When is a DPIA required?
Article 35 states that a is in particular required for systematic and extensive automated evaluation on which legal or similarly significant decisions are based; large-scale processing of special-category or criminal-conviction and offence data; and systematic monitoring of a publicly accessible area on a large scale.
Also check the ICO's Article 35(4) list and high-risk indicators. Relevant indicators include evaluation or scoring, significant automated decisions, systematic monitoring, sensitive or highly personal data, large scale, combining datasets, vulnerable people, innovative technology, and preventing access to a right, service, or contract. Two indicators often point to a , but that is not a strict threshold; one may be enough.
- Screen every new or materially changed processing activity before launch.
- Assess nature, scope, context, purposes, people affected, data, technology, scale, duration, and likely harm.
- Document a decision not to conduct a when high-risk indicators exist but the controller concludes likely is absent.
- Use one for similar operations only when their risks and controls are genuinely similar.
Binding trigger, listed cases, required assessment content, DPO advice, consultation with people where appropriate, and review duty.
Explains likely high risk, the Article 35 cases, the ICO list, nine indicators, and documented screening decisions.