All news
Regulation September 11, 2026 6 min

DPIA in Poland: when it is mandatory and what it must contain

Art. 35 GDPR, the Polish authority's list of 17 June 2019 and the nine WP248 criteria — how to check whether an impact assessment is required, before someone asks for it once the system is already running

TL;DR

A DPIA is mandatory before processing starts where a high risk is likely. The Polish authority's list (M.P. 2019 item 666) sets out twelve categories of operations. WP248 gives nine criteria: meeting two usually means an assessment is due. If the risk stays high, Art. 36 requires consulting the authority before going live.

The most common mistake is not about content, it is about timing

Art. 35(1) leaves no room: the assessment is carried out PRIOR to the processing. In practice a DPIA is usually written once the system is already running and somebody — a client, an auditor, the authority — asks for one. A document written afterwards can be substantively correct and still fail to discharge the duty, because the assessment exists to decide whether to proceed, not to justify having proceeded. The difference is visible in the document's date, and no later rewriting fixes it.

The authority's list and the WP248 criteria are two different tools

The communication of the President of the Polish DPA of 17 June 2019, published in Monitor Polski (M.P. 2019 item 666), contains a list of twelve categories of processing operations requiring an assessment, with examples. The list is not the only reference point: alongside it sit the Art. 29 Working Party guidelines (WP248 rev.01), endorsed by the EDPB, setting out nine criteria — evaluation or scoring, automated decisions with legal effect, systematic monitoring, special category data, large-scale processing, matching or combining datasets, vulnerable data subjects, innovative use of technology, and preventing data subjects from exercising a right or using a service. Meeting two of them usually means a DPIA is due.

  • The authority's list works in one direction only: if the operation is on it, a DPIA is required. If it is not on it, that does not mean one is not.
  • Art. 35(7) fixes the minimum content: a systematic description of the operations and purposes, an assessment of necessity and proportionality, an assessment of the risks to rights and freedoms, and the measures envisaged to address them.
  • Art. 35(9): the controller seeks the views of data subjects or their representatives, unless that is impossible or would prejudice commercial interests. The absence of consultation must be reasoned, not silent.
  • Art. 36: if the risk remains high despite the measures, the authority must be consulted before processing begins. The response period is eight weeks, extendable by six.

A template is a starting point, not the finished document

A DPIA template describes a structure, not your processing. An assessment nobody adapted to the actual data categories, scale and technology is recognisable at a glance and weak in any dispute: it contains nothing that could not have been written without knowing the organisation. A template saves an hour of formatting, not the analysis.

Art. 35(11) also applies: the assessment must be reviewed when the risk changes. A change of provider, a new module, a transfer outside the EEA can each invalidate a two-year-old DPIA. It is not an archive document: it is the living record of a decision.

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free