ISMS Copilot
Free tool

GDPR DPIA necessity checker

Answer nine questions about your processing to see whether a Data Protection Impact Assessment is likely required under GDPR Article 35. Based on the EDPB WP248 rev.01 criteria. A structured assessment, not legal advice.

Based on GDPR Article 35 and EDPB guidelines WP248 rev.01.

What a DPIA must contain (Article 35(7))

Where a data protection impact assessment is required, Article 35(7) sets out what it must contain. These are those elements. The checker above walks the Article 35 triggers to indicate whether a DPIA is likely required for your processing.

  • •A systematic description of the processing operations and their purposes.
  • •An assessment of whether the processing is necessary and proportionate to those purposes.
  • •An assessment of the risks to the rights and freedoms of data subjects.
  • •The measures you will take to address those risks: safeguards, security measures, and mechanisms to demonstrate compliance.
  • •Related steps (not part of Article 35(7) itself): seek the advice of your DPO (Article 35(2)), and where a high residual risk remains, consult your supervisory authority before processing (Article 36).

Official sources

Jurisdiction: EU/EEA. Instrument: Regulation (EU) 2016/679 (GDPR), Article 35, read with the WP248 rev.01 DPIA guidelines, as in force on the dates below.

Frequently asked questions

Does this tool produce a binding determination?
No. It applies the EDPB WP248 rev.01 criteria and the Article 35(3) cases to your answers and returns a structured assessment. The decision rests with the controller and its DPO, informed by your supervisory authority's published lists. When in doubt, the EDPB recommends carrying out a DPIA.
What is a DPIA?
A Data Protection Impact Assessment is the prior assessment GDPR Article 35 requires for processing likely to result in a high risk. It describes the processing, assesses necessity and proportionality, evaluates the risks to people, and sets out the measures to address them.
When must the DPIA be done?
Before the processing begins; a DPIA is a prior assessment. For ongoing processing, review it whenever the nature, scope, context, or purposes change.
What are the nine EDPB criteria?
Evaluation or scoring; automated decisions with significant effect; systematic monitoring; sensitive or highly personal data; large-scale processing; matching or combining datasets; vulnerable data subjects; innovative technology; and processing that prevents exercising a right or using a service. Meeting two or more indicates processing likely to result in a high risk.
Do supervisory authority lists override this?
Yes. Under Article 35(4) each authority publishes processing that always requires a DPIA, and may publish (35(5)) processing that does not. Those lists are authoritative for their Member State and should be checked alongside this assessment.
Where can I read the full method behind this checker?
See the long-form guide Do I need a DPIA? at /learn/do-i-need-a-dpia. It walks the same test in prose: the Article 35(1) trigger, the three Article 35(3) presumptive cases, the nine EDPB criteria and the two-or-more rule, the national Article 35(4)/(5) lists, the narrow Article 35(10) exemption, and the Article 36 prior-consultation follow-on. This checker is the interactive form of that method.

By ISMS Copilot. Based on GDPR Article 35 and EDPB guidelines WP248 rev.01.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.