Obligations

Do I need a DPIA?

Article 35 requires one where processing is likely to result in a high risk to the rights and freedoms of natural persons. That sentence is doing a lot of work, and the answer for your deployment sits inside it.

The decision structure

Four questions, in this order.

Working through them in a different order is how teams end up assessing the wrong thing, or assessing nothing because the first question was never settled.

01

Is this processing of personal data at all?

If the deployment touches no personal data, Art. 35 is not the instrument to be looking at — though something else may still attach. Settle this before anything else, because a surprising number of tools turn out to touch personal data through a secondary path nobody described.

02

Which controller is asking?

The duty sits with the controller. In a deployment involving a vendor, a platform and an internal team, establishing who is controller for which processing is prior to everything else and is frequently the actual difficulty.

03

Does the processing meet the likely-high-risk condition?

This is where the analysis lives: the nature, scope, context and purposes of the processing, read against supervisory-authority lists of operations that require an assessment and the criteria published for judging the rest.

04

If not — where is the record of that decision?

This is the question people skip. Concluding that no assessment is required is a legitimate outcome and a documentable one. Without the dated record, it is indistinguishable from never having asked.

This page cannot answer the question for you. It sets out the questions that decide it. Whether a duty attaches to a particular deployment depends on facts specific to your organisation, and whether your position is adequate is a judgement for your counsel. Nothing here is legal advice. Supervisory authorities publish their own lists of processing that requires an assessment, and those lists differ between member states.

The answer people miss

“No” is a deliverable.

Most of the value here is not in the assessments you write. It is in the deployments where you correctly concluded that none was required, and can show when you concluded it and on what basis.

A determination produces that record either way — the duty set if one attaches, and the dated statement of what was assessed and did not if none does.

If the answer is yes →

Bound statutes and a pen

Settle it in fifteen minutes

Either way, you end up with a record.

A determination tells you whether Art. 35 reaches this deployment and cites what it found. If it does not, you have the document that says so.