# Necessity of a data protection impact assessment

When is a DPIA mandatory? Threshold analysis under Article 35 GDPR with examples: the statutory examples in paragraph 3, the nine criteria for assessing the risk, the mandatory list of the German supervisory authorities, case examples, and the exemptions under paragraphs 5 and 10.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.1-erforderlichkeit
> Sprache: en



Before a data protection impact assessment (DPIA) is carried out, the question arises whether it is required at all. It is mandatory only where the processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1) GDPR). This preliminary examination is known as the threshold analysis. It must be conducted at an early stage and documented, including where it concludes that no data protection impact assessment is necessary.

<Callout type="info">
  **Key takeaways**

  * The obligation follows only from reading several paragraphs together: the general rule (paragraph 1), the statutory examples (paragraph 3) and the positive list of the supervisory authority (paragraph 4).
  * It is more efficient to reverse the order of examination: first the lists of the supervisory authorities, then the statutory examples, and only last the burdensome case-by-case assessment under paragraph 1.
  * The Article 29 Working Party lists nine criteria; as a rule, a data protection impact assessment is required where **two** of them are met.
  * The German supervisory authorities have identified 17 typical processing activities for which a data protection impact assessment must always be carried out (mandatory list).
  * Exemptions may follow from a negative list (paragraph 5) or from an impact assessment already carried out by the legislature (paragraph 10).
  * When in doubt, carry one out: the data protection impact assessment is also a useful instrument for complying with the GDPR.
</Callout>

## 1. The threshold analysis [#1-the-threshold-analysis]

### 1.1 Standard: likely to result in a high risk [#11-standard-likely-to-result-in-a-high-risk]

What matters is a forecast. Taking into account the nature, scope, context and purposes of the processing, the processing must be likely to result in a high risk (Article 35(1), first sentence, GDPR). These four attributes must be considered cumulatively; often the high risk emerges only from their interaction, but in individual cases it may follow from a single attribute alone, for instance from the purpose pursued.

What must always be assessed is the risk to the **data subjects**, not the economic or legal risk to the company. Potential fines or damage to the controller's reputation or business are irrelevant at this point. What matters is the possible physical, material or non-material damage to the data subjects, such as discrimination, identity theft, financial loss or loss of control over their own personal data (Recital 75 GDPR).

### 1.2 The four attributes in detail [#12-the-four-attributes-in-detail]

The threshold analysis examines the planned processing against four attributes. Each of them may increase the risk:

* **Nature of the processing.** What does it involve in substance? Profiling, automated decisions, the processing of special categories of data or systematic monitoring all increase the risk. Example: the automated analysis of browsing and purchasing behavior for advertising purposes.
* **Scope of the processing.** How many persons, how much data, over what period and across what territory (see 1.3)? Example: a nationwide customer database with millions of records weighs more heavily than a local customer list.
* **Context of the processing.** Does it take place openly or covertly, can the data subject avoid it, are many bodies involved? Example: background processing that the data subjects cannot recognize weighs more heavily than processing to which they actively agree.
* **Purposes of the processing.** What does it serve? The more intrusive the purpose (evaluating, monitoring or steering persons), the more likely it is that a high risk must be assumed.

### 1.3 What large scale means [#13-what-large-scale-means]

Whether processing is carried out on a large scale is not determined by absolute figures alone. The Article 29 Working Party identifies four factors that must be assessed together ([WP 248 Rev. 01](https://www.datenschutz-bayern.de/technik/orient/wp248.pdf)):

* the **number of data subjects** concerned, either as a specific number or as a proportion of the relevant population,
* the **volume of data** and the range of data types processed,
* the **duration and permanence** of the processing,
* the **geographical extent**.

On this basis, an individual physician processing the data of his or her patients does not act on a large scale, whereas a hospital processing the data of a large number of patients does.

### 1.4 New technologies [#14-new-technologies]

The Regulation singles out the use of **new technologies** (Article 35(1), first sentence, GDPR). A high risk is to be assumed in particular where extensive processing operations involving large amounts of data affect a large number of persons or include particularly sensitive data (Recital 91 GDPR). Typical fields of application include connected vehicles, connected health applications, big data and tracking techniques, artificial intelligence methods, the combination of biometric techniques such as fingerprint and facial recognition, and new surveillance technology.

Irrespective of the technology used, a high risk exists above all where the processing makes it more difficult for data subjects to exercise their rights or prevents them from doing so, for instance in the case of high complexity and lack of transparency, a large number of controllers involved, or covert and suspicionless processing as part of monitoring and security measures (Recital 91 GDPR).

<Callout type="info">
  **Special case: individual physician or lawyer.** Where an individual health professional or an individual lawyer processes the data of his or her patients or clients, that processing is not regarded as large-scale; a data protection impact assessment is then not mandatory ([Recital 91 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-91/)). The privilege applies only to the individual professional, not to larger units such as hospitals or large law firms.
</Callout>

### 1.5 An efficient order of examination [#15-an-efficient-order-of-examination]

Whether a data protection impact assessment must be carried out can be answered only by reading several paragraphs together. Instead of following the numerical order, it is more efficient to examine them in reverse:

<Steps>
  <Step>
    **Check the lists of the supervisory authorities.**

     If the processing appears on the positive list (mandatory list) under Article 35(4) GDPR, a data protection impact assessment is mandatory. If it appears on a negative list under Article 35(5) GDPR, none is required.
  </Step>

  <Step>
    **Check the statutory examples.**

     If one of the three cases set out in Article 35(3) GDPR applies, the obligation exists.
  </Step>

  <Step>
    **Check the general rule.**

     Only where the lists and the statutory examples do not provide an answer does the burdensome case-by-case assessment of the high risk under Article 35(1) GDPR follow, based on the nine criteria (see 3.).
  </Step>
</Steps>

## 2. Statutory examples (paragraph 3) [#2-statutory-examples-paragraph-3]

Article 35(3) GDPR names three cases in which a data protection impact assessment is in particular required. The list is not exhaustive.

### 2.1 Systematic and extensive evaluation (point (a)) [#21-systematic-and-extensive-evaluation-point-a]

This covers a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects or similarly significantly affect the person concerned. Examples:

* credit scoring by banks or credit reference agencies to determine the risk of default,
* risk assessment by insurers to set the level of premiums,
* fully automated pre-selection of applicants in e-recruiting without any intermediate human review.

### 2.2 Large-scale processing of special categories of data (point (b)) [#22-large-scale-processing-of-special-categories-of-data-point-b]

This covers processing on a large scale of special categories of data under Article 9(1) GDPR or of personal data relating to criminal convictions and offenses under Article 10 GDPR. Here the high risk already follows from the nature of the data itself ([see Article 9](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten)). Examples:

* the processing of patient data by a hospital,
* the large-scale processing of data on trade union membership or religious beliefs,
* the operation of a register containing data on criminal convictions.

The decisive factor is the large scale: the processing of sensitive data by an individual professional does not, as a rule, satisfy this statutory example (see 1.4).

### 2.3 Systematic monitoring of publicly accessible areas (point (c)) [#23-systematic-monitoring-of-publicly-accessible-areas-point-c]

This covers systematic monitoring of publicly accessible areas on a large scale, typically by video surveillance. Examples:

* video surveillance of a large shopping center or of a station forecourt,
* comprehensive monitoring of publicly accessible business premises with public footfall.

### 2.4 Positive list of the supervisory authority (paragraph 4) [#24-positive-list-of-the-supervisory-authority-paragraph-4]

The supervisory authorities establish and make public a list of the processing operations for which a data protection impact assessment must be carried out (Article 35(4) GDPR). For the non-public sector, the German supervisory authorities have agreed on a joint mandatory list, which the European Data Protection Board has confirmed ([German Data Protection Conference (DSK), list of processing activities under Article 35(4) GDPR](https://www.lda.bayern.de/media/dsfa_muss_liste_dsk_de.pdf)). For the federal public sector, the German Federal Commissioner for Data Protection and Freedom of Information (BfDI) maintains its own list; an overview of both lists is provided by the [collection of mandatory lists at the BfDI](https://www.bfdi.bund.de/DE/Fachthemen/Inhalte/Technik/Datenschutz-Folgenabschaetzungen.html). For the public sector of the German federal states, individual supervisory authorities maintain further lists of their own.

<Callout type="warn">
  The positive list is **not exhaustive**. It dispenses with the controller's own assessment under paragraph 1 only where the specific processing is expressly listed there. If the operation does not appear on the list, the threshold analysis remains necessary.
</Callout>

## 3. The nine criteria for assessing the risk [#3-the-nine-criteria-for-assessing-the-risk]

Where the examination of the lists and the statutory examples yields no result, the high risk under Article 35(1) GDPR must be forecast on a case-by-case basis. The nine criteria of the Article 29 Working Party, each of which indicates an increased risk, provide guidance ([Article 29 Working Party, Guidelines on Data Protection Impact Assessment, WP 248 Rev. 01](https://www.datenschutz-bayern.de/technik/orient/wp248.pdf)):

| No. | Criterion                                                           | Example                                                                            |
| --- | ------------------------------------------------------------------- | ---------------------------------------------------------------------------------- |
| 1   | Evaluation or scoring (scoring, profiling)                          | credit scoring, insurance risk assessment                                          |
| 2   | Automated decision with legal or similarly significant effect       | automatic rejection of a loan application, fully automated selection of applicants |
| 3   | Systematic monitoring                                               | video surveillance, analysis of internet and email traffic in the workplace        |
| 4   | Confidential or highly personal data                                | health, religious, financial, location and communications data                     |
| 5   | Processing on a large scale                                         | nationwide customer database with a high level of data detail                      |
| 6   | Matching or combining datasets                                      | enrichment of customer data with data from third-party sources                     |
| 7   | Data concerning vulnerable data subjects                            | children, employees, patients, elderly persons                                     |
| 8   | Innovative use of new technologies                                  | IoT, artificial intelligence, connected vehicles                                   |
| 9   | Preventing data subjects from exercising a right or using a service | credit check filter that prevents the conclusion of a contract                     |

Rule of thumb: where **two** of these criteria are met, a data protection impact assessment must generally be carried out. The more criteria that apply, the more likely the obligation is. In case of doubt, the Article 29 Working Party recommends carrying out a data protection impact assessment, because it helps the controller to comply with the requirements of the GDPR (WP 248 Rev. 01).

Thus it is sufficient, for example, to combine evaluation (No. 1) and large scale (No. 5) in a customer loyalty program involving profiling, systematic monitoring (No. 3) and vulnerable employees (No. 7) in the analysis of working behavior, or special categories of data (No. 4) and innovative technology (No. 8) in a health app.

## 4. Examples from the mandatory list of the supervisory authorities [#4-examples-from-the-mandatory-list-of-the-supervisory-authorities]

The following overview summarizes the 17 processing activities of the German mandatory list for the non-public sector. Where the planned processing is equivalent to one of these activities, a data protection impact assessment must always be carried out ([DSK mandatory list](https://www.lda.bayern.de/media/dsfa_muss_liste_dsk_de.pdf)).

| No. | Processing activity                                                                           | Example                                                                  |
| --- | --------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------ |
| 1   | Biometric data for unique identification (in combination with a further criterion)            | fingerprint for access control, payment by fingerprint                   |
| 2   | Genetic data (in combination with a further criterion)                                        | DNA-based early detection in a hospital, ancestry analysis               |
| 3   | Large-scale processing of data subject to social, professional or official secrecy            | insolvency register, large law firm                                      |
| 4   | Large-scale processing of location data                                                       | car sharing and mobility services                                        |
| 5   | Combination of data from various sources as a basis for decisions                             | fraud prevention in an online shop, scoring by credit reference agencies |
| 6   | Mobile optical-electronic capture in public areas, centrally combined                         | environmental sensors in connected vehicles                              |
| 7   | Large-scale collection and publication of rating data                                         | rating portals, debt collection and receivables management               |
| 8   | Large-scale processing of employee behavioral data for performance evaluation                 | data loss prevention with employee profiles, GPS tracking                |
| 9   | Creation of comprehensive personality and relationship profiles                               | dating portals, large social networks                                    |
| 10  | Big data combination to discover previously unknown correlations                              | customer data enriched with creditworthiness and social media data       |
| 11  | AI used to steer interaction with data subjects or to evaluate them                           | AI-supported customer service with sentiment analysis                    |
| 12  | Tracking via sensors or radio signals from mobile devices                                     | offline tracking of customer movements in a department store             |
| 13  | Automated analysis of video or audio recordings to evaluate personality                       | algorithmic sentiment analysis of telephone calls                        |
| 14  | Comprehensive profiles of movement and purchasing behavior                                    | loyalty card with reward points and profiling                            |
| 15  | Anonymization of special categories of data under Article 9 for transmission to third parties | anonymization of sensitive data by a pharmacy data center                |
| 16  | Sensitive data captured via sensors or mobile applications and centrally processed            | telemedicine using sensor data collected from the patient                |
| 17  | Sensitive data from new technologies used to determine physical performance                   | central storage of fitness tracker data                                  |

## 5. Case examples [#5-case-examples]

### 5.1 Credit scoring in an online shop [#51-credit-scoring-in-an-online-shop]

**Facts:** Before displaying the payment option of purchase on account, an online shop checks the customer's risk of default by combining its own data with information from third-party sources into a risk score.

**Assessment:** Several criteria apply: evaluation and scoring (No. 1), combining datasets (No. 6) and a decision with a significant effect on the customer (No. 2). The processing also corresponds to No. 5 of the mandatory list.

**Conclusion:** A data protection impact assessment must be carried out.

### 5.2 Movement profiles of field staff [#52-movement-profiles-of-field-staff]

**Facts:** A company uses GPS to locate the company vehicles of its field staff in order to coordinate assignments, and stores the location data permanently.

**Assessment:** The data subjects are vulnerable employees (No. 7), there is systematic monitoring (No. 3), and the data can be used to evaluate working behavior. The processing corresponds to No. 8 of the mandatory list.

**Conclusion:** A data protection impact assessment must be carried out.

### 5.3 Counterexample: a simple customer file [#53-counterexample-a-simple-customer-file]

**Facts:** A small trade business keeps a customer file containing names, addresses and invoicing data for the purpose of handling orders, without profiling, without sensitive data and without automated decisions.

**Assessment:** At most a single, weakly pronounced attribute applies. Neither a statutory example nor two of the criteria are met; the processing does not appear on the mandatory list.

**Conclusion:** A data protection impact assessment is not required. The result of the threshold analysis must nevertheless be documented (see 8.).

## 6. A single impact assessment for several processing operations [#6-a-single-impact-assessment-for-several-processing-operations]

A single data protection impact assessment may address a set of similar processing operations that present similar high risks (Article 35(1), second sentence, GDPR). This makes clear that one form of processing may comprise several individual operations, and it is sensible for reasons of economy (Recital 92 GDPR). This may be an option, for instance, where several bodies use a common application or platform or where a measure of the same kind is introduced at several sites. The obligation to carry out a data protection impact assessment nevertheless remains with each controller.

## 7. Exemptions from the obligation to carry out an assessment [#7-exemptions-from-the-obligation-to-carry-out-an-assessment]

### 7.1 Negative list of the supervisory authority (paragraph 5) [#71-negative-list-of-the-supervisory-authority-paragraph-5]

The supervisory authorities may in addition establish a list of the processing operations for which no data protection impact assessment is required (Article 35(5) GDPR). Unlike the positive list, the negative list is optional. The German supervisory authorities have not published one to date.

### 7.2 Impact assessment already carried out by the legislature (paragraph 10) [#72-impact-assessment-already-carried-out-by-the-legislature-paragraph-10]

Where the processing has a legal basis under Article 6(1)(c) or (e) GDPR and an impact assessment was already carried out as part of the adoption of that legal basis, the controller's obligation does not apply unless the legislature expressly requires a further data protection impact assessment (Article 35(10) GDPR). Its practical significance is limited, because legislatures have so far hardly ever carried out an impact assessment of their own. Only legal bases adopted after the GDPR became applicable come into consideration.

## 8. Involvement of the data protection officer and documentation [#8-involvement-of-the-data-protection-officer-and-documentation]

Once it is established that a data protection impact assessment must be carried out, the controller seeks the advice of the [data protection officer](/docs/dsgvo-hub/einzelthemen/datenschutzbeauftragter/1.3.8.3-aufgaben), where one has been designated (Article 35(2) GDPR). This involvement is procedurally mandatory, but the advice is not binding. The fact that mere involvement is required also means that the data protection impact assessment cannot be delegated to the data protection officer but remains a matter for the controller. How the roles are allocated within the company is dealt with on the subpage [Internal company organization](/docs/dsgvo-hub/einzelthemen/datenschutz-folgenabschaetzung/1.3.10.3-unternehmensinterne-organisation).

<Callout type="info">
  **Practical tip on documentation.** Record the result of the threshold analysis for every processing activity, even where no data protection impact assessment is required. Otherwise, in the event of an inspection, it cannot be demonstrated that Article 35 GDPR was taken into account before the processing began. The threshold analysis can be linked directly to the [records of processing activities](/docs/dsgvo-hub/einzelthemen/1.3.7-verzeichnis-von-verarbeitungstaetigkeiten).
</Callout>

<Cards>
  <Card title="DSK short paper No. 5" href="https://www.datenschutzkonferenz-online.de/media/kp/dsk_kpnr_5.pdf" description="Interpretation guidance of the German supervisory authorities on the data protection impact assessment." />

  <Card title="WP 248 Rev. 01" href="https://www.datenschutz-bayern.de/technik/orient/wp248.pdf" description="Guidelines on data protection impact assessment setting out the nine criteria." />

  <Card title="DPIA mandatory list (non-public sector)" href="https://www.lda.bayern.de/media/dsfa_muss_liste_dsk_de.pdf" description="Positive list of the German supervisory authorities under Article 35(4) GDPR." />

  <Card title="Mandatory lists at the BfDI" href="https://www.bfdi.bund.de/DE/Fachthemen/Inhalte/Technik/Datenschutz-Folgenabschaetzungen.html" description="Overview of the lists of processing operations under Article 35(4) GDPR." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.