HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 28.07.2026 10:32 CET 51 dossiers MITRE ATT&CK mapping

Editorial explainer · official sources (GDPR, EDPB, Garante)medium

The DPIA explained: when the impact assessment is mandatory, and what it must contain

The data protection impact assessment — the DPIA — is one of the GDPR's most cited obligations and among the most misunderstood. It lives in Article 35: it must be done before processing that is likely to result in a high risk to people's rights and freedoms, in particular with new technologies. It is not a form to fill in after the fact, but a preventive risk analysis, with precise contents and a direct link to the security of processing. An explainer on when it is mandatory under the EDPB and Garante guidance, what it must contain, and why it is a security tool before it is a formality.

It isn't a form, it's a risk analysis done beforehand

The data protection impact assessment — DPIA for short — is perhaps the GDPR obligation most often reduced to a sheet to be filed. It is the opposite. Article 35 of Regulation (EU) 2016/679 describes it as an analysis the controller must carry out before starting processing that is likely to result in a high risk to the rights and freedoms of natural persons, in particular when new technologies are used. The key word is "before": the DPIA exists to see the risk while you can still avoid it, not to certify it afterwards.

When it is mandatory

Not every processing operation requires a DPIA. The GDPR names three cases where it is required in any event, listed in Article 35(3).

  1. 01
    Systematic evaluation based on automated decisions
    with profiling and legal or similarly significant effects on people
  2. 02
    Large-scale processing of special categories
    health, biometric, criminal data
  3. 03
    Systematic monitoring on a large scale
    of a publicly accessible area

To these the authorities' interpretive work is added. The EDPB guidelines — the former Article 29 Working Party, document WP248 rev.01 — identify nine criteria that signal a high risk: from evaluation or scoring to the processing of sensitive data, from large-scale data to the matching of data sets, up to vulnerable subjects and innovative uses. The EDPB's practical rule: if a processing operation meets at least two of these criteria, a DPIA is generally required. In Italy, the Garante has also published a list of the types of processing that require an impact assessment: a concrete reference point for working out which side of the line you are on.

What it must contain

Article 35(7) does not leave the DPIA to improvisation: it fixes its minimum content. It needs a systematic description of the envisaged processing and its purposes; an assessment of necessity and proportionality in relation to those purposes; an assessment of the risks to people's rights and freedoms; and the measures envisaged to address those risks, including safeguards and security mechanisms. Along the way the controller consults the data protection officer (DPO), where one is appointed.

35
the GDPR article
where the DPIA obligation lives
2
the EDPB criteria
beyond which, as a rule, a DPIA is needed
36
the next article
prior consultation if the risk remains high

There is then a step many forget: if, despite the measures envisaged, the residual risk remains high, the controller cannot proceed alone. Article 36 requires in that case prior consultation of the supervisory authority — in Italy, the Garante — before starting the processing. The DPIA is therefore not a closed-doors exercise: when the risk is too high to be managed internally, it opens a dialogue with the regulator.

Why it is a security tool

The reason the DPIA also concerns those who work in security, and not only lawyers, is in its link to Article 32 of the GDPR — the security of processing. The impact assessment is the moment when the risks to people and the technical and organisational measures to contain them formally meet. This is where privacy by design stops being a slogan and becomes a documented choice: encryption, minimisation, access control, pseudonymisation enter the DPIA as answers to specific risks, not as generic good intentions.

Seen this way, the DPIA is not the cost of compliance but its most useful tool: it forces you to ask, before collecting a piece of data, whether it is really needed, who will be able to touch it, what happens if it ends up in the wrong place. This is an explainer, not the attack of the day; but it is the procedure that turns data protection from a formality into a conscious decision. The references that matter — the text of Article 35, the EDPB guidelines, the Garante's page and list — are verifiable at the official sources at the top of the page.

More dossiers