← GDPR · Accountability

Art.36 — Prior consultation with the supervisory authority

medium dpiarisk-assessment

Requirement

Where a data protection impact assessment indicates that processing would result in a high risk in the absence of measures taken by the controller to mitigate it, the controller shall consult the supervisory authority before starting the processing.

What the engine looks for

Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.

Required element 1 — any one of
prior consultationconsult the supervisory authorityconsult the regulatorconsult the icoconsultation with the supervisory authorityconsult the data protection authority
Required element 2 — any one of
dpiadata protection impact assessmenthigh riskresidual riskbefore processingbefore startingcannot be mitigated
Supporting terms — specificity signals
article 36eight weeksresidualdpo

Equivalent controls elsewhere

Matched on shared topics. Satisfying this control usually moves these too.

FrameworkControlTitleShared topics
CCPA/CPRA Regs (risk assessments) Risk assessments for significant-risk processing dpia risk-assessment
NDPA 2023 s.28 Data privacy impact assessment dpia risk-assessment
SOC 2 CC3.1 Objectives and risk identification risk-assessment
SOC 2 CC3.2 Risk analysis and response risk-assessment
SOC 2 CC3.3 Fraud risk risk-assessment
SOC 2 CC3.4 Assessment of significant change risk-assessment
ISO 27001 A.5.8 Information security in project management risk-assessment
PCI DSS 4.0.1 12.3.1 Targeted risk analyses risk-assessment