DPIA Lists

01 october 2018

On 26 September 2018, the European Data Protection Authorities, assembled in the European Data Protection Board, met for their third plenary session. During the plenary a wide range of topics were discussed. In particular, the EDPB reached an agreement on and adopted the 22 opinions establishing common criteria for Data Protection Impact Assessment (DPIA) lists. These lists form an important tool for the consistent application of the GDPR across the EU. DPIA is a process to help identify and mitigate data protection risks that could affect the rights and freedoms of individuals. To help clarify the types of processing which could require a DPIA, the GDPR calls for the national supervisory authorities to create and publish lists of types of operations that are likely to result in a high risk. The Board received 22 national lists with an overall of 260 different types of processing. The EDPB Chair, Andrea Jelinek said: “It has been an enormous task for the members of the Board as well as the EDPB Secretariat to examine all of these lists and to establish common criteria on what triggers a DPIA and what not. It was an excellent opportunity for the EDPB to test the possibilities and challenges of consistency in practice. The GDPR does not require full harmonisation or an 'EU list', but does require more consistency, which we have achieved in these 22 opinions by agreeing on a common view.” The 22 opinions on the DPIA lists result from art 35.4 and art. 35.6 GDPR and are in line with earlier guidance established by the Article 29 Working Party.

News archive

 

Firm news

gen9

09/01/2026

Tariffe minime di consegna di libri

La Sentenza della Corte di Giustizia dell' UE, nella causa C-366/24 | Amazon EU, riconosce che  l’imposizione, con una misura nazionale, di tariffe minime per la consegna a domicilio

gen9

09/01/2026

In caso di utilizzo di una telecamera indossabile (bodycam) durante il controllo dei biglietti, alcune informazioni devono essere fornite immediatamente al passeggero interessato

La Sentenza della Corte di Giustizia dell' UE, nella causa C-422/24 | Storstockholms Lokaltrafik, affronta il caso di una azienda di trasporto pubblico di Stoccolma (Svezia) che  fornisce ai

gen9

09/01/2026

Recommendations 2/2025 on the legal basis for requiring the creation of user accounts on e-commerce websites.

he European Data Protection Board welcomes comments on the Recommendations 2/2025 on the legal basis for requiring the creation of user accounts on e-commerce websites.Such comments should be

Lawyer News

gen10

10/01/2026

Notai: concorso per 400 posti

Pubblicato in Gazzetta Ufficiale il bando,

gen10

10/01/2026

Il Sistema di Informazione Schengen tra sicurezza e diritti fondamentali

Il ruolo del Garante per la protezione