Structured, sourced documentary assistance. This service does not constitute legal advice: the legally binding aspects require a qualified professional (lawyer, DPO or certified auditor).
GDPR - ARTICLE 35 - DATA PROTECTION IMPACT ASSESSMENT (DPIA)

Your DPIA compliant
with the CNIL method

The GDPR requires a Data Protection Impact Assessment for any processing likely to result in a high risk to the rights and freedoms of individuals. SYAGA DPIA-Express structures and documents your DPIA according to the Article 35 methodology and the EDPB guidelines, without improvisation and without jargon.

35
GDPR article (DPIA)
9
EDPB criteria (WP248 rev.01)
3
Cases of obligation (art. 35.3)
4
Method components (art. 35.7 a-d)

The obligation

Determine whether your processing must undergo a DPIA, then conduct it by the book

GDPR Article 35 requires a DPIA

Any processing likely to result in a high risk to the rights and freedoms of natural persons must undergo a Data Protection Impact Assessment before its implementation (GDPR, art. 35).

📋

The CNIL "2 out of 9 criteria" rule

The EDPB (formerly the Article 29 Working Party, WP29), in its guidelines WP248 rev.01, defined 9 high-risk criteria. As soon as a processing operation meets at least two of these criteria, a DPIA must in principle be carried out: a single misjudged criterion, and the file is incomplete.

🔍

CNIL lists to check article by article

The CNIL (the French data protection authority) publishes lists of processing operations for which a DPIA is required or not required. Determining precisely where your processing falls requires a rigorous reading, not a general impression.

Without method, the risk is twofold

Conducting a DPIA too hastily exposes you to incompleteness before a supervisory authority; not conducting one when required exposes the organisation to a breach of Article 35. The CNIL method structures this decision and documents it.

The method: DPIA-Express

The structure required by Article 35.7 of the GDPR, applied to your processing, with a reasoned conclusion at every step

1
Determining the obligation

Is your processing really subject to a DPIA?

Analysis against the 3 cases of Article 35.3, the EDPB's 9-criteria grid (WP248 rev.01), and the CNIL lists of required and non-required processing. Reasoned conclusion, whether the DPIA is ultimately mandatory or not.

2
Art. 35.7.a

Systematic description of the processing

Purposes, categories of data and data subjects, recipients, retention periods: the complete mapping required by Article 35.7.a, consistent with your record of processing activities (art. 30).

3
Art. 35.7.b

Necessity and proportionality

Verification that each piece of data collected is necessary for the purpose pursued, that the legal basis (art. 6) is identified for each processing operation, and that the data minimisation principle (art. 5.1.c) is respected.

4
Art. 35.7.c

Assessment of risks to individuals

For each identified risk: severity, likelihood, measures already in place, residual risk, presented as a table usable by your management or your DPO.

5
Art. 35.7.d and 5.2

Measures and documented conclusion

Technical and organisational measures envisaged (art. 32), reasoned conclusion and documented justification under the accountability principle (art. 5.2), ready for use in the event of a CNIL inspection.

What you receive

A structured, sourced document, honest about what still needs validation by your lawyer or your DPO

📝

Structured DPIA report

The complete document following Article 35.7 (a to d), with a reasoned conclusion.

  • Systematic description of the processing
  • Necessity and proportionality analysis
  • Risk table (severity/likelihood/measures)
  • Conclusion and documented justification (art. 5.2)

Determination grid

The preliminary analysis that decides whether your processing falls within the scope of the obligation.

  • The 3 cases of Article 35.3
  • The 9 EDPB criteria (WP248 rev.01)
  • Comparison against the CNIL lists
  • Reasoned and sourced conclusion
📁

Consistency with the Article 30 record

The DPIA relies on the same foundation as your record of processing activities.

  • Purposes and legal bases
  • Categories of data and data subjects
  • Recipients and processors
  • Retention periods by category
🚩

Points for your lawyer/DPO to validate

Every point of uncertainty is explicitly flagged, never decided on your behalf.

  • Controller / processor qualification
  • Legal bases by purpose
  • Identified transfers outside the EU
  • Appointment of a DPO (art. 37), where applicable
🔗

Sources and traceability

Every legal statement is sourced, not stated from memory.

  • Consolidated GDPR text (CELEX 32016R0679)
  • CNIL pages and lists (DPIA, record)
  • EDPB guidelines (WP248 rev.01)
  • Verifiable URLs cited in the document
📄

Editable document

Delivered in an editable format, reusable by your DPO or your lawyer.

  • Structure compliant with Article 35.7
  • Reusable for your future processing operations
  • Ready to be completed before final validation
  • No fixed formatting imposed

References used

A method based on texts and authorities, not on in-house interpretations

35

GDPR - Article 35

Data protection impact assessment. Consolidated text of Regulation (EU) 2016/679 (EUR-Lex, CELEX 32016R0679).

EDPB

Guidelines WP248 rev.01

The EDPB's (formerly Article 29 Working Party) 9 high-risk criteria, adopted by the CNIL as the reference method for determining the DPIA obligation.

CNIL

CNIL lists and method

Lists of processing operations for which a DPIA is required or not required, and the CNIL method for conducting an impact assessment.

30

GDPR - Article 30

Record of processing activities: the consistency foundation (purposes, data, retention periods) on which every DPIA relies.

A tailored DPIA, with no hidden pricing

The scope depends on the number of processing operations, their complexity, and what is already documented on your side. Quote established after an initial discussion.

Determining the obligation

You don't know whether your processing is concerned

Quote on request
depending on the number of processing operations to analyse
  • EDPB 9-criteria grid
  • Comparison against Article 35.3
  • Verification of the CNIL lists
  • Reasoned and sourced conclusion
Request a quote

Multi-year programme

Several at-risk processing operations to cover

Quote on request
depending on the number of processing operations and review cadence
  • Everything in Full DPIA +
  • Common methodological framework
  • Periodic review (art. 35.11)
  • Consistency maintained with the record (art. 30)
Request a quote

A DPIA is never set in stone

Article 35.11 of the GDPR requires the analysis to be reviewed in the event of a significant change to the processing (new processor, hosting change, extension of the collection scope). A review quote is established on a case-by-case basis.

Frequently asked questions

Is my processing really subject to the DPIA obligation?
This depends on three elements checked methodically: the 3 cases of Article 35.3 of the GDPR, the EDPB's 9-criteria grid (guidelines WP248 rev.01, adopted by the CNIL: as soon as 2 out of 9 criteria are met, a DPIA must in principle be carried out), and the CNIL lists of required and non-required processing. The delivered document settles this question and justifies it, point by point.
What exactly does the delivered document contain?
A document structured according to Article 35.7 of the GDPR: systematic description of the processing (a), necessity and proportionality analysis (b), assessment of risks to data subjects (c), envisaged technical and organisational measures (d), then a reasoned conclusion. Every legal reference is sourced (consolidated GDPR text, CNIL, EDPB).
What if my processing turns out not to be subject to the DPIA obligation?
The document is kept on a voluntary, documentary basis: it constitutes the justification for your decision not to conduct a formal DPIA, under the accountability principle (art. 5.2 of the GDPR), ready for use in the event of a CNIL inspection.
Does this document replace the opinion of my lawyer or DPO?
No. DPIA-Express is a methodological support tool that structures and documents the analysis; it does not constitute legal advice. Every document delivered explicitly lists the points that still need to be validated by your lawyer or your Data Protection Officer before any binding use.
Who must carry out the DPIA within my organisation?
The controller remains legally responsible for the DPIA; the DPO, where one exists, must be consulted (art. 35.2 of the GDPR). DPIA-Express prepares the material (description, risks, measures) so that this consultation takes place on an already structured file, not a blank page.
Why go through SYAGA rather than doing it entirely in-house?
SYAGA Consulting has existed since 2009 and applies this same method to its own processing operations, including its own Microsoft 365 audit product, whose DPIA obligation analysis follows exactly this structure. We do not deliver a generic template: every document is built processing by processing, article by article.

Regulatory watch - official sources

What the text really says, digested in plain language. Every point keeps its link to the official document.

📋

What is a DPIA, in plain terms?

A DPIA is simply an assessment exercise: it looks at the risks a data processing activity poses to individuals, before it is put in place. The CNIL defines it as "a formal process for assessing the risks related to the processing of personal data". It is not just another administrative formality, it is a common-sense tool made mandatory by the GDPR in certain cases. Source: CNIL →

🎯

Who is really concerned: the "2 out of 9 criteria" rule

You do not need to be a large company to be concerned. The CNIL considers a DPIA mandatory as soon as a processing activity meets at least two of these nine situations: scoring or evaluating people, making an automated decision that has a real effect on them, systematically monitoring them, collecting sensitive data (health, origin, etc.), collecting on a large scale, cross-referencing several databases, targeting vulnerable people (employees, patients, minors...), using new technology, or depriving someone of a right or a service. Source: CNIL →

Two CNIL lists that often answer for you

To avoid guesswork, the CNIL has published two official lists: a list of 14 types of processing where a DPIA is mandatory (health data, HR profiling, employee monitoring, large-scale geolocation...), and a list of 12 types where it is not required (payroll and personnel management for fewer than 250 employees excluding profiling, supplier management, the patient file of a sole-practice health professional...). These lists do not cover every case, but they already answer many common situations. Source: CNIL list of processing requiring a DPIA →

🧩

What the analysis must actually contain

The GDPR (Article 35) does not ask for a novel, but four precise building blocks: describe the processing and its purpose, verify that it is genuinely necessary and proportionate, assess the risks to the individuals concerned, then list the measures planned to reduce those risks. A clear conclusion at the end: is the processing acceptable, and under what conditions. Source: GDPR, Article 35 →

👤

The role of your DPO (if you have one)

If your organization has appointed a Data Protection Officer, the GDPR requires that they be consulted when conducting the DPIA, and tasked with verifying that the analysis has actually been carried out. It is a safeguard, not a box to tick: the DPO remains the right reflex before validating a conclusion. Source: GDPR, Articles 35 and 39 →

And if the risk remains high after the analysis?

If, despite the planned measures, the processing still presents a high risk to individuals, the GDPR requires consulting the CNIL before starting. It then has eight weeks to give its written opinion (extendable by six weeks if the file is complex). Reassuring to know: this case remains the exception, not the rule. Source: GDPR, Article 36 →

💰

The penalties, without overdramatizing

The CNIL reminds us that GDPR fines can reach up to 10 million euros or 2% of worldwide annual turnover, whichever is higher. This is a legal ceiling, not an inevitability: a well-conducted DPIA is precisely what allows you to show, in the event of an inspection, that the matter was taken seriously. Source: CNIL →

📢

A European development to watch

The European Data Protection Board (EDPB) held a public consultation, from 14 April to 9 June 2026, on a draft single DPIA template intended to harmonize practices between European countries. The consultation is now closed; we are following up on this project to inform our clients in due course. Source: EDPB →

Who is really concerned by the DPIA?

Before knowing how to do a DPIA, you need to know if you are concerned. Here is the exact scope, as defined by the GDPR and the CNIL, without unnecessary suspense.

⚖️

The only criterion that matters: risk, not size

The GDPR sets no headcount threshold for the DPIA obligation. Its Article 35 imposes this analysis on the "data controller", whatever its form (association, sole trader, SME, local authority, large group), as soon as a processing activity "is likely to result in a high risk to the rights and freedoms of natural persons". A common trap to avoid: the 250-employee threshold does exist in the GDPR, but it concerns a partial exemption from the record of processing activities (Article 30), not the DPIA. A company with 5 employees may be concerned; a group with 2000 employees may not be: it all depends on the processing, never on the size of the organization. Source: GDPR, Article 35 (as reproduced by the CNIL) →

🏢

Public or private: no one is excluded from the scope

Article 35 targets the "data controller" in the broad sense: a private company as much as a public administration, a local authority, an association or a healthcare institution. The text even explicitly covers the case of "systematic monitoring of a publicly accessible area on a large scale", which typically applies to a town hall or a social housing provider installing video surveillance on public roads, not just a commercial company. Source: GDPR, Article 35, paragraph 3 →

📊

The practical trigger: 2 out of 9 criteria

The CNIL and the former Article 29 Working Party (now the European Board, EDPB) set out nine reference criteria in their guidelines (WP248). As soon as a processing activity meets at least two of them, a DPIA becomes mandatory: scoring or evaluating people, automatically deciding something that affects them, systematically monitoring them, processing sensitive data, processing on a large scale, cross-referencing files, targeting vulnerable people (employees, patients, minors), using new technology, or depriving someone of a right or a contract. Source: CNIL, G29/EDPB guidelines (WP248) →

🏥

Concrete examples of profiles concerned

In practice, CNIL doctrine typically links these criteria to: a medical practice or clinic processing health data on a large scale, an HR department using a scoring or profiling tool for employees, a company equipped with badges and systematic video surveillance of its premises open to the public, a credit or debt-collection organization practicing scoring, or a connected health device collecting lifestyle habit data. Source: CNIL, list of 14 processing activities requiring a mandatory DPIA →

🟢

And if I am not concerned, how do I know?

The CNIL has also published a list of 12 types of processing for which a DPIA is NOT required: for example payroll and personnel management for an organization with fewer than 250 employees (excluding profiling), the patient file of a sole-practice health professional, or routine supplier management. Reassuring for many small businesses: having employees or clients is not, on its own, enough to trigger the obligation. Source: CNIL, list of 12 processing activities without a DPIA →

The questions a business leader really asks about the DPIA

No lawyer jargon: simple answers, each backed by the official text it is based on.

Do I need to do the DPIA before launching my project, or can I do it once it's already up and running?
Before. The GDPR is clear on this point: the analysis must be carried out "prior to the processing", meaning before you start collecting or using the data, not once the software has already been deployed to users. The idea: spot problems while it is still easy to change solution, not afterwards. Source: GDPR, Recital 90 →
If I have several similar processing activities (several subsidiaries, several similar tools), do I have to redo a DPIA every time?
No. The European text explicitly provides that "a single assessment" may cover "a set of similar processing operations". In practice, the CNIL's official tool goes even further: it allows you to create a DPIA template and duplicate it for processing activities of the same nature. You therefore do not have to start from scratch for every subsidiary or every tool that works the same way. Source: GDPR, Recital 90 →   Source: PIA tool, CNIL →
Do I have to send my DPIA to the CNIL for its approval?
No, in the vast majority of cases. The CNIL says so itself, unambiguously: "you have carried out an impact assessment but you are not in one of the above cases, you do not need to consult the CNIL." Submission is only mandatory if, despite the planned measures, the residual risk remains high (prior consultation), or if a specific national law requires it. In other cases, the DPIA remains an internal document that you keep and present only in the event of an inspection. Source: CNIL →
Once the DPIA is done, is it good forever?
No. The CNIL specifies: "it is also necessary to regularly review a DPIA to ensure that the level of risk remains acceptable throughout the life of the processing." In practice: if you change tools, collect new data, or the volume of individuals concerned changes significantly, that is the right time to review your DPIA and check whether the conclusion still holds. Source: CNIL →
If the DPIA is botched or missing, who is responsible: me (the business leader), my DPO, or my IT provider?
You, as the data controller. The CNIL is explicit: the data controller "is bound by the obligation to ensure the compliance of its processing with the GDPR." The DPO, if one exists, is consulted and verifies that the DPIA has indeed been carried out, but does not bear the responsibility in your place. The processor (your IT provider, for example) must for its part "provide assistance and the necessary information" when you carry it out. In other words: technical delegation exists, but final responsibility stays with the business leader. Source: CNIL →
In concrete terms, how much does a breach cost?
Up to 10 million euros, or 2% of worldwide annual turnover if that second amount is higher: that is the legal ceiling recalled by the CNIL itself. In practice, this ceiling concerns the most serious cases; it mainly serves as a serious reminder, not a daily threat. A well-conducted DPIA is precisely what allows you to show, in the event of an inspection, that the subject was taken seriously before the problem arose. Source: CNIL →
Is there a free tool to do it myself without paying a firm?
Yes. The CNIL publishes and maintains a free, open-source piece of software called "PIA", available as an installable version (Windows, Linux, Mac) and as a web version, to "facilitate the conduct and formalization" of the analysis. It is a good starting point to become familiar with the method. Our role at SYAGA is not to replace this tool but to apply the same method to your actual case, processing by processing, with an outside perspective that spots what you no longer see when you have your nose in your own software. Source: PIA tool, CNIL →

The DPIA timeline, in plain terms

The dates that really matter, sourced, so you know what is already mandatory today and what is coming.

Already in force today

The GDPR has been applicable since 25 May 2018, across Europe. The DPIA obligation (Article 35), the two CNIL lists that state when it is mandatory or not, and the European guidelines explaining how to conduct it: all of this is in force, stable, and does not depend on any upcoming reform. This is the foundation you can rely on right now.

🕑

To be followed, not yet settled

The European Data Protection Board (EDPB) is working on a single DPIA template to harmonize practices between European countries. The public consultation on this project ended on 9 June 2026; no publication date for the final template has yet been announced. There is no need to wait: the CNIL method remains valid in the meantime.

2016
27 April 2016, then 4 May 2016

The GDPR is adopted, then published in the EU Official Journal

The European Parliament and the Council adopt Regulation 2016/679 on 27 April 2016. It is published in the Official Journal of the European Union (OJ L119) on 4 May 2016, then enters into force twenty days later, on 24 May 2016, without yet being applicable. Source: EUR-Lex, official reference of the regulation →

2018
25 May 2018 - the key date

The GDPR becomes applicable: the DPIA becomes a real obligation

Two years after its adoption, the regulation finally applies across Europe (Article 99.2). This is the day the DPIA obligation under Article 35 becomes enforceable, and the European Data Protection Board (EDPB) is set up for the first time, taking over the DPIA guidelines already drafted (WP248 rev.01). Source: EUR-Lex, regulation record (Article 99) → Source: EDPB, adopted guidelines →

2018
11 October 2018

The CNIL publishes its list of 14 processing activities where a DPIA is mandatory

A few months after the GDPR entered into application, the CNIL adopts decision no. 2018-327: a concrete list of 14 types of processing (health data, HR profiling, employee monitoring...) for which a DPIA must systematically be carried out. No more guessing case by case. Source: CNIL →

2019
12 September 2019

The CNIL publishes the reverse list: when a DPIA is not necessary

A year later, the CNIL completes its doctrine with decision no. 2019-118: a list of processing activities for which a DPIA is NOT required (payroll for fewer than 250 employees excluding profiling, supplier management, the patient file of a sole-practice professional...). Together, the two CNIL lists already answer many common situations without having to decide for yourself. Source: CNIL →

2026
14 April - 9 June 2026 (closed)

The EDPB consults on a single European DPIA template

The EDPB held a public consultation on a draft common DPIA template, intended to harmonize practices between European countries (today, each national authority has its own somewhat different framework). The consultation has been closed since 9 June 2026; it is not yet an applicable text, just a draft under review. Source: EDPB →

?
Coming - no date set

Finalization of the EDPB template, with no known deadline

The EDPB itself states that the template "will be finalized, subject to appropriate amendments", after which national authorities will begin the process of adopting it as a single template, or as a "meta-model" compatible with existing templates (including the CNIL's). No date has been announced to date: we are following this matter to inform our clients as soon as there is anything concrete, without anticipating anything. Source: EDPB →

GDPR penalties, in plain terms

Who sanctions, how much, and on what criteria. Without overdramatizing: the vast majority of cases have nothing to do with the amounts that make headlines.

Who decides, in France: the CNIL's restricted committee

It is a specialized body of the CNIL, distinct from the board that carries out day-to-day inspections and advice, that issues sanctions. It has several graduated tools, not just fines: formal notice, warning, order to comply (with or without a financial penalty), injunction, temporary or permanent limitation of processing. The fine is only the last rung of the ladder. Source: CNIL, sanctions issued →

💰

Two legal ceilings, not a single amount

The GDPR (Article 83) sets two ceilings, with the higher of the two applying: up to 10 million euros or 2% of worldwide turnover of the previous financial year for breaches of organizational obligations (security, records, DPO, impact assessment...); up to 20 million euros or 4% for breaches of substantive principles (legal basis, consent, individuals' rights, transfers outside the EU). These are ceilings, not automatic amounts. Source: GDPR, Article 83 →

How the amount is really set

Article 83.2 requires the authority to take into account: the gravity and duration of the breach, whether it was intentional or merely negligent, the measures already taken to limit the damage, the degree of responsibility, prior history, cooperation with the authority, and the sensitivity of the data concerned. In practice: an organization that has documented its approach (records, DPIA, security measures) and cooperates is judged differently from one that has done nothing. Source: GDPR, Article 83.2 →

👀

A real case where the absence of a DPIA mattered: Discord

On 10 November 2022, the CNIL's restricted committee issued a fine of 800,000 euros against Discord. Among the breaches found: an excessive retention period, a security failure, and Article 35 of the GDPR, the absence of an impact assessment even though the processing, being large-scale and involving minors, required one. This is the most direct example of the link between "no documented DPIA" and a sanction being issued. Source: decision SAN-2022-020, Légifrance →

🌐

The large amounts exist, but remain rare

Criteo was fined 40 million euros on 15 June 2023, for failing to demonstrate valid consent for placing advertising cookies. Clearview AI was fined 20 million euros on 17 October 2022, for a massive collection of photos without a legal basis. These amounts concern very large-scale international processing operations, not the case of an SME that documents its approach. Source: decision SAN-2023-009, Légifrance →

📊

The reality of most CNIL cases

On the same official CNIL page listing decisions, a significant share of published sanctions are counted in thousands of euros, not millions: an advertising agency fined 3,000 euros, two doctors fined 3,000 and 6,000 euros, a meal-delivery service fined 20,000 euros. The sanction is proportionate to the size and severity, not a uniform cutoff. Source: CNIL, sanctions issued →

What to remember

A well-conducted DPIA does not make an organization untouchable: it constitutes proof, in the event of an inspection, that the matter was taken seriously. This is precisely what Article 83.2 of the GDPR requires to be taken into account when setting, or not setting, a fine.

Your supervisory authority, by country

In Europe, each country has its own authorities. Here, for the 30 countries of the European Economic Area, is the data protection authority (your GDPR contact) and the national cybersecurity authority. Each name links to the official website.

CountryData protectionCybersecurity
GermanyBfDI - Die Bundesbeauftragte für den Datenschutz und die InformationsfreiheitBSI - Bundesamt für Sicherheit in der Informationstechnik (Federal Office for Information Security)
AustriaOsterreichische Datenschutzbehorde (DSB)CERT.at
BelgiumAutorite de la protection des donnees - Gegevensbeschermingsautoriteit (APD-GBA)Centre for Cybersecurity Belgium (CCB)
BulgariaCommission for Personal Data Protection (CPDP)CERT Bulgaria (National Cybersecurity Incident Response Team, State e-Government Agency)
CyprusOffice of the Commissioner for Personal Data Protection (Cyprus Data Protection Authority)Digital Security Authority (DSA)
CroatiaAgencija za zastitu osobnih podataka (AZOP) - Croatian Personal Data Protection AgencyNational Cyber Security Centre (NCSC-HR), operating under the Security and Intelligence Agency (SOA)
DenmarkDatatilsynetForsvarets Efterretningstjeneste (FE) - Cybersituationscenter, national CSIRT (Danish Defence Intelligence Service)
SpainAgencia Espanola de Proteccion de Datos (AEPD)INCIBE - Instituto Nacional de Ciberseguridad (Spanish National Cybersecurity Institute)
EstoniaEstonian Data Protection Inspectorate (Andmekaitse Inspektsioon)Information System Authority (RIA) - National Cyber Security Centre of Estonia (NCSC-EE), heberge CERT-EE
FinlandOffice of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)National Cyber Security Centre Finland (NCSC-FI)
FranceCNIL (Commission Nationale de l'Informatique et des Libertes)ANSSI (Agence Nationale de la Securite des Systemes d'Information)
GreeceHellenic Data Protection Authority (HDPA) - Arkhi Prostasias Dedomenon Prosopikou KharaktiraNational Cybersecurity Authority (NCSA) - Ethniki Arkhi Kyvernoasfaleias
HungaryNemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH) - Hungarian National Authority for Data Protection and Freedom of InformationNational Cyber Security Center of Hungary (NCSC-HU / NKI), operant au sein du Special Service for National Security (SSNS)
IrelandData Protection Commission (DPC)National Cyber Security Centre (NCSC-IE), incluant le CSIRT-IE
IcelandPersonuvernd (Icelandic Data Protection Authority)CERT-IS
ItalyGarante per la protezione dei dati personaliAgenzia per la Cybersicurezza Nazionale (ACN)
LatviaData State Inspectorate (Datu valsts inspekcija)CERT.LV - Cyber Incident Response Institution of the Republic of Latvia
LiechtensteinDatenschutzstelle Fürstentum LiechtensteinCSIRT.LI (Computer Security Incident Response Team Liechtenstein / National Cyber Security Unit)
LithuaniaState Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija - VDAI)National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras - NKSC)
LuxembourgCommission Nationale pour la Protection des Données (CNPD)Agence nationale de la sécurité des systèmes d'information (ANSSI Luxembourg), sous le Haut-Commissariat à la protection nationale (HCPN)
MaltaOffice of the Information and Data Protection Commissioner (IDPC)CSIRTMalta (Critical Information Infrastructure Protection Unit, Ministry for Home Affairs and National Security)
NorwayDatatilsynetNSM (Nasjonal sikkerhetsmyndighet / National Security Authority) (to be confirmed)
NetherlandsAutoriteit Persoonsgegevens (AP)National Cyber Security Centre (NCSC-NL)
PolandUrząd Ochrony Danych Osobowych (UODO)CSIRT NASK (CERT Polska)
PortugalComissão Nacional de Proteção de Dados (CNPD)Centro Nacional de Cibersegurança (CNCS)
RomaniaANSPDCP - Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (National Supervisory Authority for Personal Data Processing)to be confirmed
SlovakiaUrad na ochranu osobnych udajov Slovenskej republikyNarodny bezpecnostny urad (National Security Authority) - SK-CERT / National Cyber Security Centre
SloveniaInformation Commissioner of the Republic of Slovenia (Informacijski pooblascenec)Government Information Security Office (GISO / URSIV - Urad Vlade RS za Informacijsko Varnost)
SwedenIntegritetsskyddsmyndigheten (IMY) - Swedish Authority for Privacy ProtectionNationellt cybersakerhetscenter (NCSC-SE), rattache a FRA, integre CERT-SE (CSIRT national)
CzechiaUrad pro ochranu osobnich udaju (UOOU) - Office for Personal Data ProtectionNarodni urad pro kybernetickou a informacni bezpecnost (NUKIB) - National Cyber and Information Security Agency

Sources: official authority websites and the EDPB members list (edpb.europa.eu), consulted on 18 July 2026. Data protection authorities confirmed: 30/30. Cybersecurity authorities confirmed: 28/30. The "to be confirmed" notes indicate an official source not yet stabilized as of this date.

Ready to document your DPIA?

Describe your processing to us, and we'll get back to you with a tailored quote.

Start my free diagnostic

Free: your score + your gaps. The detailed report and the attestation: 499 EUR excl. VAT, only if you decide to.

contact@syaga.eu Revisit the CNIL method