- CNIL describes the PIA as a continuous improvement process updated when significant change occurs.
"continuous improvement process"
A concrete workflow for deciding whether a DPIA is required, completing the Article 35 assessment, and escalating only when residual high risk triggers Article 36 prior consultation.
Use it for new or materially changed processing that may affect individuals through profiling, large-scale sensitive data, systematic monitoring, vulnerable groups, combined datasets, new technology, or difficult-to-avoid services.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use one operating record for GDPR Articles 35 and 36: screen the processing before launch, complete the , obtain DPO advice where a DPO is designated, choose and verify measures, reassess residual high risk, and prepare prior consultation when the remaining risk cannot be sufficiently mitigated.
Start before the processing begins or before a material change is released. Record the processing operation, controller role, purposes, data categories, affected people, systems, suppliers, recipients, storage periods, and countries involved.
A is required where the nature, scope, context, and purposes of processing, especially when using new technologies, are likely to create high risk for natural persons. Treat the screening as a written decision: either open a DPIA, rely on a single assessment covering a set of similar operations with similar high risks, or document why the threshold is not met. Check the competent supervisory authority's published Article 35(4) list of processing that requires a DPIA and any Article 35(5) list of processing for which a DPIA is not required.
Article 35(10) can remove the Article 35(1)-(7) duty where processing under Article 6(1)(c) or (e) has a legal basis in Union or Member State law, that law regulates the specific processing operation or set of operations, and a general impact assessment was already performed when that legal basis was adopted. The exception does not apply where Member State law requires a DPIA before processing.
Tie the to the processing operation and keep enough detail for an auditor, DPO, or supervisory authority to understand the decision without reconstructing the project history. A generic privacy memo does not supply that project record.
Use the CNIL structure to keep the assessment complete: context, fundamental principles, security risks, and validation. Use the DPC template prompts to capture scope, consultation, necessity and proportionality, risks, mitigation, residual risk, sign-off, and review ownership.
For each identified risk, record the initial likelihood and severity, the specific measure proposed, the owner, the expected effect on risk, and the residual risk after the measure. Do not close the on a list of broad controls without showing which individual risk each measure reduces.
Measures can change the processing design as well as the security layer. If a risk is created by unnecessary data, avoid it by removing the data. If the risk comes from access, retention, supplier handling, user information, or international transfer, the measure should address that exact cause.
Article 36 prior consultation is required when the indicates that the processing would result in high risk without measures that sufficiently mitigate it. Requiring a DPIA does not by itself trigger consultation.
Before consulting, assemble the package Article 36 expects. Keep the workflow jurisdiction-neutral unless a specific supervisory authority and national procedure have been verified from current official sources. The intended processing should remain on hold while consultation is pending because Article 36 requires consultation before processing.
Close the workflow only when the screening decision, contents, measures, residual-risk decision, and consultation assessment are all traceable to the same processing operation. If the product, data, threat environment, provider model, or affected population changes, reopen the screen and decide whether the DPIA needs review.
Keep the evidence concise but durable. The goal is to prove the controller knew the risks, selected measures, considered affected people and DPO advice where required, and escalated when Article 36 required it.
Sorena can help turn your DPIA screening, risk register, mitigation plan, DPO advice, and prior-consultation package into a cited operating record.
Ask questions tied to cited sources about DPIA triggers, Article 35 content, residual high risk, and Article 36 prior consultation.
Review your DPIA workflow, evidence gaps, mitigation plan, and prior-consultation decision with Sorena.
"continuous improvement process"
"define and describe the context of the processing of personal data under consideration"
"Good record keeping during the DPIA process"
"Security of Personal Data Processing"
"Where necessary, the controller shall carry out a review"
"The assessment shall contain at least"
"The controller shall consult"
"likely to result in a high risk"