Mapping DPIA requirements across 8 European authorities, LGPD Brazil, AI Act and sector-specific laws.
GDPR establishes that DPIA is mandatory when processing is likely to result in high risk (Article 35(3)).
EDPB in WP248 defined 9 cumulative criteria indicating mandatory DPIA:
If any one of these criteria applies, DPIA is mandatory under GDPR.
Each supervisory authority issued an indicative list of categories requiring DPIA. Requirements vary by jurisdiction.
| Authority | Jurisdiction | Mandatory Categories |
|---|---|---|
| CNPD | Portugal | International transfers; automated decisions; sensitive data; minors; surveillance; AI; biometrics |
| CNIL | France | Sensitive data processing; automated decisions; minors; video surveillance; cookie analytics; cross-border cloud services |
| BfDI | Germany | Large-scale processing; sensitive data; surveillance; automated decisions with legal effects; intra-group transfers |
| ICO | United Kingdom | Systematic and extensive processing; surveillance; automated decision-making; sensitive data; post-Brexit transfers; UK GDPR compliance |
| Garante | Italy | Sensitive data (Article 9); automated decisions (Article 22); surveillance; biometrics; AI; minors |
| AEPD | Spain | Large-scale processing; surveillance; AI; profiling; sensitive data; minors; international transfers |
| APD | Belgium | Sensitive data; surveillance; automated decisions; international transfers; AI; biometrics; large-scale processing |
| AP / DPA | Netherlands | Systematic and extensive processing; surveillance; automated decision-making; special category data; AI; biometrics; minors |
For multinational operations, integrate requirements of all 8 authorities in a single DPIA. This avoids incomplete compliance, rework and divergences.
The United Kingdom left the EU in January 2020. UK GDPR originated from GDPR, but divergences have emerged.
Brazil implemented the General Data Protection Law (LGPD) in 2020 and the Resolution on International Transfers (RIPD).
Consult P06 — CPLP Markets for deeper insight on LGPD and interoperability with GDPR.
The AI Act (EU, in force since January 2025) requires DPIA for high-risk AI systems, often in cross-border operations.
Use this checklist to self-assess if you need multi-jurisdictional DPIA.
Yes → Proceed to next question. No → Domestic DPIA may suffice (consult CNPD for Portugal).
Yes → MANDATORY DPIA + TIA (Transfer Impact Assessment). Schrems II applies if transfer includes US.
Yes → MANDATORY multinational DPIA across all 8 European authorities listed.
Yes → MANDATORY DPIA + FRIA + AI Act Article 27. Multinational DPIA if AI is cross-border.
Yes → MANDATORY DPIA. If multinational transfers, requires harmonisation of protections per jurisdiction (consent age varies by country).
Yes → MANDATORY DPIA. If video data is stored internationally, requires multinational TIA.
Yes → MANDATORY DPIA. Especially if scoring has cross-border effects (credit access, employment, insurance).
Outcome: You Need Multi-Jurisdictional DPIA
If you answered "Yes" to any question above, we recommend integrated multinational DPIA with DPO involvement and legal experts per jurisdiction.
DPIA execution is mandatory. Lack of compliance carries substantial risks.
For the Portuguese domestic context, consult complete CNPD guidance.
aipd.pt/obrigatoriedade — Official CNPD criteria for when DPIA is mandatory in Portugal.
Deepen with multinational methodology and contact us for implementation.
Methodology for Multinationals →Send a brief message and we'll respond within 24 hours.