← GDPR · Accountability

Art.35 — Data protection impact assessment

high dpiarisk-assessment

Requirement

Where processing is likely to result in a high risk to the rights and freedoms of natural persons, in particular using new technologies, the controller shall carry out a data protection impact assessment prior to the processing.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
dpiadata protection impact assessmentprivacy impact assessmentpia
Required element 2 — any one of
high riskprior tobefore processingthresholdscreening
Supporting terms — specificity signals
article 35consult dpomitigationnecessityproportionalitytemplateregister of dpias
Contradiction markers

Finding any of these outranks coverage — a policy that admits the gap is worse than silence.

no dpia process

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
CCPA/CPRA Regs (risk assessments) Risk assessments for significant-risk processing dpia risk-assessment
NDPA 2023 s.28 Data privacy impact assessment dpia risk-assessment
SOC 2 CC3.1 Objectives and risk identification risk-assessment
SOC 2 CC3.2 Risk analysis and response risk-assessment
SOC 2 CC3.3 Fraud risk risk-assessment
SOC 2 CC3.4 Assessment of significant change risk-assessment
ISO 27001 A.5.8 Information security in project management risk-assessment
PCI DSS 4.0.1 12.3.1 Targeted risk analyses risk-assessment