WP29 WP248 rev.01 (endorsed by EDPB)
Guidelines on Data Protection Impact Assessment (DPIA) and determining whether processing is "likely to result in a high risk" for the purposes of Regulation 2016/679 (WP248 rev.01)
What it covers
This WP29 guidance, endorsed by the EDPB, clarifies the scope of Article 35 GDPR, explaining when a data protection impact assessment is mandatory, who is responsible for carrying it out, and the criteria and methodology for conducting one. It also addresses when the supervisory authority must be consulted under Article 36.
Why it matters
It remains the foundational reference for determining when a DPIA is legally required and how to structure one, underpinning national supervisory authority lists of processing operations requiring a DPIA.
Refer to it when
- determining whether a processing operation triggers a mandatory DPIA
- structuring a DPIA methodology
- deciding whether to consult a supervisory authority on residual risk
- assessing DPIA obligations for existing processing operations
Questions this document addresses
- When is a DPIA mandatory under Article 35?
- Who is responsible for carrying out a DPIA?
- What criteria determine an acceptable DPIA methodology?
- When must the supervisory authority be consulted following a DPIA?
Topics
- DPIA & high-risk processing
- Security of processing
- Supervisory authorities
The reference guidance on when a DPIA is mandatory, the nine high-risk criteria, the methodology for carrying out an assessment, and when prior consultation with the supervisory authority is required.
Mapped GDPR Articles
Reproduced from official EDPB publications for reference. Not legal advice.