place openly or covertly, can the data subject avoid it, are many bodies involved? Example: background processing that the data subjects cannot recognize weighs more heavily than processing to which they actively agree.
  • Purposes of the processing. What does it serve? The more intrusive the purpose (evaluating, monitoring or steering persons), the more likely it is that a high risk must be assumed.

1.3 What large scale means

Whether processing is carried out on a large scale is not determined by absolute figures alone. The Article 29 Working Party identifies four factors that must be assessed together (WP 248 Rev. 01):

  • the number of data subjects concerned, either as a specific number or as a proportion of the relevant population,
  • the volume of data and the range of data types processed,
  • the duration and permanence of the processing,
  • the geographical extent.

On this basis, an individual physician processing the data of his or her patients does not act on a large scale, whereas a hospital processing the data of a large number of patients does.

1.4 New technologies

The Regulation singles out the use of new technologies (Article 35(1), first sentence, GDPR). A high risk is to be assumed in particular where extensive processing operations involving large amounts of data affect a large number of persons or include particularly sensitive data (Recital 91 GDPR). Typical fields of application include connected vehicles, connected health applications, big data and tracking techniques, artificial intelligence methods, the combination of biometric techniques such as fingerprint and facial recognition, and new surveillance technology.

Irrespective of the technology used, a high risk exists above all where the processing makes it more difficult for data subjects to exercise their rights or prevents them from doing so, for instance in the case of high complexity and lack of transparency, a large number of controllers involved, or covert and suspicionless processing as part of monitoring and security measures (Recital 91 GDPR).

Special case: individual physician or lawyer. Where an individual health professional or an individual lawyer processes the data of his or her patients or clients, that processing is not regarded as large-scale; a data protection impact assessment is then not mandatory (Recital 91 GDPR). The privilege applies only to the individual professional, not to larger units such as hospitals or large law firms.

1.5 An efficient order of examination

Whether a data protection impact assessment must be carried out can be answered only by reading several paragraphs together. Instead of following the numerical order, it is more efficient to examine them in reverse:

Check the lists of the supervisory authorities. If the processing appears on the positive list (mandatory list) under Article 35(4) GDPR, a data protection impact assessment is mandatory. If it appears on a negative list under Article 35(5) GDPR, none is required.
Check the statutory examples. If one of the three cases set out in Article 35(3) GDPR applies, the obligation exists.
Check the general rule. Only where the lists and the statutory examples do not provide an answer does the burdensome case-by-case assessment of the high risk under Article 35(1) GDPR follow, based on the nine criteria (see 3.).

2. Statutory examples (paragraph 3)

Article 35(3) GDPR names three cases in which a data protection impact assessment is in particular required. The list is not exhaustive.

2.1 Systematic and extensive evaluation (point (a))

This covers a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects or similarly significantly affect the person concerned. Examples:

  • credit scoring by banks or credit reference agencies to determine the risk of default,
  • risk assessment by insurers to set the level of premiums,
  • fully automated pre-selection of applicants in e-recruiting without any intermediate human review.

2.2 Large-scale processing of special categories of data (point (b))

This covers processing on a large scale of special categories of data under Article 9(1) GDPR or of personal data relating to criminal convictions and offenses under Article 10 GDPR. Here the high risk already follows from the nature of the data itself (see Article 9). Examples:

  • the processing of patient data by a hospital,
  • the large-scale processing of data on trade union membership or religious beliefs,
  • the operation of a register containing data on criminal convictions.

The decisive factor is the large scale: the processing of sensitive data by an individual professional does not, as a rule, satisfy this statutory example (see 1.4).

2.3 Systematic monitoring of publicly accessible areas (point (c))

This covers systematic monitoring of publicly accessible areas on a large scale, typically by video surveillance. Examples:

  • video surveillance of a large shopping center or of a station forecourt,
  • comprehensive monitoring of publicly accessible business premises with public footfall.

2.4 Positive list of the supervisory authority (paragraph 4)

The supervisory authorities establish and make public a list of the processing operations for which a data protection impact assessment must be carried out (Article 35(4) GDPR). For the non-public sector, the German supervisory authorities have agreed on a joint mandatory list, which the European Data Protection Board has confirmed (German Data Protection Conference (DSK), list of processing activities under Article 35(4) GDPR). For the federal public sector, the German Federal Commissioner for Data Protection and Freedom of Information (BfDI) maintains its own list; an overview of both lists is provided by the collection of mandatory lists at the BfDI. For the public sector of the German federal states, individual supervisory authorities maintain further lists of their own.

The positive list is not exhaustive. It dispenses with the controller's own assessment under paragraph 1 only where the specific processing is expressly listed there. If the operation does not appear on the list, the threshold analysis remains necessary.

3. The nine criteria for assessing the risk

Where the examination of the lists and the statutory examples yields no result, the high risk under Article 35(1) GDPR must be forecast on a case-by-case basis. The nine criteria of the Article 29 Working Party, each of which indicates an increased risk, provide guidance (Article 29 Working Party, Guidelines on Data Protection Impact Assessment, WP 248 Rev. 01):

No.CriterionExample
1Evaluation or scoring (scoring, profiling)credit scoring, insurance risk assessment
2Automated decision with legal or similarly significant effectautomatic rejection of a loan application, fully automated selection of applicants
3Systematic monitoringvideo surveillance, analysis of internet and email traffic in the workplace
4Confidential or highly personal datahealth, religious, financial, location and communications data
5Processing on a large scalenationwide customer database with a high level of data detail
6Matching or combining datasetsenrichment of customer data with data from third-party sources
7Data concerning vulnerable data subjectschildren, employees, patients, elderly persons
8Innovative use of new technologiesIoT, artificial intelligence, connected vehicles
9Preventing data subjects from exercising a right or using a servicecredit check filter that prevents the conclusion of a contract

Rule of thumb: where two of these criteria are met, a data protection impact assessment must generally be carried out. The more criteria that apply, the more likely the obligation is. In case of doubt, the Article 29 Working Party recommends carrying out a data protection impact assessment, because it helps the controller to comply with the requirements of the GDPR (WP 248 Rev. 01).

Thus it is sufficient, for example, to combine evaluation (No. 1) and large scale (No. 5) in a customer loyalty program involving profiling, systematic monitoring (No. 3) and vulnerable employees (No. 7) in the analysis of working behavior, or special categories of data (No. 4) and innovative technology (No. 8) in a health app.

4. Examples from the mandatory list of the supervisory authorities

The following overview summarizes the 17 processing activities of the German mandatory list for the non-public sector. Where the planned processing is equivalent to one of these activities, a data protection impact assessment must always be carried out (DSK mandatory list).

No.Processing activityExample
1Biometric data for unique identification (in combination with a further criterion)fingerprint for access control, payment by fingerprint
2Genetic data (in combination with a further criterion)DNA-based early detection in a hospital, ancestry analysis
3Large-scale processing of data subject to social, professional or official secrecyinsolvency register, large law firm
4Large-scale processing of location datacar sharing and mobility services
5Combination of data from various sources as a basis for decisionsfraud prevention in an online shop, scoring by credit reference agencies
6Mobile optical-electronic capture in public areas, centrally combinedenvironmental sensors in connected vehicles
7Large-scale collection and publication of rating datarating portals, debt collection and receivables management
8Large-scale processing of employee behavioral data for performance evaluationdata loss prevention with employee profiles, GPS tracking
9Creation of comprehensive personality and relationship profilesdating portals, large social networks
10Big data combination to discover previously unknown correlationscustomer data enriched with creditworthiness and social media data
11AI used to steer interaction with data subjects or to evaluate themAI-supported customer service with sentiment analysis
12Tracking via sensors or radio signals from mobile devicesoffline tracking of customer movements in a department store
13Automated analysis of video or audio recordings to evaluate personalityalgorithmic sentiment analysis of telephone calls
14Comprehensive profiles of movement and purchasing behaviorloyalty card with reward points and profiling
15Anonymization of special categories of data under Article 9 for transmission to third partiesanonymization of sensitive data by a pharmacy data center
16Sensitive data captured via sensors or mobile applications and centrally processedtelemedicine using sensor data collected from the patient
17Sensitive data from new technologies used to determine physical performancecentral storage of fitness tracker data

5. Case examples

5.1 Credit scoring in an online shop

Facts: Before displaying the payment option of purchase on account, an online shop checks the customer's risk of default by combining its own data with information from third-party sources into a risk score.

Assessment: Several criteria apply: evaluation and scoring (No. 1), combining datasets (No. 6) and a decision with a significant effect on the customer (No. 2). The processing also corresponds to No. 5 of the mandatory list.

Conclusion: A data protection impact assessment must be carried out.

5.2 Movement profiles of field staff

Facts: A company uses GPS to locate the company vehicles of its field staff in order to coordinate assignments, and stores the location data permanently.

Assessment: The data subjects are vulnerable employees (No. 7), there is systematic monitoring (No. 3), and the data can be used to evaluate working behavior. The processing corresponds to No. 8 of the mandatory list.

Conclusion: A data protection impact assessment must be carried out.

5.3 Counterexample: a simple customer file

Facts: A small trade business keeps a customer file containing names, addresses and invoicing data for the purpose of handling orders, without profiling, without sensitive data and without automated decisions.

Assessment: At most a single, weakly pronounced attribute applies. Neither a statutory example nor two of the criteria are met; the processing does not appear on the mandatory list.

Conclusion: A data protection impact assessment is not required. The result of the threshold analysis must nevertheless be documented (see 8.).

6. A single impact assessment for several processing operations

A single data protection impact assessment may address a set of similar processing operations that present similar high risks (Article 35(1), second sentence, GDPR). This makes clear that one form of processing may comprise several individual operations, and it is sensible for reasons of economy (Recital 92 GDPR). This may be an option, for instance, where several bodies use a common application or platform or where a measure of the same kind is introduced at several sites. The obligation to carry out a data protection impact assessment nevertheless remains with each controller.

7. Exemptions from the obligation to carry out an assessment

7.1 Negative list of the supervisory authority (paragraph 5)

The supervisory authorities may in addition establish a list of the processing operations for which no data protection impact assessment is required (Article 35(5) GDPR). Unlike the positive list, the negative list is optional. The German supervisory authorities have not published one to date.

7.2 Impact assessment already carried out by the legislature (paragraph 10)

Where the processing has a legal basis under Article 6(1)(c) or (e) GDPR and an impact assessment was already carried out as part of the adoption of that legal basis, the controller's obligation does not apply unless the legislature expressly requires a further data protection impact assessment (Article 35(10) GDPR). Its practical significance is limited, because legislatures have so far hardly ever carried out an impact assessment of their own. Only legal bases adopted after the GDPR became applicable come into consideration.

8. Involvement of the data protection officer and documentation

Once it is established that a data protection impact assessment must be carried out, the controller seeks the advice of the data protection officer, where one has been designated (Article 35(2) GDPR). This involvement is procedurally mandatory, but the advice is not binding. The fact that mere involvement is required also means that the data protection impact assessment cannot be delegated to the data protection officer but remains a matter for the controller. How the roles are allocated within the company is dealt with on the subpage Internal company organization.

Practical tip on documentation. Record the result of the threshold analysis for every processing activity, even where no data protection impact assessment is required. Otherwise, in the event of an inspection, it cannot be demonstrated that Article 35 GDPR was taken into account before the processing began. The threshold analysis can be linked directly to the records of processing activities.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn