The impact assessment: when it becomes mandatory
Where a high risk is likely, Article 35 GDPR requires an impact assessment before processing begins. The threshold is lower than many assume – and the timing is the real sticking point.
The impact assessment is not a review after the fact but a planning tool. It is meant to surface risks while the project can still be changed – which is precisely why it has to exist before processing starts, not after the first complaint.
When it is mandatory
Article 35(3) names three cases where it is always required: extensive evaluation of personal aspects by automated processing, extensive processing of special categories of data, and systematic extensive monitoring of publicly accessible areas.
Alongside that, every supervisory authority maintains its own list of processing operations for which an assessment is compulsory. These lists are published and are the quickest way into the question.
The Board's rule of thumb
What belongs in the document
- A description of the planned processing: purposes, kinds of data, people affected, recipients, periods, technology used.
- An assessment of necessity and proportionality – can the purpose be reached with less data?
- The risks to rights and freedoms – from the perspective of the people affected, not of the company.
- The measures planned to address them and the residual risk once they are in place.
When the residual risk stays high
If a high risk remains after all planned measures, Article 36 requires prior consultation with the supervisory authority. It has eight weeks to respond, extendable by a further six. Processing may not begin until then.
In practice such consultations are rare – not because high residual risks are rare, but because a project is as a rule adjusted once the assessment makes the risk visible. That is exactly its purpose.
An impact assessment concluding that everything is fine was either unnecessary or came too late.