GDPR
Do you need a DPIA? Ireland has its own list, and it is specific
Most guidance answers this with European criteria. Ireland has a published list of its own, and it is the one that decides the question here.
By Oscar CobbeCurrent as at 10 minute read5 sources
Where the obligation comes from
Article 35(1) of the GDPR requires a data protection impact assessment where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons, and it requires it before the processing starts.
Article 35(3) names three cases where one is required regardless: a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal or similarly significant effects; processing on a large scale of special category data or of criminal conviction and offence data; and systematic monitoring of a publicly accessible area on a large scale.
Article 35(4) then lets each supervisory authority publish its own list of processing operations that require one. The Data Protection Commission has done that, and its list is what settles the question for an Irish controller.
The Irish list, and the sentence in front of it
The DPC's list has ten items. It carries a condition at the top that is routinely dropped when the list is reproduced, and the condition is doing real work: the ten apply where a documented screening or preliminary risk assessment indicates that the processing operation is likely to result in a high risk.
So the list does not fire by itself. Something has to indicate the risk first, and that something is a screening. Which is exactly why a screening is the honest first step and why it can be automated when a full assessment cannot.
The items are quoted below rather than paraphrased. Paraphrasing a statutory list is how a check ends up telling somebody they are clear when the regulator's own words say otherwise.
| Item | What the DPC's list says, shortened |
|---|---|
| 1 | Using personal data on a large scale for a purpose other than the one it was collected for, under Article 6(4) |
| 2 | Profiling vulnerable persons including children to target marketing or online services at them |
| 3 | Profiling, algorithmic means or special category data used to determine access to services, or producing legal or similarly significant effects |
| 4 | Systematically monitoring, tracking or observing individuals' location or behaviour |
| 5 | Profiling individuals on a large scale |
| 6 | Biometric data used to identify or authenticate a person, in combination with another WP29 criterion |
| 7 | Genetic data, in combination with another WP29 criterion |
| 8 | Indirectly sourced personal data where transparency requirements are not being met |
| 9 | Combining or cross-referencing separate datasets where the linking contributes to profiling or behavioural analysis |
| 10 | Large scale processing where the Data Protection Act 2018 requires suitable and specific measures |
The two that catch ordinary businesses
Items 4 and 9 are the ones worth reading twice, because between them they describe a normal marketing setup rather than anything exotic.
Item 4 is systematically monitoring, tracking or observing individuals' location or behaviour. That is what an advertising pixel does. It is what session recording and heatmaps do. Aggregate visitor counts are not it; anything tied to an identifier that follows a person between pages or between visits is.
Item 9 is combining, linking or cross-referencing separate datasets where such linking significantly contributes to or is used for profiling or behavioural analysis of individuals, particularly where the datasets are combined from different sources where processing was carried out for different purposes or by different controllers. That is what a joined-up dashboard does when it puts an ad platform, an analytics property and a payment processor on the same customer.
We should say plainly that the second one describes work we sell. The reporting product this company builds joins exactly those sources. If the join is used for behavioural analysis of individuals rather than for totals, item 9 is engaged, and it is better that you read that here than hear it from a client's solicitor.
Two of the ten do not stand on their own
Items 6 and 7 end with the words in combination with any of the other criteria set out in WP29 DPIA Guidelines. A five-person shop with a fingerprint clocking-in machine and nothing else on the list has not triggered a mandatory DPIA on item 6 alone. Read literally the other way round, that item would put half the small employers in the country into an assessment they do not owe.
What the European guidance adds, and what it does not
The Article 29 Working Party's guidelines, WP248 rev.01, endorsed by the European Data Protection Board, set out nine criteria: evaluation or scoring; automated decision-making with legal or similar significant effect; systematic monitoring; sensitive data or data of a highly personal nature; data processed on a large scale; matching or combining datasets; vulnerable data subjects; innovative use of new technologies; and processing that prevents data subjects from exercising a right or using a service or a contract.
The rule of thumb attached to those is quoted much more firmly than it was written. What WP248 actually says is that in most cases a controller can consider that processing meeting two criteria would require a DPIA. Can consider, not must. It is a heuristic, and a single criterion can be enough where the risk is high.
For an Irish controller the ordering is: the DPC's list first, because it is the Article 35(4) instrument that binds here; the WP29 criteria second, as the analysis that fills the gaps.
What happens if the assessment says the risk is still high
Article 36(1) requires prior consultation with the supervisory authority where the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate it. In other words, you consult where your own assessment says you cannot get the risk down, not merely because a DPIA was needed.
The timing under Article 36(2) is worth knowing before anybody plans a launch around it. The authority provides written advice within a period of up to eight weeks of receiving the request, and that period may be extended by six weeks. The extension has to be notified within one month of receipt, and the clock can be suspended while the authority waits for information it has asked for.
Fourteen weeks, in the worst case, before you get an answer. That is the argument for doing the screening early rather than the week before go-live.
What a DPIA is not
It is not a form, and it is not a document you buy. Article 35(7) sets the minimum contents: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to data subjects, and the measures you propose to address them.
It is also not the same as a lawful basis. An assessment that concludes the risk is manageable does not supply a legal ground for the processing, and neither does the fact that nobody objected.
And it is not required for everything. A great deal of ordinary business processing, including payroll, order fulfilment and a customer list used for the thing it was collected for, sits outside the list and outside Article 35(3). The most common outcome of an honest screening is that no assessment is mandatory.
Where this connects to everything else
Three of the questions on this site end up back here. Automated decisions about job candidates engage item 3 about as clearly as the wording allows. Automating a process that moves personal data between systems frequently engages item 1 or item 9. And a privacy notice describes processing that sometimes needed an assessment before it started, which is an awkward thing to discover while writing the notice.
The AI Act connection runs the other way from how it is usually presented. Article 27 of the AI Act, the fundamental rights impact assessment, does not bind most private businesses. Article 35 of the GDPR binds anybody whose processing is on the list, has done since 2018, and is enforced by a regulator with a published decision record.
What to do about it
The order that answers the cheapest question first.
- 1Do the screening and keep it. The DPC's list is conditional on a documented screening, so the screening is not a preliminary to the obligation, it is part of it.
- 2Answer honestly about tracking. If there is an advertising pixel on the site, item 4 is in play and pretending otherwise costs more later than it saves now.
- 3Look at what your dashboards join. Different sources, different original purposes, different controllers, linked to analyse people, is item 9 in its own words.
- 4Where the answer is unsure, treat it as unsure rather than as no. An assessment that records an open question is worth more than one that resolves it in your favour by default.
- 5If the assessment says the residual risk is still high, start the Article 36 consultation early. It can take fourteen weeks.
Sources
- 1.Data protection impact assessments, and the Article 35(4) list · Data Protection Commission
- 2.The DPC's list of processing operations requiring a DPIA · Data Protection Commission
- 3.Guidelines on Data Protection Impact Assessment, WP248 rev.01 · Article 29 Working Party, endorsed by the EDPB
- 4.Opinion 11/2018 on the draft Irish list · European Data Protection Board
- 5.Regulation (EU) 2016/679, Articles 35 and 36 · EUR-Lex, Publications Office of the European Union
Free, and the answers stay in your browser
Run the Irish list against what you do
Nine questions, each one an item from the DPC's own list in the words a business owner would use. It says whether an assessment is mandatory, and it says which items it left out and why. The answers stay in your browser.
Run the free checkIf the screening says yes
We write the assessment from what the systems actually do rather than from a template, which means the description of the processing is accurate enough to be worth having. Where the honest conclusion is that the risk is low, the document says that and stops.
DPIA and AI risk assessmentWho wrote this
Oscar Cobbe · Founder, FourWinds Digital
Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.
More about how we work →Read next
Automation
Automating something that touches personal data: what has to be written down
The build is the easy half. What decides whether it survives a complaint is the five things that should have been written down before it went live.
GDPR
AI in hiring: the rule that is already in force
Article 22 has applied since May 2018. If software rejects candidates and no person really decides, the rules that bite are the data protection ones.
GDPR
Does a small Irish business website need a privacy notice?
We fetched 82 Irish business websites in one week. Thirty-four had no privacy notice at any of the usual addresses, and three had one that nothing on the site linked to.
Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.