Get Demo
↑

GDPR DPIA (Article 35): When It's Required and a Template

Article 35 requires a Data Protection Impact Assessment when processing is likely to result in a high risk — with a practical template structure.

Published: September 2026 Compliance · GDPR 8–12 min read

A Data Protection Impact Assessment (DPIA) under Article 35 is required where processing is likely to result in a high risk to the rights and freedoms of natural persons. Article 36 covers prior consultation when residual risk remains high.

Related: GDPR hub · Article 25 · DPO.

Triggers (examples): systematic extensive evaluation/profiling with significant effects; large-scale special-category processing; systematic monitoring of publicly accessible areas. Check your supervisory authority’s DPIA list.

When a DPIA Is Required

DPIA Template Sections

  1. Description of processing (nature, scope, context, purposes)
  2. Necessity and proportionality assessment
  3. Risks to data subjects (likelihood × severity)
  4. Measures to address risks (Art 32 TOMs, PbD defaults)
  5. Residual risk and go/no-go
  6. DPO advice (where appointed) and stakeholder consultation
  7. Review date / change triggers

How CyberSilo Helps

Run DPIAs Before High-Risk Go-Lives

Gate AI, biometrics, and large-scale monitoring behind a completed Article 35 assessment.

Frequently Asked Questions

Who must do a DPIA?

The controller. The DPO advises where appointed; processors assist with information.

What if residual risk stays high?

Article 36 may require prior consultation with the supervisory authority before processing.

Is a DPIA a one-time document?

No. Revisit when the processing changes materially or risks shift.

GDPR hub · Privacy by design · GDPR & AI Act · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!