← back to the act's dossier

GDPR — Article 35

The article's text

Article 35 Data protection impact assessment 1. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks. 2. The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the nat
full text
ural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale. and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale. 4. The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68. 5. The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board. no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board. 6. Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union. behaviour in several Member States, or may substantially affect the free movement of personal data within the Union. 7. The assessment shall contain at least: (a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; (b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes; (c) an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and (d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned. this Regulation taking into account the rights and legitimate interests of data subjects and other persons concerned. 8. Compliance with approved codes of conduct referred to in Article 40 by the relevant controllers or processors shall be taken into due account in assessing the impact of the processing operations performed by such controllers or processors, in particular for the purposes of a data protection impact assessment. 9. Where appropriate, the controller shall seek the views of data subjects or their representatives on the intended processing, without prejudice to the protection of commercial or public interests or the security of processing operations. without prejudice to the protection of commercial or public interests or the security of processing operations. 10. Where processing pursuant to point (c) or (e) of Article 6(1) has a legal basis in Union law or in the law of the Member State to which the controller is subject, that law regulates the specific processing operation or set of operations in question, and a data protection impact assessment has already been carried out as part of a general impact assessment in the context of the adoption of that legal basis, paragraphs 1 to 7 shall not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities. not apply unless Member States deem it to be necessary to carry out such an assessment prior to processing activities. 11. Where necessary, the controller shall carry out a review to assess if processing is performed in accordance with the data protection impact assessment at least when there is a change of the risk represented by processing operations.

Who wrote about this article in the consultations

Filers who named this exact article number in their own text. It is their sentence, not our reading — and not a causal claim.

7
NGO
5
business association
3
company
2
other
2
ACADEMIC_RESEARCH_INSTITTUTION
WhoCountryWhat they wrote
Deutscher Juristinnenbund e.V.DErden müssen. Dazu gehört, betroffene Personen vor Schaden und Diskriminierung zu bewahren (Erw. 85). Bereits nach der Wertung von Art. 35 Abs. 3 lit a) DSGVO hat Profiling grundsätzlich ein hohes Risiko für die Rechte und Freiheiten natürlicher Personen zur Fo
ACCISBEred for high-risk data processing, is not inherently mandated for profiling, except in cases covered by Article 22 GDPR (refer to Article 35.3.a GDPR). Details of relevant GDPR provisions for the AI Act:
Information Accountability FoundationUSue. GDPR, AI and risk assessment Considering the two-step concept outlined above the IAF proposes that there is merit in amending Article 35 of the GDPR. It should be amended to apply to the application of insights stage (use of data) more clearly, where there
BSA | The Software AllianceBEtection impact assessments (DPIAs) for high-risk activities, which can be a helpful tool for businesses, the powers granted under Article 35(5) of the GDPR to DPAs to create their own list of processing operations subject to DPIAs has caused irregular approach
Van Bael & BellisBEt pertinent issues. For example, the guidance on DPIA7 does not address key points such as the exact methods for risk assessment (Article 35(7)(c) GDPR), for proportionality and necessity assessment (Article 35(7)(b) GDPR) or for consultation with data subject
AvvocatoITl'emersione di numerose incertezze/difficoltà di ordine teorico e pratico), la valutazione di impatto sulla protezione dei dati (art. 35) e soprattutto la designazione del DPO (art. 37); 2) la razionalizzazione delle basi giuridiche, constatata la non sempre
ZKI e.V.DEEin weiteres offizielles Musterdokument könnte für die Durchführung einer Datenschutzfolgenabschätzung gemäß Art. 35 DSGVO sowie für die Durchführung eines Transfer Impact Assessment (TIA) im Rahmen der Art. 44 ff. DSGVO erstellt und veröffentlicht werden. All
Oplysningsforbundet May DayDKligheder skal vælges den mindst bebyrdende foranstaltning, jf. fx GDPRs artikel 25, stk. 1 state-of-the-art vedr. design og GDPRs artikel 35, stk. 1 om konsekvensanalyse. Desto hårdere en retsakt rammer private interesser, desto mere må forvaltningen sikre sig
Europeans for Safe ConnectionsBEtion laws We call for such assessment to be conducted regularly, every year, and for each EU member state. This requires amending Article 35 of the GDPR on the basis of Article 16 of the TFEU, so that this type of impact assessment can be initiated at the leve
Délégué à la Protection des Données (ancien et formateur)FRà la personne physique concernée pour que celle-ci puisse atténuer les effets négatifs potentiels de la violation. 12) Article 35 RGPD : les risques résiduels identifiés dans le cadre d’une analyse d’impact doivent peser explicitement sur le responsable de tra
Privacy CompanyNLs We recommend introducing a requirement for large organisations or smaller organisations with high risk processing as defined in Art. 35 GDPR to include a paragraph in their annual report about their progress with privacy compliance, similar to obligations ab
Anonos Inc.USitimate interests are in place.” • Improve Scalability of Data Protection Impact Assessments a. Pseudonymization helps to satisfy Article 35(3)(b) obligations when “processing on a large scale of special categories of data referred to in Article 9(1).” b.
noybATnd the Board. Those implementing acts shall be adopted in accordance with the examination procedure referred to in Article 93(2). Article 35 - Statistics
Border Violence Monitoring NetworkDEtoring to ensure new technology that circumvents EU law cannot be used freely. While there are supposed provisions for this under Article 35 and 36 of the GDPR, BVMN asserts that these do not go far enough in preventing the use of these technologies, which can
David BARNARD-WILLSGBining when DPIAs are required in certain contexts, and for consulting with data processors following impact assessment exercises (Article 35). DPAs should determine collectively what they consider to be data processing that is likely to result in a high risk t
Federation of Austrian Industries (Industriellenvereinigung)ATbtain. - a specification what should be part of the information about the joint controller arrangement given to data subjects. h. Art 35 – Data Protection Impact Assessment (DPIA) In practice there are some uncertainties how comprehensive a DPIA should be.
Digitale Gesellschaft e.V.DEdata protection impact assessment according to Article 35(4) and prior consultation pursuant to Article 36 of the GDPR. 3. Specifying the Rules for Profiling Profiling addresses a broad number of different cases. From simple customer data bases containing name
Ecommerce EuropeBErations which are subject to the requirement for a data protection impact assessment” established by the German DPAs according to Art. 35 (4) GDPR. The “blacklist” according to Art. 35 (5) GDPR is not established yet by the German DPAs. In the end, the control
BSA | The Software AllianceBEbenefit from uniformity and guidance on DPIA thresholds and triggers. Local differences created by the opt-in and opt-out lists (Article 35 (4) and (5)) bring harmonization risks. More guidance pertaining to cloud-based examples or multi-party contracting exa
Federation of German Consumer Associations (Verbraucherzentrale Bundesverband e.V. - vzbv)DEo children in the normative text and thereby ensuring that controllers respect their specific rights and freedoms. The changes to Art. 35 GDPR go further than mere clarification and establish specific obligations to pay par- ticular attention to children when
Centre for Information Policy Leadership (CIPL)GBs and society of not going forward with a specific project due to potential risks?) should be part of risk assessments and DPIAs. Article 35(1) GDPR uses the notion of “impact”, which can include both negative and positive factors and does not prevent the incl

Source: public consultation submissions and position papers. n = 21 mentions; counted as a literal reference to the article number.

Ask about this article →