Agent · gdpr-2016-679-35
GDPR artikel 35: Data protection impact assessment
Operative tree, written by hand from the article's conditions.
CELEX 32016R0679 · 2026-08-18 · Weight 106 · minimal-risk
PremiumHand written or high weight rule tree. Metered per call at the edge once metering is switched on, at the same address and with the same answer as today.
- What this page is
- Agent, GDPR artikel 35
- Checked against the official source
- 2026-08-18Current
- Responsible publisher
- ExploreWorld Legal, editorial deskLiability position
Short answer
What does GDPR Article 35 require, and what outcome does the rule tree give?
GDPR Article 35 is tested here by a deterministic rule tree of 3 rules, built from the article's own conditions. The tree reads your facts and names the outcome that applies, starting with An impact assessment is required and missing, carrying paragraph citation, content hash and read date 2026-08-18 against CELEX 32016R0679. The outcome is a machine classification, not a compliance decision.
GDPR Article 35Checked against the publisher 2026-08-18Official text
- An impact assessment is required and missing. The assessment shall be carried out prior to the processing and contain a description, a necessity test, a risk assessment and measures under Article 35(7).
- The impact assessment has been carried out. Where a high risk remains despite the measures, the supervisory authority shall be consulted under Article 36.
- None of the listed situations applies. An assessment is still required where the processing is likely to result in a high risk, and the supervisory authority's list shall be taken into account.
A source reference, not legal advice.
Jurisdiction
The same agent, read through one country's lens.
Inputs
- systematic_evaluationSystematic and extensive evaluation with automated decisionsboolean
- large_scale_specialLarge scale processing of special categoriesboolean
- public_monitoringSystematic monitoring of a publicly accessible area on a large scaleboolean
- dpia_doneA data protection impact assessment has been carried outboolean
Rule tree
If: alla(någon(systematic_evaluation = true, large_scale_special = true, public_monitoring = true), inte(dpia_done = true))
An impact assessment is required and missing
The assessment shall be carried out prior to the processing and contain a description, a necessity test, a risk assessment and measures under Article 35(7).
Paragraph 1, 3, 7
If: dpia_done = true
The impact assessment has been carried out
Where a high risk remains despite the measures, the supervisory authority shall be consulted under Article 36.
Paragraph 7, 11
If: alla(systematic_evaluation = false, large_scale_special = false, public_monitoring = false)
None of the listed situations applies
An assessment is still required where the processing is likely to result in a high risk, and the supervisory authority's list shall be taken into account.
Paragraph 1, 4
If no rule matches: None of the article's conditions are met with the facts supplied. Supply more facts or read the article in full.
The article text as read
- 11. Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data. A single assessment may address a set of similar processing operations that present similar high risks.
- 22. The controller shall seek the advice of the data protection officer, where designated, when carrying out a data protection impact assessment.
- 33. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of:
- 4(a)
- 5a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person;
- 6(b)
- 7processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or
- 8(c)
- 9a systematic monitoring of a publicly accessible area on a large scale.
- 104. The supervisory authority shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment pursuant to paragraph 1. The supervisory authority shall communicate those lists to the Board referred to in Article 68.
- 115. The supervisory authority may also establish and make public a list of the kind of processing operations for which no data protection impact assessment is required. The supervisory authority shall communicate those lists to the Board.
- 126. Prior to the adoption of the lists referred to in paragraphs 4 and 5, the competent supervisory authority shall apply the consistency mechanism referred to in Article 63 where such lists involve processing activities which are related to the offering of goods or services to data subjects or to the monitoring of their behaviour in several Member States, or may substantially affect the free movement of personal data within the Union.
- 137. The assessment shall contain at least:
- 14(a)
Lineage
Interface
Hashes
Artefacts
No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.
Citation: 32016R0679 art. 35, Data protection impact assessment. ExploreWorld Legal, https://legal.exploreworldai.com/agent/gdpr-2016-679/artikel-35 (hämtad 2026-08-18, bevis sha256:b18917bbc6b1c6fa, bygge legal-2026-08-25).