Skip to content

Data Protection Impact Assessment (DPIA): Mandatory for High Risk

Provimedia 4 min read 11 July 2026 2 views
Unternehmerpflichten
Data Protection Impact Assessment (DPIA): Mandatory for High Risk
Illustrative image · AI-generated

Some data processing activities carry a particularly high risk to the rights and freedoms of the individuals concerned, for example scoring procedures, extensive processing of health data, or systematic video surveillance. In such cases, a simple record of processing activities is no longer enough.

In brief: a Data Protection Impact Assessment (DPIA) is a documented risk analysis that companies must carry out under Art. 35 GDPR before starting processing that is likely to be high risk, for example scoring, extensive health data processing, or video surveillance. This applies to every controller whose procedures appear on the supervisory authorities' mandatory lists. If the DPIA is skipped, fines of up to 10 million euros or 2% of worldwide annual turnover are at risk.

Who Must Carry Out a DPIA?

Every controller under data protection law who plans processing that is likely to pose a high risk to the rights of the individuals concerned is obligated to act. The obligation is not tied to company size but to the type of processing: mid-sized businesses, too, are increasingly using scoring models for creditworthiness or risk assessment, extensive processing of health data (for example in HR or at healthcare providers), or video surveillance systems in branches and business premises, and in doing so automatically trigger the assessment obligation. What always matters is the prior assessment, not a review after the fact, because under Art. 35 GDPR the DPIA must be completed before the actual processing begins. Anyone who misses this point in time can no longer cure the obligation retroactively in a legally secure way. A tool like Company Audit shows you exactly which of these obligations apply to your company.

Which Types of Processing Count as High Risk?

Art. 35 GDPR names three example case groups. First, scoring procedures in which people are systematically classified based on automated evaluations, for example for assessing creditworthiness or behavior. Second, the extensive processing of special categories of personal data such as health data, where a large number of individuals or a large volume of data is affected. Third, systematic video surveillance of publicly accessible areas, for example on business premises or in shop spaces. Since this list is not exhaustive, the supervisory authorities publish supplementary lists of processing activities that require a DPIA. These mandatory lists should be used as an initial point of reference before carrying out your own risk assessment tailored to the specific processing.

How Does a DPIA Work?

The DPIA follows a systematic review scheme and builds directly on the record of processing activities, which should therefore be kept complete and up to date before the impact assessment begins. Only on this basis can the purposes, scope, and risks of a processing activity be described and assessed properly. The process includes the following steps:

  1. Check whether a processing activity is likely to pose a high risk (cross-check the supervisory authority's mandatory list).
  2. Systematically describe the processing operation, its purposes, and its necessity.
  3. Assess the risks to the individuals concerned and define mitigation measures (technical and organizational measures).
  4. Document the result and involve the data protection officer where applicable.
  5. If a high residual risk remains, consult the supervisory authority beforehand.

Written documentation is not an end in itself: it serves as evidence to the supervisory authority that the risk assessment took place before processing began, and it creates the basis on which the data protection officer can give an opinion.

What Are the Consequences Without a DPIA?

If a required Data Protection Impact Assessment is not carried out, or if the high-risk processing begins before the DPIA is completed, this constitutes a violation of Art. 35 GDPR. Supervisory authorities can impose fines of up to 10 million euros or 2% of worldwide annual turnover for this. Because the obligation explicitly applies before processing begins, this risk can only be avoided through an upfront, documented review; retroactive correction is not provided for. For companies, the DPIA therefore pays off twice over: it fulfills the statutory obligation and, at the same time, creates clarity about the actual risks of their own processing.

Frequently Asked Questions

What Is a Data Protection Impact Assessment?

The DPIA is a documented assessment, required under Art. 35 GDPR, of the risks that planned processing poses to the rights and freedoms of the individuals concerned, including the mitigation measures planned for it. It must be completed in writing before the processing actually begins.

When Must a DPIA Be Prepared?

Whenever processing is likely to pose a high risk, for example with scoring, extensive processing of health data, or video surveillance, and always before the processing actually begins.

How Do I Find Out Whether My Processing Requires a DPIA?

The supervisory authorities publish lists of processing activities that require a DPIA. These mandatory lists serve as an initial point of reference before carrying out your own risk assessment tailored to the specific processing.

Must the Data Protection Officer Be Involved?

The outcome of the DPIA must be documented, and the data protection officer should be involved if a data protection officer has been appointed at the company. Their professional assessment feeds into the evaluation of the risks and the planned mitigation measures.

What Happens If a High Residual Risk Remains?

If a high risk to the individuals concerned remains after mitigation measures have been defined, the competent supervisory authority must be consulted before processing begins.

Source: Art. 35 GDPR. This article is general information and does not replace legal advice for individual cases. As of: July 2026.

Share this article

Stay up to date

Get the latest articles, insights and industry updates straight to your inbox.

Unsubscribe at any time. See our privacy policy.

Decide for yourself what Google shows you

Google lets you choose which sources appear more prominently in your search results: in Top Stories and in AI answers. Two clicks, and you see the sites you trust.

Add provimedia.de to my preferred sources

Ihre Unternehmer­pflichten im Griff

Company Audit erstellt Ihnen in wenigen Minuten eine individuelle Pflichtenliste – mit Fristen-Kalender, Erinnerungen und KI-Assistent. Für Selbständige und KMU.