A DPIA is required under Article 35 GDPR before any processing that is likely to result in a high risk to individuals. Getting the trigger assessment right, and the methodology defensible, requires understanding how the EDPB and national supervisory authorities approach evaluation.

When is a DPIA mandatory?

Article 35(3) GDPR identifies three scenarios that always require a DPIA: systematic and extensive profiling with legal or similarly significant effects; large-scale processing of special categories of data or criminal records; and systematic public monitoring on a large scale. These are narrow and will not cover the majority of processing activities.

For everything else, the EDPB guidelines (WP248 rev.01) set out nine criteria. Meeting two or more generally triggers the obligation, though in some cases a single criterion suffices.

What are the nine EDPB criteria for a mandatory DPIA?

The nine criteria are: evaluation or scoring, including profiling; automated decision-making with legal or similarly significant effects; systematic monitoring of individuals; processing of sensitive or highly personal data; large-scale data processing; matching or combining datasets from different sources; processing data of vulnerable individuals; innovative use of technology or novel application of existing technology; and processing that prevents individuals from exercising a right or using a service.

Each criterion reflects a type of processing where the risk of harm to individuals is elevated. The EDPB notes that organisations should apply the criteria in context: a hospital processing patient data at scale will likely meet multiple criteria simultaneously, requiring a DPIA. A sole trader processing client contact details for invoicing purposes will meet none.

The EDPB adopted a DPIA template in April 2026 now under public consultation, intended to become a harmonised reference tool across EU supervisory authorities.

What structure do regulators expect in a DPIA?

A defensible DPIA addresses four elements in sequence. First, a systematic description of the processing, including its purposes, legitimate interests where applicable, and the data and individuals involved. Second, an assessment of necessity and proportionality – whether the processing is genuinely required for the stated purpose and whether less privacy-invasive alternatives were considered. Third, an assessment of risks to the rights and freedoms of individuals. Fourth, the measures proposed to address those risks, including their effectiveness.

Regulators assess DPIAs against the substance of these elements, not their format. A document that lists risks without genuinely assessing their likelihood and severity, or that proposes generic controls without linking them to specific risk findings, will not withstand scrutiny.

What happens when residual risk cannot be mitigated?

Where the measures identified in the DPIA do not reduce residual risk to an acceptable level, Article 36 GDPR requires the controller to consult the supervisory authority before commencing processing. This is known as prior consultation. Supervisory authorities have up to eight weeks to respond, extendable by a further six weeks for complex cases.

Several of the largest GDPR fines issued to date have cited failures to conduct required DPIAs, or DPIAs of insufficient quality, as aggravating factors in enforcement decisions.

What this means for your organisation

  • A DPIA is not optional where the nine EDPB criteria are met. Conducting one as a box-ticking exercise does not satisfy the obligation – supervisory authorities assess quality, not completion.
  • Missing DPIAs have been cited as aggravating factors in some of the largest GDPR fines issued to date. The risk is not theoretical.
  • The EDPB adopted a harmonised DPIA template in April 2026 currently under public consultation. Organisations should monitor this development and align their methodology accordingly.
  • AI systems that process personal data are increasingly likely to trigger DPIA obligations, particularly where they involve profiling, automated decision-making, or novel technology.

What you should do now

  1. Map your processing activities against the nine EDPB criteria and identify where two or more apply.
  2. Check your supervisory authority's mandatory DPIA list for processing operations that trigger the obligation regardless of the nine criteria.
  3. For existing DPIAs, review whether they meet the four-element structure regulators expect – description, necessity, risk assessment, and mitigation measures.
  4. Where residual risk cannot be mitigated to an acceptable level, initiate prior consultation with your supervisory authority before processing commences.
  5. Treat DPIAs as living documents – schedule reviews when processing activities change.

How Priventia helps

Priventia detects processing activities meeting the GDPR high-risk threshold through the Compliance Intelligence Assessment and flags mandatory DPIA triggers across your active regulatory domains. The Controls Library links documented DPIA outputs to the applicable processing activities.