The GDPR requires a Data Protection Impact Assessment for any processing likely to result in a high risk to the rights and freedoms of individuals. SYAGA DPIA-Express structures and documents your DPIA according to the Article 35 methodology and the EDPB guidelines, without improvisation and without jargon.
Determine whether your processing must undergo a DPIA, then conduct it by the book
Any processing likely to result in a high risk to the rights and freedoms of natural persons must undergo a Data Protection Impact Assessment before its implementation (GDPR, art. 35).
The EDPB (formerly the Article 29 Working Party, WP29), in its guidelines WP248 rev.01, defined 9 high-risk criteria. As soon as a processing operation meets at least two of these criteria, a DPIA must in principle be carried out: a single misjudged criterion, and the file is incomplete.
The CNIL (the French data protection authority) publishes lists of processing operations for which a DPIA is required or not required. Determining precisely where your processing falls requires a rigorous reading, not a general impression.
Conducting a DPIA too hastily exposes you to incompleteness before a supervisory authority; not conducting one when required exposes the organisation to a breach of Article 35. The CNIL method structures this decision and documents it.
The structure required by Article 35.7 of the GDPR, applied to your processing, with a reasoned conclusion at every step
Analysis against the 3 cases of Article 35.3, the EDPB's 9-criteria grid (WP248 rev.01), and the CNIL lists of required and non-required processing. Reasoned conclusion, whether the DPIA is ultimately mandatory or not.
Purposes, categories of data and data subjects, recipients, retention periods: the complete mapping required by Article 35.7.a, consistent with your record of processing activities (art. 30).
Verification that each piece of data collected is necessary for the purpose pursued, that the legal basis (art. 6) is identified for each processing operation, and that the data minimisation principle (art. 5.1.c) is respected.
For each identified risk: severity, likelihood, measures already in place, residual risk, presented as a table usable by your management or your DPO.
Technical and organisational measures envisaged (art. 32), reasoned conclusion and documented justification under the accountability principle (art. 5.2), ready for use in the event of a CNIL inspection.
A structured, sourced document, honest about what still needs validation by your lawyer or your DPO
The complete document following Article 35.7 (a to d), with a reasoned conclusion.
The preliminary analysis that decides whether your processing falls within the scope of the obligation.
The DPIA relies on the same foundation as your record of processing activities.
Every point of uncertainty is explicitly flagged, never decided on your behalf.
Every legal statement is sourced, not stated from memory.
Delivered in an editable format, reusable by your DPO or your lawyer.
A method based on texts and authorities, not on in-house interpretations
Data protection impact assessment. Consolidated text of Regulation (EU) 2016/679 (EUR-Lex, CELEX 32016R0679).
The EDPB's (formerly Article 29 Working Party) 9 high-risk criteria, adopted by the CNIL as the reference method for determining the DPIA obligation.
Lists of processing operations for which a DPIA is required or not required, and the CNIL method for conducting an impact assessment.
Record of processing activities: the consistency foundation (purposes, data, retention periods) on which every DPIA relies.
The scope depends on the number of processing operations, their complexity, and what is already documented on your side. Quote established after an initial discussion.
You don't know whether your processing is concerned
Processing identified as high risk
Several at-risk processing operations to cover
A DPIA is never set in stone
Article 35.11 of the GDPR requires the analysis to be reviewed in the event of a significant change to the processing (new processor, hosting change, extension of the collection scope). A review quote is established on a case-by-case basis.
What the text really says, digested in plain language. Every point keeps its link to the official document.
A DPIA is simply an assessment exercise: it looks at the risks a data processing activity poses to individuals, before it is put in place. The CNIL defines it as "a formal process for assessing the risks related to the processing of personal data". It is not just another administrative formality, it is a common-sense tool made mandatory by the GDPR in certain cases. Source: CNIL →
You do not need to be a large company to be concerned. The CNIL considers a DPIA mandatory as soon as a processing activity meets at least two of these nine situations: scoring or evaluating people, making an automated decision that has a real effect on them, systematically monitoring them, collecting sensitive data (health, origin, etc.), collecting on a large scale, cross-referencing several databases, targeting vulnerable people (employees, patients, minors...), using new technology, or depriving someone of a right or a service. Source: CNIL →
To avoid guesswork, the CNIL has published two official lists: a list of 14 types of processing where a DPIA is mandatory (health data, HR profiling, employee monitoring, large-scale geolocation...), and a list of 12 types where it is not required (payroll and personnel management for fewer than 250 employees excluding profiling, supplier management, the patient file of a sole-practice health professional...). These lists do not cover every case, but they already answer many common situations. Source: CNIL list of processing requiring a DPIA →
The GDPR (Article 35) does not ask for a novel, but four precise building blocks: describe the processing and its purpose, verify that it is genuinely necessary and proportionate, assess the risks to the individuals concerned, then list the measures planned to reduce those risks. A clear conclusion at the end: is the processing acceptable, and under what conditions. Source: GDPR, Article 35 →
If your organization has appointed a Data Protection Officer, the GDPR requires that they be consulted when conducting the DPIA, and tasked with verifying that the analysis has actually been carried out. It is a safeguard, not a box to tick: the DPO remains the right reflex before validating a conclusion. Source: GDPR, Articles 35 and 39 →
If, despite the planned measures, the processing still presents a high risk to individuals, the GDPR requires consulting the CNIL before starting. It then has eight weeks to give its written opinion (extendable by six weeks if the file is complex). Reassuring to know: this case remains the exception, not the rule. Source: GDPR, Article 36 →
The CNIL reminds us that GDPR fines can reach up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. This is a legal ceiling, not an inevitability: a well-conducted DPIA is precisely what allows you to show, in the event of an inspection, that the matter was taken seriously. Source: CNIL →
The European Data Protection Board (EDPB) held a public consultation, from 14 April to 9 June 2026, on a draft single DPIA template intended to harmonize practices between European countries. The consultation is now closed; we are following up on this project to inform our clients in due course. Source: EDPB →
Before knowing how to do a DPIA, you need to know if you are concerned. Here is the exact scope, as defined by the GDPR and the CNIL, without unnecessary suspense.
The GDPR sets no headcount threshold for the DPIA obligation. Its Article 35 imposes this analysis on the "data controller", whatever its form (association, sole trader, SME, local authority, large group), as soon as a processing activity "is likely to result in a high risk to the rights and freedoms of natural persons". A common trap to avoid: the 250-employee threshold does exist in the GDPR, but it concerns a partial exemption from the record of processing activities (Article 30), not the DPIA. A company with 5 employees may be concerned; a group with 2000 employees may not be: it all depends on the processing, never on the size of the organization. Source: GDPR, Article 35 (as reproduced by the CNIL) →
Article 35 targets the "data controller" in the broad sense: a private company as much as a public administration, a local authority, an association or a healthcare institution. The text even explicitly covers the case of "systematic monitoring of a publicly accessible area on a large scale", which typically applies to a town hall or a social housing provider installing video surveillance on public roads, not just a commercial company. Source: GDPR, Article 35, paragraph 3 →
The CNIL and the former Article 29 Working Party (now the European Board, EDPB) set out nine reference criteria in their guidelines (WP248). As soon as a processing activity meets at least two of them, a DPIA becomes mandatory: scoring or evaluating people, automatically deciding something that affects them, systematically monitoring them, processing sensitive data, processing on a large scale, cross-referencing files, targeting vulnerable people (employees, patients, minors), using new technology, or depriving someone of a right or a contract. Source: CNIL, G29/EDPB guidelines (WP248) →
In practice, CNIL doctrine typically links these criteria to: a medical practice or clinic processing health data on a large scale, an HR department using a scoring or profiling tool for employees, a company equipped with badges and systematic video surveillance of its premises open to the public, a credit or debt-collection organization practicing scoring, or a connected health device collecting lifestyle habit data. Source: CNIL, list of 14 processing activities requiring a mandatory DPIA →
The CNIL has also published a list of 12 types of processing for which a DPIA is NOT required: for example payroll and personnel management for an organization with fewer than 250 employees (excluding profiling), the patient file of a sole-practice health professional, or routine supplier management. Reassuring for many small businesses: having employees or clients is not, on its own, enough to trigger the obligation. Source: CNIL, list of 12 processing activities without a DPIA →
No lawyer jargon: simple answers, each backed by the official text it is based on.
The dates that really matter, sourced, so you know what is already mandatory today and what is coming.
The GDPR has been applicable since 25 May 2018, across Europe. The DPIA obligation (Article 35), the two CNIL lists that state when it is mandatory or not, and the European guidelines explaining how to conduct it: all of this is in force, stable, and does not depend on any upcoming reform. This is the foundation you can rely on right now.
The European Data Protection Board (EDPB) is working on a single DPIA template to harmonize practices between European countries. The public consultation on this project ended on 9 June 2026; no publication date for the final template has yet been announced. There is no need to wait: the CNIL method remains valid in the meantime.
The European Parliament and the Council adopt Regulation 2016/679 on 27 April 2016. It is published in the Official Journal of the European Union (OJ L119) on 4 May 2016, then enters into force twenty days later, on 24 May 2016, without yet being applicable. Source: EUR-Lex, official reference of the regulation →
Two years after its adoption, the regulation finally applies across Europe (Article 99.2). This is the day the DPIA obligation under Article 35 becomes enforceable, and the European Data Protection Board (EDPB) is set up for the first time, taking over the DPIA guidelines already drafted (WP248 rev.01). Source: EUR-Lex, regulation record (Article 99) → Source: EDPB, adopted guidelines →
A few months after the GDPR entered into application, the CNIL adopts decision no. 2018-327: a concrete list of 14 types of processing (health data, HR profiling, employee monitoring...) for which a DPIA must systematically be carried out. No more guessing case by case. Source: CNIL →
A year later, the CNIL completes its doctrine with decision no. 2019-118: a list of processing activities for which a DPIA is NOT required (payroll for fewer than 250 employees excluding profiling, supplier management, the patient file of a sole-practice professional...). Together, the two CNIL lists already answer many common situations without having to decide for yourself. Source: CNIL →
The EDPB held a public consultation on a draft common DPIA template, intended to harmonize practices between European countries (today, each national authority has its own somewhat different framework). The consultation has been closed since 9 June 2026; it is not yet an applicable text, just a draft under review. Source: EDPB →
The EDPB itself states that the template "will be finalized, subject to appropriate amendments", after which national authorities will begin the process of adopting it as a single template, or as a "meta-model" compatible with existing templates (including the CNIL's). No date has been announced to date: we are following this matter to inform our clients as soon as there is anything concrete, without anticipating anything. Source: EDPB →
Who sanctions, how much, and on what criteria. Without overdramatizing: the vast majority of cases have nothing to do with the amounts that make headlines.
It is a specialized body of the CNIL, distinct from the board that carries out day-to-day inspections and advice, that issues sanctions. It has several graduated tools, not just fines: formal notice, warning, order to comply (with or without a financial penalty), injunction, temporary or permanent limitation of processing. The fine is only the last rung of the ladder. Source: CNIL, sanctions issued →
The GDPR (Article 83) sets two ceilings, with the higher of the two applying: up to 10 million euros or 2% of worldwide turnover of the previous financial year for breaches of organizational obligations (security, records, DPO, impact assessment...); up to 20 million euros or 4% for breaches of substantive principles (legal basis, consent, individuals' rights, transfers outside the EU). These are ceilings, not automatic amounts. Source: GDPR, Article 83 →
Article 83.2 requires the authority to take into account: the gravity and duration of the breach, whether it was intentional or merely negligent, the measures already taken to limit the damage, the degree of responsibility, prior history, cooperation with the authority, and the sensitivity of the data concerned. In practice: an organization that has documented its approach (records, DPIA, security measures) and cooperates is judged differently from one that has done nothing. Source: GDPR, Article 83.2 →
On 10 November 2022, the CNIL's restricted committee issued a fine of 800,000 euros against Discord. Among the breaches found: an excessive retention period, a security failure, and Article 35 of the GDPR, the absence of an impact assessment even though the processing, being large-scale and involving minors, required one. This is the most direct example of the link between "no documented DPIA" and a sanction being issued. Source: decision SAN-2022-020, Légifrance →
Criteo was fined 40 million euros on 15 June 2023, for failing to demonstrate valid consent for placing advertising cookies. Clearview AI was fined 20 million euros on 17 October 2022, for a massive collection of photos without a legal basis. These amounts concern very large-scale international processing operations, not the case of an SME that documents its approach. Source: decision SAN-2023-009, Légifrance →
On the same official CNIL page listing decisions, a significant share of published sanctions are counted in thousands of euros, not millions: an advertising agency fined 3,000 euros, two doctors fined 3,000 and 6,000 euros, a meal-delivery service fined 20,000 euros. The sanction is proportionate to the size and severity, not a uniform cutoff. Source: CNIL, sanctions issued →
What to remember
A well-conducted DPIA does not make an organization untouchable: it constitutes proof, in the event of an inspection, that the matter was taken seriously. This is precisely what Article 83.2 of the GDPR requires to be taken into account when setting, or not setting, a fine.
In Europe, each country has its own authorities. Here, for the 30 countries of the European Economic Area, is the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official website.
Sources: official authority websites and the EDPB members list (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to be confirmed" notes indicate an official source not yet stabilized as of this date.
Describe your processing to us, and we'll get back to you with a tailored quote.
Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.
contact@syaga.eu Revisit the CNIL method