What happens if I do not carry it out? What are the possible consequences?
Home » The GDPR » Main Tools and Actions » Data Protection Impact Assessment (DPIA) » What happens if I do not carry it out? What are the possible consequences?

“Under the GDPR, non-compliance with DPIA requirements can lead to fines imposed by the competent supervisory authority. Failure to carry out a DPIA when the processing is subject to a DPIA (Article 35(1) and (3)-(4)), carrying out a DPIA in an incorrect way (Article 35(2) and (7) to (9)), or failing to consult the competent supervisory authority where required (Article 36(3)(e)), can result in an administrative fine of up to 10M€, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.”[1]
 

 

References


1wp248rev.01, page 4, Section I, 3rd paragraph.

Skip to content