GDPR — 35: Data protection impact assessment
GDPR — 35: Data protection impact assessment seen through the recitals: the source row from the register, the obligations it carries, the roles it reaches and the steps it belongs to. The legal text stays with the source — here you get the link, the address and the reading date.
Source row from the register
- When an impact assessment is required: systematic monitoring, sensitive data at scale and new technology.
Obligations
- Controller: Carry out a data protection impact assessment for high-risk processing.
Recitals interpreting the article
- 90: When an impact assessment is required: systematic monitoring, sensitive data at scale and new technology.
What forces a redo
- The node hash changes — the text behind the row is no longer the same.
- The reading date moves forward — the row has been re-read against the source.
- A timeline passes — the requirement starts to apply or tightens.
As data
- The same node as data: add ?format=json to the address, or ?format=agent for receipt and dependencies.
Roles
Workflows
Relations
Metadata
- Acts
- GDPR
- Articles
- 1
- Reading date
- 2026-08-31
- Freshness
- 74/100
- Hash
- e3f5d603a6997830
- Corpus version
- legal-2026-08-25
- Next check
- —
- CELEX
- 32016R0679
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.