When is a DPIA required? The EDPB's 9 criteria, explained
We already covered where GDPR and the AI Act overlap. Here's the practical question underneath it: does your processing activity need a DPIA, yes or no? The answer isn't a gut call — it's 9 published criteria, and 2 of them are already enough.
The base rule, and why it's not enough on its own
GDPR Art. 35(1) requires a DPIA (Data Protection Impact Assessment) when processing is "likely to result in a high risk" to people's rights. The problem is that "high risk" doesn't define itself — which is why the European Data Protection Board (EDPB) published a list of 9 concrete criteria to stop relying on intuition.
The EDPB's 9 criteria (WP248 guidelines)
- Evaluation or scoring — including profiling and predicting behavior.
- Automated decision-making with legal or similarly significant effect — without meaningful human involvement.
- Systematic monitoring — of individuals, including observation of a publicly accessible area.
- Sensitive data or data of a highly personal nature — Article 9 special categories, criminal-offence data.
- Large-scale processing — GDPR doesn't set an exact numeric threshold, but Recital 91 points to the number of people, volume of data, duration, and geographic extent.
- Matching or combining datasets — from different sources or operations, beyond what the person would reasonably expect.
- Vulnerable data subjects — children, employees, patients, asylum seekers.
- Innovative use or new technology — with consequences that are still poorly understood.
- Blocking access to a service or contract — when the processing determines whether someone can access something.
The practical rule: 2 criteria, sometimes just 1
The operating rule most authorities apply: if your processing matches 2 or more of the 9 criteria, a DPIA is required. But a single criterion can be enough if the risk is clearly high on its own — for example, large-scale systematic biometric surveillance of a public space.
Art. 35(3) goes further and names 3 cases where a DPIA is always mandatory, no criteria-counting needed: systematic and extensive evaluation of personal aspects involving profiling, large-scale processing of special-category or criminal-offence data, and systematic large-scale monitoring of a publicly accessible area.
New in 2026: the first EU-wide harmonized template
On April 14, 2026, the EDPB published the first DPIA template harmonized across the entire Union — with public consultation closing June 9, 2026. Using it isn't mandatory in itself, but once finalized, every national data protection authority will have to adopt it or align their own templates with it. For a company operating across several countries, that's a real simplification: a DPIA done with this template in one country will be recognized by authorities across the rest of the EEA.
The new template also includes a section built explicitly for the intersection with the AI Act.
The AI Act connection almost nobody documents well
AI Act Art. 26(9) requires anyone deploying an AI system to use the information the provider gives them (under AI Act Art. 13) to complete their own GDPR Art. 35 DPIA obligation. These are two separate legal obligations — one under the AI Act, one under GDPR — that feed into each other. If you deploy a third-party AI system and complete your DPIA without requesting that documentation from the provider, the assessment is very likely incomplete.
What it should contain, beyond the Art. 35(7) minimums
The WP248 guidance recommends documenting, beyond the 4 mandatory elements of Art. 35(7): the identity and contact details of the controller and DPO, categories of data subjects and data, retention periods, a record of how the DPO was consulted, and the assessment date with its scheduled review date. A two-page summary asserting that "appropriate measures have been taken" is not a valid DPIA — the EDPB expects a structured, repeatable methodology.
The template, already structured
The DPIA Template includes the 9 criteria as a trigger checklist, and the full minimum-content structure — ready to adapt to your specific processing activity.