DPIA screening: is a DPIA required?
Tick what applies to a planned processing activity and get a screening result based on the nine criteria in the WP29 DPIA guidelines endorsed by the EDPB and the cases in Article 35(3) GDPR. Pick your country to open the supervisory authority's Article 35(4) list, then copy a short summary into your records.
Runs entirely in your browser. Nothing you type or tick is stored or sent anywhere.
Copied to the clipboard.
Next step: a DPIA needs the vendor's facts. Run a full vendor review in Validemic and get a draft DPIA from the vendor's documents.
Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace
When a DPIA is required
Article 35(1) GDPR requires the controller to carry out a data protection impact assessment before processing that is "likely to result in a high risk to the rights and freedoms of natural persons", in particular when new technologies are used. The controller must seek the advice of its data protection officer when doing so (Article 35(2)). A DPIA is always required in the three cases in Article 35(3):
- systematic and extensive evaluation of personal aspects, based on automated processing including profiling, on which decisions with legal or similarly significant effects are based;
- large-scale processing of special categories of data or of data on criminal convictions and offences;
- systematic monitoring of a publicly accessible area on a large scale.
Each supervisory authority must also publish a list of processing types that require a DPIA (Article 35(4)), and may publish a list of types that do not (Article 35(5)).
The nine criteria and the two-criteria rule
The Article 29 Working Party's DPIA guidelines, WP248 rev.01 (adopted 4 April 2017, last revised 4 October 2017), set out nine criteria for spotting high-risk processing. The EDPB endorsed them at its first plenary meeting, and national lists such as IMY's build on them. The guidelines say that in most cases a controller can consider that processing meeting two criteria requires a DPIA, that more criteria make a DPIA more likely, and that a single criterion can be enough in some cases.
They also say that if processing meets the criteria but the controller still considers it not likely to result in a high risk, the controller should justify and document the reasons for not carrying out a DPIA and record the DPO's views. The copyable summary above is designed for that record.
Applying the criteria in a university
Validemic's analysis
Three criteria come up in almost every higher education screening. Student data is usually large-scale (criterion 5) because one platform covers every student in a programme or the whole institution. Students are often treated as vulnerable (criterion 7) because they depend on the institution for grades and degrees, which is the kind of imbalance the guidelines describe. And AI-based tools usually count as innovative technology (criterion 8). That means a new AI tool used across a student population will often meet two or three criteria before anyone looks at what it actually does with the data.
National Article 35(4) lists
Check the list of the supervisory authority that is competent for your institution. The lists add to Article 35(3) and are not exhaustive.
| Country | Authority and list | Notes |
|---|---|---|
| Sweden | IMY: När ska en konsekvensbedömning genomföras? (links the förteckning under Article 35.4) | Uses the nine criteria; as a main rule two criteria trigger a DPIA |
| Finland | Tietosuojavaltuutetun toimisto: Luettelo vaikutustenarviointia edellyttävistä käsittelytoimista | Linked from the authority's page on DPIAs (vaikutustenarviointi) |
| Norway | Datatilsynet's list (English version in the EDPB register) | Datatilsynet's own site also publishes the list in Norwegian |
| Denmark | Datatilsynet: Konsekvensanalyse (links the list of processing that always requires a konsekvensanalyse) | Datatilsynet notes the list is not exhaustive |
| Netherlands | Autoriteit Persoonsgegevens: DPIA (links the DPIA-lijst) | The AP notes its list is not exhaustive |
| Ireland | DPC: List of Types of Data Processing Operations which require a DPIA | Covers national and cross-border processing |
| Belgium | APD/GBA: Decision no. 01/2019 of 16 January 2019 | Linked from the authority's DPIA page |
| Germany | DSK: DSFA Muss-Liste, version 1.1 | The DSK labels it the list for the non-public sector; public universities should also check their state authority |
| France | CNIL: liste des traitements pour lesquels une AIPD est requise | Fourteen types of processing, with examples |
DPIAs and AI systems
If the processing involves a high-risk AI system under the EU AI Act, Article 26(9) of that Act requires deployers to use the information the provider gives under Article 13 when carrying out their DPIA. Public universities deploying high-risk systems also face a fundamental rights impact assessment under Article 27, which can cross-refer to the DPIA. Our AI Act checker for education shows whether that applies.
After the screening
- If a DPIA is required, start it before the processing begins. Article 35(7) sets the minimum content: a description of the processing, an assessment of necessity and proportionality, an assessment of the risks, and the measures to address them.
- If the DPIA indicates that the processing would result in a high risk in the absence of measures you take to mitigate it, consult the supervisory authority before processing (Article 36(1)).
- If no DPIA is needed, keep the screening summary with the record of processing activities and revisit it when the processing or the vendor changes.
Sources
All sources retrieved 7 October 2026.
- Regulation (EU) 2016/679 (GDPR), Articles 35 and 36, EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Article 29 Working Party, Guidelines on Data Protection Impact Assessment (DPIA), WP248 rev.01: ec.europa.eu/newsroom/article29/items/611236
- EDPB, Endorsed WP29 guidelines: edpb.europa.eu/endorsed-wp29-guidelines_en
- EDPB, Register of DPIA lists of processing activities: edpb.europa.eu, DPIA lists register
- National lists: IMY, Tietosuojavaltuutetun toimisto, Datatilsynet (Norway, via the EDPB register), Datatilsynet (Denmark), Autoriteit Persoonsgegevens, Data Protection Commission, APD/GBA, Datenschutzkonferenz and CNIL, as linked in the table above.
- Regulation (EU) 2024/1689 (AI Act), Articles 26 and 27, as amended by Regulation (EU) 2026/1744: eur-lex.europa.eu/eli/reg/2024/1689/oj/eng and eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
About this tool
We built this screening from the GDPR text, the WP248 rev.01 guidelines and the national lists linked above, all read on 7 October 2026. A screening is a first step, not a DPIA, and the result depends on how you describe the processing. It is not legal advice; the controller and its DPO remain responsible for the assessment. Authorities update their lists from time to time. If a link has moved or you spot an error, please contact us and we will correct it.
Frequently asked questions
When is a DPIA required under the GDPR?
Article 35(1) requires a DPIA before processing that is likely to result in a high risk to people's rights and freedoms. Article 35(3) names three cases where it is always required, and each supervisory authority publishes a list of further processing types under Article 35(4).
What are the nine DPIA criteria?
The WP29 guidelines (WP248 rev.01, endorsed by the EDPB) list: evaluation or scoring; automated decisions with legal or similar effect; systematic monitoring; sensitive or highly personal data; large-scale processing; matching or combining datasets; vulnerable data subjects; innovative use of technology; and processing that prevents people from exercising a right or using a service.
How many criteria trigger a DPIA?
The guidelines say that in most cases processing meeting two criteria requires a DPIA, and that the more criteria are met, the more likely a DPIA is needed. In some cases a single criterion can be enough.
Do I need to document a decision not to do a DPIA?
Yes, in practice. The guidelines say that where processing meets the criteria but the controller considers it is not likely to result in a high risk, the controller should justify and document the reasons and record the views of the DPO.
Are students vulnerable data subjects?
The guidelines describe vulnerable data subjects as cases where there is an imbalance of power between the person and the controller, naming children and employees as examples. Students who depend on the university for grades and degrees are often treated the same way, so many DPOs tick this criterion for student data.