Mandatory DPIA in 2026: when and how?

By Pierre-Louis Roquet, Attorney at the Lyon Bar | 24 mars 2026 | Reading time : 7 min
Legal article: Mandatory DPIA in 2026: when and how? - Lyon Lawyer Blog

The Data Protection Impact Assessment (DPIA) is a major legal obligation under the GDPR. Find out when it is mandatory and how to implement it.

The DPIA: an essential tool for GDPR compliance

The Data Protection Impact Assessment, commonly known as DPIA (Data Protection Impact Assessment), represents one of the major innovations of the General Data Protection Regulation (GDPR). This preventive assessment procedure allows companies to identify and minimise risks related to the processing of personal data before its implementation.

Although optional in some cases, the DPIA becomes mandatory in specific situations defined by Article 35 of the GDPR. This legal obligation applies to any data controller, whether a private company, a public administration, or an association. Failure to comply with this requirement exposes organisations to administrative sanctions that can reach 10 million euros or 2% of the annual worldwide turnover, as highlighted by the CNIL with a record of €486M in 2026.

The increasing complexity of data processing, particularly with the rise of artificial intelligence and emerging technologies, makes mastering the DPIA particularly strategic for businesses in 2026.

Criteria for DPIA obligation

The three cases of legal obligation according to Article 35 of the GDPR

GDPR establishes three situations in which carrying out a DPIA becomes imperative:

1. Systematic and extensive evaluation When processing involves a systematic and extensive evaluation of personal aspects relating to natural persons, based on automated profiling. This obligation particularly concerns scoring systems, recommendation algorithms, and automated decision-making tools. For organisations implementing AI systems, this requirement falls within the broader framework of AI Act compliance in 2026.

2. Large-scale processing of sensitive data Large-scale processing of special categories of data (health data, political opinions, religious beliefs) or data relating to criminal convictions systematically requires a DPIA.

3. Systematic monitoring of a publicly accessible area Any processing involving systematic large-scale monitoring of a publicly accessible area, such as intelligent video surveillance or facial recognition systems, requires an impact assessment.

Do you have a legal question on this topic? Maître Pierre-Louis Roquet, a lawyer focused on business law in Lyon, supports you with responsiveness and expertise. Contact the firm for a consultation.

National lists of processing operations subject to DPIA

Each national data protection authority can establish complementary lists of processing operations subject to the DPIA obligation. In France, the CNIL has published a detailed list including:

The notion of "large scale": practical interpretation

The notion of "large scale" is not subject to any numerical definition in the GDPR. The guidelines of the European Data Protection Board (EDPB) specify several assessment criteria:

A processing operation concerning more than 10,000 individuals is generally considered large-scale, but this assessment must take into account the specific context.

Particularly concerned sectors of activity

Health and insurance sector

Healthcare establishments, health insurance bodies, and mutual insurance companies must systematically carry out a DPIA for any processing of medical data. The particular sensitivity of this data and the number of individuals concerned justify this reinforced requirement.

Financial and banking sector

Financial institutions process sensitive data (credit history, asset information) on a large scale. Any credit scoring, risk assessment, or behavioural analysis system requires a prior DPIA.

Public sector and local authorities

Public administrations, town halls, prefectures, and centralised services process data on a large scale. The DPIA becomes mandatory for the majority of their processing operations, particularly those involving monitoring or profiling of citizens.

Digital marketing and e-commerce sector

Digital marketing companies, e-commerce platforms, and advertisers using behavioural targeting must carry out a DPIA when they implement large-scale profiling or recommendation algorithms.

The DPIA procedure

Preliminary steps: needs assessment

Before undertaking the full implementation of a DPIA, companies must assess whether their processing is actually subject to this obligation. This preliminary phase is crucial and must be documented. Several tools exist, including rapid assessment questionnaires proposed by national data protection authorities.

Technical implementation of the impact assessment

When the DPIA is mandatory, its implementation generally includes:

1. Description of the processing

2. Risk assessment

3. Identification of mitigation measures

Prior consultation of the CNIL

When the risk assessment concludes that the processing would present high risks to rights and freedoms, even after applying mitigation measures, the data controller must consult the data protection authority (CNIL in France) before implementing the processing.

This prior consultation is not an approval, but an examination procedure by the competent authority, which may make recommendations or impose modifications to the processing.

Deadlines and compliance calendar for 2026

Acceleration of CNIL controls

Since 2023, the CNIL has reinforced its controls on DPIA compliance. The number of audits focusing on this requirement has increased by 40% annually. This movement is part of a broader strategy of CNIL controls and sanctions in 2026.

Intersections with the NIS2 directive and the AI Act

The 2026 compliance calendar combines several converging obligations:

These three regulations all require a DPIA or an equivalent impact assessment, thus creating possible synergies in their implementation.

Recommendations for businesses

Before March 31, 2026:

Before June 30, 2026:

Before December 31, 2026:

Common mistakes to avoid

Confusion between DPIA and IT risk studies

A DPIA is not a simple IT audit. It is an assessment specifically focused on the impact of processing on the rights and freedoms of data subjects, not on the general IT security of the system. Although interdependent, these two analyses must be conducted in parallel but cannot substitute for each other.

Failure to consult in case of high risk

Many companies correctly carry out a DPIA but forget to consult the CNIL when high risks remain. This omission constitutes a violation of Article 36 of the GDPR and exposes them to significant penalties.

Lack of documentary traceability

The DPIA must be fully and detailed documented. A simple partially completed questionnaire does not meet legal requirements. The documentation must allow a third party (CNIL inspector) to understand the reasoning followed.

Absence of regular updates

A DPIA is not a static document. It must be revised in case of processing modification, technological evolution, or following incidents involving personal data.

Related articles