Mandatory DPIA in 2026: when and how?
The Data Protection Impact Assessment (DPIA) is a major legal obligation under the GDPR. Find out when it is mandatory and how to implement it.
The DPIA: an essential tool for GDPR compliance
The Data Protection Impact Assessment, commonly known as DPIA (Data Protection Impact Assessment), represents one of the major innovations of the General Data Protection Regulation (GDPR). This preventive assessment procedure allows companies to identify and minimise risks related to the processing of personal data before its implementation.
Although optional in some cases, the DPIA becomes mandatory in specific situations defined by Article 35 of the GDPR. This legal obligation applies to any data controller, whether a private company, a public administration, or an association. Failure to comply with this requirement exposes organisations to administrative sanctions that can reach 10 million euros or 2% of the annual worldwide turnover, as highlighted by the CNIL with a record of €486M in 2026.
The increasing complexity of data processing, particularly with the rise of artificial intelligence and emerging technologies, makes mastering the DPIA particularly strategic for businesses in 2026.
Criteria for DPIA obligation
The three cases of legal obligation according to Article 35 of the GDPR
GDPR establishes three situations in which carrying out a DPIA becomes imperative:
1. Systematic and extensive evaluation When processing involves a systematic and extensive evaluation of personal aspects relating to natural persons, based on automated profiling. This obligation particularly concerns scoring systems, recommendation algorithms, and automated decision-making tools. For organisations implementing AI systems, this requirement falls within the broader framework of AI Act compliance in 2026.
2. Large-scale processing of sensitive data Large-scale processing of special categories of data (health data, political opinions, religious beliefs) or data relating to criminal convictions systematically requires a DPIA.
3. Systematic monitoring of a publicly accessible area Any processing involving systematic large-scale monitoring of a publicly accessible area, such as intelligent video surveillance or facial recognition systems, requires an impact assessment.
Do you have a legal question on this topic? Maître Pierre-Louis Roquet, a lawyer focused on business law in Lyon, supports you with responsiveness and expertise. Contact the firm for a consultation.
National lists of processing operations subject to DPIA
Each national data protection authority can establish complementary lists of processing operations subject to the DPIA obligation. In France, the CNIL has published a detailed list including:
- Processing of biometric data for unique identification purposes
- Processing of genetic data
- Geolocation processing for monitoring individuals
- Processing using data concerning vulnerable individuals (minors, elderly, patients)
- Machine learning or artificial intelligence algorithms, particularly in the context of classification of high-risk AI systems
The notion of "large scale": practical interpretation
The notion of "large scale" is not subject to any numerical definition in the GDPR. The guidelines of the European Data Protection Board (EDPB) specify several assessment criteria:
- The number of data subjects (in absolute value or as a percentage of the population)
- The volume of data processed
- The duration or permanence of the processing activity
- The geographical extent of the processing
A processing operation concerning more than 10,000 individuals is generally considered large-scale, but this assessment must take into account the specific context.
Particularly concerned sectors of activity
Health and insurance sector
Healthcare establishments, health insurance bodies, and mutual insurance companies must systematically carry out a DPIA for any processing of medical data. The particular sensitivity of this data and the number of individuals concerned justify this reinforced requirement.
Financial and banking sector
Financial institutions process sensitive data (credit history, asset information) on a large scale. Any credit scoring, risk assessment, or behavioural analysis system requires a prior DPIA.
Public sector and local authorities
Public administrations, town halls, prefectures, and centralised services process data on a large scale. The DPIA becomes mandatory for the majority of their processing operations, particularly those involving monitoring or profiling of citizens.
Digital marketing and e-commerce sector
Digital marketing companies, e-commerce platforms, and advertisers using behavioural targeting must carry out a DPIA when they implement large-scale profiling or recommendation algorithms.
The DPIA procedure
Preliminary steps: needs assessment
Before undertaking the full implementation of a DPIA, companies must assess whether their processing is actually subject to this obligation. This preliminary phase is crucial and must be documented. Several tools exist, including rapid assessment questionnaires proposed by national data protection authorities.
Technical implementation of the impact assessment
When the DPIA is mandatory, its implementation generally includes:
1. Description of the processing
- The purpose of the processing
- Categories of data processed
- Categories of recipients
- Retention period
- Envisaged security measures
2. Risk assessment
- Identification of risks to the rights and freedoms of data subjects
- Assessment of the likelihood and severity of each risk
- Consideration of the technological and organisational context
3. Identification of mitigation measures
- Technical measures (encryption, pseudonymisation, anonymisation)
- Organisational measures (limiting data access, staff training)
- Governance measures (processing register, documenting by consulting the comprehensive guide to the GDPR processing register)
Prior consultation of the CNIL
When the risk assessment concludes that the processing would present high risks to rights and freedoms, even after applying mitigation measures, the data controller must consult the data protection authority (CNIL in France) before implementing the processing.
This prior consultation is not an approval, but an examination procedure by the competent authority, which may make recommendations or impose modifications to the processing.
Deadlines and compliance calendar for 2026
Acceleration of CNIL controls
Since 2023, the CNIL has reinforced its controls on DPIA compliance. The number of audits focusing on this requirement has increased by 40% annually. This movement is part of a broader strategy of CNIL controls and sanctions in 2026.
Intersections with the NIS2 directive and the AI Act
The 2026 compliance calendar combines several converging obligations:
- The progressive application of the AI Act for high-risk systems
- The entry into force of the NIS2 directive and its cybersecurity obligations
- Algorithm audit requirements for AI systems
These three regulations all require a DPIA or an equivalent impact assessment, thus creating possible synergies in their implementation.
Recommendations for businesses
Before March 31, 2026:
- Conduct an internal audit of existing processing operations
- Identify all processing operations subject to DPIA obligation
- Update the GDPR processing register
- Begin performing priority DPIAs
Before June 30, 2026:
- Complete all mandatory DPIAs
- Document consultations with the CNIL if necessary
- Implement identified mitigation measures
- Train teams on obligations arising from DPIAs
Before December 31, 2026:
- Make final adjustments
- Prepare documentation for CNIL controls
- Establish a sustainable DPIA monitoring process
Common mistakes to avoid
Confusion between DPIA and IT risk studies
A DPIA is not a simple IT audit. It is an assessment specifically focused on the impact of processing on the rights and freedoms of data subjects, not on the general IT security of the system. Although interdependent, these two analyses must be conducted in parallel but cannot substitute for each other.
Failure to consult in case of high risk
Many companies correctly carry out a DPIA but forget to consult the CNIL when high risks remain. This omission constitutes a violation of Article 36 of the GDPR and exposes them to significant penalties.
Lack of documentary traceability
The DPIA must be fully and detailed documented. A simple partially completed questionnaire does not meet legal requirements. The documentation must allow a third party (CNIL inspector) to understand the reasoning followed.
Absence of regular updates
A DPIA is not a static document. It must be revised in case of processing modification, technological evolution, or following incidents involving personal data.
Related articles
A matter on this topic? My areas of practice — Contact the firm