Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Agent · gdpr-2016-679-35

GDPR artikel 35: Data protection impact assessment

Operative tree, written by hand from the article's conditions.

CELEX 32016R0679 · 2026-08-18 · Weight 106 · minimal-risk

PremiumHand written or high weight rule tree. Metered per call at the edge once metering is switched on, at the same address and with the same answer as today.

GDPROfficial source

What this page is
Agent, GDPR artikel 35
Checked against the official source
2026-08-18Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position

Jurisdiction

The same agent, read through one country's lens.

Inputs

  • systematic_evaluationSystematic and extensive evaluation with automated decisionsboolean
  • large_scale_specialLarge scale processing of special categoriesboolean
  • public_monitoringSystematic monitoring of a publicly accessible area on a large scaleboolean
  • dpia_doneA data protection impact assessment has been carried outboolean

Rule tree

  1. If: alla(någon(systematic_evaluation = true, large_scale_special = true, public_monitoring = true), inte(dpia_done = true))

    An impact assessment is required and missing

    The assessment shall be carried out prior to the processing and contain a description, a necessity test, a risk assessment and measures under Article 35(7).

    Paragraph 1, 3, 7

  2. If: dpia_done = true

    The impact assessment has been carried out

    Where a high risk remains despite the measures, the supervisory authority shall be consulted under Article 36.

    Paragraph 7, 11

  3. If: alla(systematic_evaluation = false, large_scale_special = false, public_monitoring = false)

    None of the listed situations applies

    An assessment is still required where the processing is likely to result in a high risk, and the supervisory authority's list shall be taken into account.

    Paragraph 1, 4

If no rule matches: None of the article's conditions are met with the facts supplied. Supply more facts or read the article in full.

The article text as read

  1. 11. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
  2. 22. The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
  3. 33. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
  4. 4(a)
  5. 5a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
  6. 6(b)
  7. 7processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
  8. 8(c)
  9. 9a systematic monitoring of a publicly accessible area on a large scale.
  10. 104. The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.
  11. 115. The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
  12. 126. Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
  13. 137. The assessment shall contain at least:
  14. 14(a)

Lineage

treatyTFEU art. 288 (förordning)
act32016R0679
chapterIV. Controller and processor
article35
paragraphs14
jurisdictionEuropean Union (EU)
supervisorIMY — Sweden
national

Interface

callhttps://legal.exploreworldai.com/api/public/v1/agents/gdpr-2016-679-35/run
methodGET
outputmatched, outcome, trace, missing, hash
Quota60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hashes

textsha256:82a3d1a86fa3f797569965093f2ba718964e2fbadfe58be6482984261bd73b79
scriptsha256:3f3263867002ce0c28ff7340fc4dfe720ed4fab7e5741adac2d13aad2e64768e
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:590277222635001cf6e051df0dc481f33b43bb01f6ee0bf7c7459b08b68e300b
versionagent-engine-1+legal-2026-08-25 / 590277222635001c

Artefacts

No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Citation: 32016R0679 art. 35, Data protection impact assessment. ExploreWorld Legal, https://legal.exploreworldai.com/agent/gdpr-2016-679/artikel-35 (hämtad 2026-08-18, bevis sha256:b18917bbc6b1c6fa, bygge legal-2026-08-25).