Free tool

DPIA screening: is a DPIA required?

Tick what applies to a planned processing activity and get a screening result based on the nine criteria in the WP29 DPIA guidelines endorsed by the EDPB and the cases in Article 35(3) GDPR. Pick your country to open the supervisory authority's Article 35(4) list, then copy a short summary into your records.

Published 7 October 2026 · Sources checked 7 October 2026

For example "Online proctoring for written exams" or "AI transcription of research interviews". It only appears in your summary.

Opens that authority's Article 35(4) list of processing that always needs a DPIA.

Each of these makes a DPIA mandatory on its own.

Runs entirely in your browser. Nothing you type or tick is stored or sent anywhere.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

When a DPIA is required

Article 35(1) GDPR requires the controller to carry out a data protection impact assessment before processing that is "likely to result in a high risk to the rights and freedoms of natural persons", in particular when new technologies are used. The controller must seek the advice of its data protection officer when doing so (Article 35(2)). A DPIA is always required in the three cases in Article 35(3):

Each supervisory authority must also publish a list of processing types that require a DPIA (Article 35(4)), and may publish a list of types that do not (Article 35(5)).

The nine criteria and the two-criteria rule

The Article 29 Working Party's DPIA guidelines, WP248 rev.01 (adopted 4 April 2017, last revised 4 October 2017), set out nine criteria for spotting high-risk processing. The EDPB endorsed them at its first plenary meeting, and national lists such as IMY's build on them. The guidelines say that in most cases a controller can consider that processing meeting two criteria requires a DPIA, that more criteria make a DPIA more likely, and that a single criterion can be enough in some cases.

They also say that if processing meets the criteria but the controller still considers it not likely to result in a high risk, the controller should justify and document the reasons for not carrying out a DPIA and record the DPO's views. The copyable summary above is designed for that record.

Applying the criteria in a university

Validemic's analysis
Three criteria come up in almost every higher education screening. Student data is usually large-scale (criterion 5) because one platform covers every student in a programme or the whole institution. Students are often treated as vulnerable (criterion 7) because they depend on the institution for grades and degrees, which is the kind of imbalance the guidelines describe. And AI-based tools usually count as innovative technology (criterion 8). That means a new AI tool used across a student population will often meet two or three criteria before anyone looks at what it actually does with the data.

National Article 35(4) lists

Check the list of the supervisory authority that is competent for your institution. The lists add to Article 35(3) and are not exhaustive.

CountryAuthority and listNotes
SwedenIMY: När ska en konsekvensbedömning genomföras? (links the förteckning under Article 35.4)Uses the nine criteria; as a main rule two criteria trigger a DPIA
FinlandTietosuojavaltuutetun toimisto: Luettelo vaikutustenarviointia edellyttävistä käsittelytoimistaLinked from the authority's page on DPIAs (vaikutustenarviointi)
NorwayDatatilsynet's list (English version in the EDPB register)Datatilsynet's own site also publishes the list in Norwegian
DenmarkDatatilsynet: Konsekvensanalyse (links the list of processing that always requires a konsekvensanalyse)Datatilsynet notes the list is not exhaustive
NetherlandsAutoriteit Persoonsgegevens: DPIA (links the DPIA-lijst)The AP notes its list is not exhaustive
IrelandDPC: List of Types of Data Processing Operations which require a DPIACovers national and cross-border processing
BelgiumAPD/GBA: Decision no. 01/2019 of 16 January 2019Linked from the authority's DPIA page
GermanyDSK: DSFA Muss-Liste, version 1.1The DSK labels it the list for the non-public sector; public universities should also check their state authority
FranceCNIL: liste des traitements pour lesquels une AIPD est requiseFourteen types of processing, with examples

DPIAs and AI systems

If the processing involves a high-risk AI system under the EU AI Act, Article 26(9) of that Act requires deployers to use the information the provider gives under Article 13 when carrying out their DPIA. Public universities deploying high-risk systems also face a fundamental rights impact assessment under Article 27, which can cross-refer to the DPIA. Our AI Act checker for education shows whether that applies.

After the screening

Sources

All sources retrieved 7 October 2026.

  1. Regulation (EU) 2016/679 (GDPR), Articles 35 and 36, EUR-Lex: eur-lex.europa.eu/eli/reg/2016/679/oj/eng
  2. Article 29 Working Party, Guidelines on Data Protection Impact Assessment (DPIA), WP248 rev.01: ec.europa.eu/newsroom/article29/items/611236
  3. EDPB, Endorsed WP29 guidelines: edpb.europa.eu/endorsed-wp29-guidelines_en
  4. EDPB, Register of DPIA lists of processing activities: edpb.europa.eu, DPIA lists register
  5. National lists: IMY, Tietosuojavaltuutetun toimisto, Datatilsynet (Norway, via the EDPB register), Datatilsynet (Denmark), Autoriteit Persoonsgegevens, Data Protection Commission, APD/GBA, Datenschutzkonferenz and CNIL, as linked in the table above.
  6. Regulation (EU) 2024/1689 (AI Act), Articles 26 and 27, as amended by Regulation (EU) 2026/1744: eur-lex.europa.eu/eli/reg/2024/1689/oj/eng and eur-lex.europa.eu/eli/reg/2026/1744/oj/eng

About this tool

We built this screening from the GDPR text, the WP248 rev.01 guidelines and the national lists linked above, all read on 7 October 2026. A screening is a first step, not a DPIA, and the result depends on how you describe the processing. It is not legal advice; the controller and its DPO remain responsible for the assessment. Authorities update their lists from time to time. If a link has moved or you spot an error, please contact us and we will correct it.

Frequently asked questions

When is a DPIA required under the GDPR?

Article 35(1) requires a DPIA before processing that is likely to result in a high risk to people's rights and freedoms. Article 35(3) names three cases where it is always required, and each supervisory authority publishes a list of further processing types under Article 35(4).

What are the nine DPIA criteria?

The WP29 guidelines (WP248 rev.01, endorsed by the EDPB) list: evaluation or scoring; automated decisions with legal or similar effect; systematic monitoring; sensitive or highly personal data; large-scale processing; matching or combining datasets; vulnerable data subjects; innovative use of technology; and processing that prevents people from exercising a right or using a service.

How many criteria trigger a DPIA?

The guidelines say that in most cases processing meeting two criteria requires a DPIA, and that the more criteria are met, the more likely a DPIA is needed. In some cases a single criterion can be enough.

Do I need to document a decision not to do a DPIA?

Yes, in practice. The guidelines say that where processing meets the criteria but the controller considers it is not likely to result in a high risk, the controller should justify and document the reasons and record the views of the DPO.

Are students vulnerable data subjects?

The guidelines describe vulnerable data subjects as cases where there is an imbalance of power between the person and the controller, naming children and employees as examples. Students who depend on the university for grades and degrees are often treated the same way, so many DPOs tick this criterion for student data.