[{"data":1,"prerenderedAt":14},["ShallowReactive",2],{"article:en:the-gdpr-impact-assessment-for-a-software-company-the-three-cases-of-article-35-3-the-nine-criteria-behind-them-the-four-elements-of-article-35-7-and-a-page-that-writes-it":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"answer":9,"body":13},"en","the-gdpr-impact-assessment-for-a-software-company-the-three-cases-of-article-35-3-the-nine-criteria-behind-them-the-four-elements-of-article-35-7-and-a-page-that-writes-it","The GDPR impact assessment for a software company: the three cases of Article 35(3), the nine criteria behind them, the four elements of Article 35(7), and a page that writes it","Article 35 requires a data protection impact assessment before any processing likely to result in a high risk, and names three cases where it is required in any event. Which product features fall into them, the nine criteria the supervisory authorities apply and the rule that two of them usually mean an assessment, the lists the authorities publish under Article 35(4) and (5), the four elements the assessment must contain, the data protection officer's advice and the data subjects' views, the prior consultation of Article 36 with its eight weeks, and the review when the risk changes. With the free page that decides whether one is due and writes it.","2026-09-12",{"who":10,"when":11,"do":12},"Every software company as controller of a processing it designs: a scoring, ranking or screening feature, behavioural analytics, tracking, an AI feature, large-scale special-category data or monitoring of a public area; the processor supports the assessment but does not owe it (Article 28(3)(f)).","Before the processing starts (Article 35(1)), reviewed when the risk changes (Article 35(11)); where a high residual risk remains, the supervisory authority is consulted first and answers within eight weeks, extendable by six (Article 36).","Answer the three questions of Article 35(3) on the free page, then the Article 35(1) question where none applies; if an assessment is due, write its four elements there, element by element, and keep it on the record of processing it belongs to.","\nThe data protection impact assessment is the GDPR document a software company writes last and should write first: it is due before the processing starts, it is the place where the product's riskiest feature is described in the Regulation's own terms, and it is what the supervisory authority reads when a complaint names that feature. This article reads Article 35 point by point for a company that builds software and hands you the [page that decides whether one is due and writes it](\u002Fgdpr\u002Fimpact-assessment).\n\n## When one is due: Article 35(1) and the three named cases\n\nArticle 35(1) requires an assessment where a type of processing, in particular using new technologies, and taking into account its nature, scope, context and purposes, is likely to result in a high risk to the rights and freedoms of natural persons. Article 35(3) then names three cases where it is required in any event: (a) a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; (b) processing on a large scale of the special categories of Article 9(1) or of criminal data under Article 10; (c) a systematic monitoring of a publicly accessible area on a large scale.\n\nFor a software company the first case is the one that catches product features: a candidate ranking, a credit or fraud score, an automated eligibility check, a content or account decision taken by a model. It is a systematic and extensive evaluation whether or not anyone calls it profiling, and it turns the assessment on. The second catches health, biometric and similar data at scale, the third public video and sensor analytics.\n\n## The nine criteria behind \"likely to result in a high risk\"\n\nOutside the three cases, \"likely to result in a high risk\" is read with the guidelines the Article 29 Working Party adopted and the European Data Protection Board endorsed, which give nine criteria: evaluation or scoring; automated decision-making with legal or similar effect; systematic monitoring; sensitive data or data of a highly personal nature; data processed on a large scale; matching or combining datasets; data concerning vulnerable data subjects; innovative use or applying new technological or organisational solutions; and processing that prevents data subjects from exercising a right or using a service or contract. The guidelines' rule of thumb is that a processing meeting two of the criteria will in most cases require an assessment, and that one criterion can be enough.\n\nArticle 35(4) requires each supervisory authority to publish a list of the kinds of processing subject to the assessment, and Article 35(5) lets it publish a list of kinds that are not; the lists differ by member state, and the one of your lead authority is the one to read. Product analytics that combines usage data with account data, an AI feature applied to customer content, and any tracking of users across services score on several of the nine, and a company that ships those features is usually inside the assessment before it reaches the named cases.\n\n## The four elements: Article 35(7)\n\nThe assessment contains at least: (a) a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; (b) an assessment of the necessity and proportionality of the processing operations in relation to the purposes; (c) an assessment of the risks to the rights and freedoms of data subjects; (d) the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance, taking into account the rights and legitimate interests of data subjects and other persons concerned.\n\nTwo further paragraphs shape the document. Article 35(2) requires the controller to seek the advice of the data protection officer where one is designated, and Article 35(9) requires it, where appropriate, to seek the views of data subjects or their representatives on the intended processing. Article 35(8) lets compliance with approved codes of conduct count in the assessment. Element (d) is where the assessment meets the security programme: the measures are the ISO 27001 controls and the ISO 27701 privacy controls the company already runs, named per risk rather than in general, and the [page that writes the assessment](\u002Fgdpr\u002Fimpact-assessment) labels each element with the point of Article 35(7) it answers.\n\n## Prior consultation: Article 36\n\nWhere the assessment indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk, Article 36(1) requires the controller to consult the supervisory authority before the processing. Article 36(2) gives the authority eight weeks to provide written advice, extendable by six weeks taking into account the complexity of the processing, and lets it use any of its powers under Article 58. Article 36(3) lists what the consultation provides: the responsibilities of the controller, joint controllers and processors, the purposes and means, the measures and safeguards, the officer's contact details, the assessment itself, and anything else the authority requests. In practice the consultation is rare, because element (d) is written to bring the residual risk down; the page asks the residual-risk question last and writes the Article 36 paragraph only when the answer is that a high risk remains.\n\n## The review, and the fine\n\nArticle 35(11) requires the controller to review the assessment where necessary, at least when there is a change of the risk represented by the processing operations; a new model, a new data source or a new purpose is such a change. Article 83(4)(a) sets the ceiling for a breach of Articles 35 and 36 at EUR 10 million or 2% of worldwide annual turnover, and the authorities' decisions on the assessment turn on two findings: whether one existed before the processing started, and whether its element (d) named measures that were then actually run.\n\n## Writing it\n\nThe [impact assessment page](\u002Fgdpr\u002Fimpact-assessment) asks the three questions of Article 35(3) in the Regulation's own words, then the Article 35(1) question where none applies, writes the reading with the provision behind it, and takes the four elements as inputs labelled with the point itself; the residual-risk question decides whether the Article 36 paragraph is added. The result is the assessment as a document to copy or download, one per processing activity, kept next to the [record of processing](\u002Fgdpr\u002Frecord-of-processing) that describes the activity; the [duties determination](\u002Fgdpr\u002Fduties) hands its three answers over so the questions are asked once.\n",1789383984603]