GDPR and the DPC, for Irish businesses

GDPR

Do you need a DPIA? Ireland has its own list, and it is specific

Most guidance answers this with European criteria. Ireland has a published list of its own, and it is the one that decides the question here.

By Oscar CobbeCurrent as at 10 minute read5 sources

Where the obligation comes from

Article 35(1) of the GDPR requires a data protection impact assessment where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, and it requires it before the processing starts.

Article 35(3) names three cases where one is required regardless: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal or similarly significant effects; processing on a large scale of special category data or of criminal conviction and offence data; and systematic monitoring of a publicly accessible area on a large scale.

Article 35(4) then lets each supervisory authority publish its own list of processing operations that require one. The Data Protection Commission has done that, and its list is what settles the question for an Irish controller.

The Irish list, and the sentence in front of it

The DPC's list has ten items. It carries a condition at the top that is routinely dropped when the list is reproduced, and the condition is doing real work: the ten apply where a documented screening or preliminary risk assessment indicates that the processing operation is likely to result in a high risk.

So the list does not fire by itself. Something has to indicate the risk first, and that something is a screening. Which is exactly why a screening is the honest first step and why it can be automated when a full assessment cannot.

The items are quoted below rather than paraphrased. Paraphrasing a statutory list is how a check ends up telling somebody they are clear when the regulator's own words say otherwise.

ItemWhat the DPC's list says, shortened
1Using personal data on a large scale for a purpose other than the one it was collected for, under Article 6(4)
2Profiling vulnerable persons including children to target marketing or online services at them
3Profiling, algorithmic means or special category data used to determine access to services, or producing legal or similarly significant effects
4Systematically monitoring, tracking or observing individuals' location or behaviour
5Profiling individuals on a large scale
6Biometric data used to identify or authenticate a person, in combination with another WP29 criterion
7Genetic data, in combination with another WP29 criterion
8Indirectly sourced personal data where transparency requirements are not being met
9Combining or cross-referencing separate datasets where the linking contributes to profiling or behavioural analysis
10Large scale processing where the Data Protection Act 2018 requires suitable and specific measures

The two that catch ordinary businesses

Items 4 and 9 are the ones worth reading twice, because between them they describe a normal marketing setup rather than anything exotic.

Item 4 is systematically monitoring, tracking or observing individuals' location or behaviour. That is what an advertising pixel does. It is what session recording and heatmaps do. Aggregate visitor counts are not it; anything tied to an identifier that follows a person between pages or between visits is.

Item 9 is combining, linking or cross-referencing separate datasets where such linking significantly contributes to or is used for profiling or behavioural analysis of individuals, particularly where the datasets are combined from different sources where processing was carried out for different purposes or by different controllers. That is what a joined-up dashboard does when it puts an ad platform, an analytics property and a payment processor on the same customer.

We should say plainly that the second one describes work we sell. The reporting product this company builds joins exactly those sources. If the join is used for behavioural analysis of individuals rather than for totals, item 9 is engaged, and it is better that you read that here than hear it from a client's solicitor.

Two of the ten do not stand on their own

Items 6 and 7 end with the words in combination with any of the other criteria set out in WP29 DPIA Guidelines. A five-person shop with a fingerprint clocking-in machine and nothing else on the list has not triggered a mandatory DPIA on item 6 alone. Read literally the other way round, that item would put half the small employers in the country into an assessment they do not owe.

What the European guidance adds, and what it does not

The Article 29 Working Party's guidelines, WP248 rev.01, endorsed by the European Data Protection Board, set out nine criteria: evaluation or scoring; automated decision-making with legal or similar significant effect; systematic monitoring; sensitive data or data of a highly personal nature; data processed on a large scale; matching or combining datasets; vulnerable data subjects; innovative use of new technologies; and processing that prevents data subjects from exercising a right or using a service or a contract.

The rule of thumb attached to those is quoted much more firmly than it was written. What WP248 actually says is that in most cases a controller can consider that processing meeting two criteria would require a DPIA. Can consider, not must. It is a heuristic, and a single criterion can be enough where the risk is high.

For an Irish controller the ordering is: the DPC's list first, because it is the Article 35(4) instrument that binds here; the WP29 criteria second, as the analysis that fills the gaps.

What happens if the assessment says the risk is still high

Article 36(1) requires prior consultation with the supervisory authority where the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate it. In other words, you consult where your own assessment says you cannot get the risk down, not merely because a DPIA was needed.

The timing under Article 36(2) is worth knowing before anybody plans a launch around it. The authority provides written advice within a period of up to eight weeks of receiving the request, and that period may be extended by six weeks. The extension has to be notified within one month of receipt, and the clock can be suspended while the authority waits for information it has asked for.

Fourteen weeks, in the worst case, before you get an answer. That is the argument for doing the screening early rather than the week before go-live.

What a DPIA is not

It is not a form, and it is not a document you buy. Article 35(7) sets the minimum contents: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to data subjects, and the measures you propose to address them.

It is also not the same as a lawful basis. An assessment that concludes the risk is manageable does not supply a legal ground for the processing, and neither does the fact that nobody objected.

And it is not required for everything. A great deal of ordinary business processing, including payroll, order fulfilment and a customer list used for the thing it was collected for, sits outside the list and outside Article 35(3). The most common outcome of an honest screening is that no assessment is mandatory.

Where this connects to everything else

Three of the questions on this site end up back here. Automated decisions about job candidates engage item 3 about as clearly as the wording allows. Automating a process that moves personal data between systems frequently engages item 1 or item 9. And a privacy notice describes processing that sometimes needed an assessment before it started, which is an awkward thing to discover while writing the notice.

The AI Act connection runs the other way from how it is usually presented. Article 27 of the AI Act, the fundamental rights impact assessment, does not bind most private businesses. Article 35 of the GDPR binds anybody whose processing is on the list, has done since 2018, and is enforced by a regulator with a published decision record.

What to do about it

The order that answers the cheapest question first.

  1. 1Do the screening and keep it. The DPC's list is conditional on a documented screening, so the screening is not a preliminary to the obligation, it is part of it.
  2. 2Answer honestly about tracking. If there is an advertising pixel on the site, item 4 is in play and pretending otherwise costs more later than it saves now.
  3. 3Look at what your dashboards join. Different sources, different original purposes, different controllers, linked to analyse people, is item 9 in its own words.
  4. 4Where the answer is unsure, treat it as unsure rather than as no. An assessment that records an open question is worth more than one that resolves it in your favour by default.
  5. 5If the assessment says the residual risk is still high, start the Article 36 consultation early. It can take fourteen weeks.

Sources

  1. 1.Data protection impact assessments, and the Article 35(4) list · Data Protection Commission
  2. 2.The DPC's list of processing operations requiring a DPIA · Data Protection Commission
  3. 3.Guidelines on Data Protection Impact Assessment, WP248 rev.01 · Article 29 Working Party, endorsed by the EDPB
  4. 4.Opinion 11/2018 on the draft Irish list · European Data Protection Board
  5. 5.Regulation (EU) 2016/679, Articles 35 and 36 · EUR-Lex, Publications Office of the European Union

Free, and the answers stay in your browser

Run the Irish list against what you do

Nine questions, each one an item from the DPC's own list in the words a business owner would use. It says whether an assessment is mandatory, and it says which items it left out and why. The answers stay in your browser.

Run the free check

If the screening says yes

We write the assessment from what the systems actually do rather than from a template, which means the description of the processing is accurate enough to be worth having. Where the honest conclusion is that the risk is low, the document says that and stops.

DPIA and AI risk assessment

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on GDPR and the DPC, for Irish businesses

Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.