DPIAs and prior consultation under Regulation 2018/1725: Article 39, Article 40, and the EDPS clocks
What the institutions’ own data-protection regulation requires before high-risk processing starts — the Article 39 trigger and the EDPS threshold list, the contents of the assessment, the eight-week and six-week clocks of an Article 40 prior consultation, the Article 31 records behind both, the 72-hour breach rule, the DPO’s statutory role, and where the regime departs from GDPR Article 35.
Regulation (EU) 2018/1725 is the GDPR written for the Union’s own administration. It applies to the processing of personal data by all Union institutions, bodies, offices and agencies set up by or on the basis of the Treaties, it repealed Regulation (EC) No 45/2001 with effect from 11 December 2018, and it names one supervisory authority for all of them: the European Data Protection Supervisor. Recital 5 says that wherever its provisions follow the same principles as the GDPR they “should … be interpreted homogeneously,” and Article 39 tracks GDPR Article 35 almost clause for clause. The differences are small in the text and large in practice: who the DPO is, which list decides the threshold, what triggers a prior consultation, and how the records behind the assessment must be published. Citations link to EUR-Lex and the EDPS; it is general information, not legal advice.
Scope and vocabulary
Regulation (EU) 2018/1725 applies under Article 2(1) to “the processing of personal data by all Union institutions and bodies,” which Article 3(10) defines as the institutions, bodies, offices and agencies set up by, or on the basis of, the TEU, the TFEU or the Euratom Treaty. The controller definition in Article 3(8) is the one to notice: the controller is “the Union institution or body or the directorate-general or any other organisational entity which, alone or jointly with others, determines the purposes and means of the processing.” In a large institution the controller for a DPIA is usually a DG or a unit, and the EDPS toolkit builds its who-does-what tables on that footing.
Article 31: the records that come first
Every DPIA sits on a record of processing. Article 31(1) requires each controller to keep a record for every processing activity containing the controller’s and DPO’s contact details and, where applicable, the processor’s and joint controller’s; the purposes; the categories of data subjects and of personal data; the categories of recipients, including those in Member States, third countries or international organisations; transfers and their safeguards; where possible the envisaged erasure time limits; and where possible a general description of the Article 33 security measures. Records must be in writing and available to the EDPS on request. Article 31(5) is where the institutions part company with the GDPR: “Unless it is not appropriate taking into account the size of the Union institution or body, Union institutions and bodies shall keep their records of processing activities in a central register. They shall make the register publicly accessible.” There is no equivalent of the GDPR’s exemption for organisations with fewer than 250 persons.
Part I of the EDPS toolkit, Accountability on the ground Part I: Records, Registers and when to do Data Protection Impact Assessments (v1.3, July 2019), shows how to generate the records on a per-process basis, run the accompanying compliance-and-risk check, and keep and publish the register.
Article 39: when a DPIA is required
Article 39(1) sets the trigger: “Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.” A single assessment may cover a set of similar operations presenting similar high risks. Article 39(3) names three cases where a DPIA is required in particular: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based; large-scale processing of the Article 10 special categories or Article 11 criminal-conviction data; and systematic monitoring of a publicly accessible area on a large scale.
Article 39(4) obliges the EDPS to publish a list of the kinds of processing operations subject to the requirement, and Article 39(5) lets it publish a list of those for which none is required. The EDPS did both in its Decision of 16 July 2019 on DPIA lists issued under Articles 39(4) and (5), after consulting the European Data Protection Board. The decision works in three parts:
- Annex 1 — the threshold assessment. A template with nine criteria: systematic and extensive evaluation or scoring, including profiling and predicting; automated decision-making with legal or similar significant effect; systematic monitoring; sensitive or highly personal data; large-scale processing; datasets matched or combined across purposes or controllers beyond the data subject’s reasonable expectations; vulnerable data subjects; innovative use or novel technological or organisational solutions; and processing that prevents data subjects from exercising a right or using a service or contract. Article 3(2) of the decision: “Where two or more of the criteria in the template in Annex 1 are applicable, the controller shall in general carry out a DPIA.” A controller that decides not to, with more than one criterion met, must document and justify the decision.
- Annex 2 — the positive list. Operations that go straight to a DPIA without a threshold assessment: exclusion databases; large-scale processing of special categories such as disease surveillance, pharmacovigilance and central databases for law-enforcement cooperation; internet traffic analysis that breaks encryption, such as data-loss-prevention tools; and e-recruitment tools that automatically pre-select or exclude candidates without human intervention.
- Annex 3 — the negative list. Operations prima facie not requiring a DPIA when an institution is sole or joint controller: management of personal files under Article 26 of the Staff Regulations, standard annual appraisal, standard 360-degree evaluations, standard staff selection, establishment of rights on entry into service, leave, flexitime and telework management, standard non-biometric access control, and standard limited-scale CCTV.
Both lists are expressly non-exhaustive, and Article 4 of the decision adds that where the Commission adopts an implementing act under Article 40(4) listing cases requiring prior authorisation, a DPIA is required for those as well.
Article 39: what the assessment must contain
Article 39(7) sets four minimum contents: a systematic description of the envisaged operations and their purposes; an assessment of the necessity and proportionality of the operations in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects; and the measures envisaged to address the risks, “including safeguards, security measures and mechanisms to ensure the protection of personal data and to demonstrate compliance with this Regulation.” Around that core sit four procedural duties. Article 39(2): the controller shall seek the advice of the DPO — unconditionally, since every institution has one. Article 39(9): where appropriate, seek the views of data subjects or their representatives. Article 39(10): where the processing is regulated by a legal act adopted on the basis of the Treaties and a DPIA was carried out as part of the general impact assessment preceding that act, paragraphs 1 to 6 do not apply unless the act says otherwise. Article 39(11): review the assessment where necessary, and at least when the risk represented by the operations changes.
Part II of the toolkit, Accountability on the ground Part II: Data Protection Impact Assessments & Prior Consultation (v1.3, July 2019), is the EDPS’s method for meeting those contents: a generic DPIA process, a catalogue of guiding questions per data-protection principle, risk treatment with an indicative list of generic controls, review cycles, publicity of DPIA reports and, in Annex 3, a template structure for the DPIA report. An institution that adopts that structure has adopted the regulator’s own checklist.
Article 40: prior consultation of the EDPS
The DPIA decides whether the EDPS must be consulted before processing starts. Article 40(1) sets the trigger in two limbs: the DPIA indicates that the processing “would, in the absence of safeguards, security measures and mechanisms to mitigate the risk, result in a high risk,” and “the controller is of the opinion that the risk cannot be mitigated by reasonable means in view of the available technologies and costs of implementation.” The controller must seek the DPO’s advice on the need for consultation, and under Article 45(1)(f) the DPO must consult the EDPS in case of doubt. Article 40(3) lists what goes to the EDPS: where applicable, the respective responsibilities of controller, joint controllers and processors; the purposes and means of the intended processing; the measures and safeguards protecting data subjects’ rights; the DPO’s contact details; the DPIA itself; and any other information the EDPS requests. Then the clocks in Article 40(2):
- Up to eight weeks from receipt of the request for the EDPS to provide written advice where it considers the intended processing would infringe the Regulation, in particular where the controller has insufficiently identified or mitigated the risk; the EDPS may also use any of its Article 58 powers.
- Plus six weeks where the complexity of the intended processing justifies it; the EDPS must inform the controller of the extension, with reasons, within one month of receipt.
- Suspension of those periods until the EDPS has obtained information it has requested — which is why an incomplete Article 40(3) package is the commonest way a fourteen-week process becomes a longer one.
Article 40(4) lets the Commission adopt, by implementing act, a list of cases in which controllers must consult the EDPS and obtain prior authorisation for processing in the public interest, including social protection and public health; the GDPR leaves the same option to Member State law.
Articles 34 and 35: breach notification and communication
Article 34(1) requires the controller to notify a personal data breach to the EDPS “without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons,” with reasons for any delay beyond 72 hours. The notification must at least describe the nature of the breach including, where possible, the categories and approximate numbers of data subjects and records concerned; give the DPO’s contact details; describe the likely consequences; and describe the measures taken or proposed. Information may be provided in phases. Article 34(5) requires the controller to inform the DPO, and Article 34(6) requires every breach to be documented — facts, effects and remedial action — whether or not it was notified.
Article 35 adds the communication to data subjects: where the breach is likely to result in a high risk, without undue delay and in clear and plain language. It is not required where the data were rendered unintelligible to unauthorised persons, for example by encryption; where subsequent measures mean the high risk is no longer likely to materialise; or where it would involve disproportionate effort, in which case a public communication must inform data subjects equally effectively. Under Article 35(4) the EDPS may require the communication if the controller has not made it. The EDPS’s Guidelines on personal data breach notification for the European Union institutions and bodies (21 November 2018) walk through risk assessment, phased notification, communication and documentation, with a template and worked examples. Notifications go through the EDPS’s online or downloadable form; email attachments must be encrypted, and an update must quote the EDPS case reference.
Articles 43 to 45: the data protection officer
The DPO is the hinge on which Articles 39, 40 and 34 turn, and the Regulation protects the post more than the GDPR does. Article 43(1): each Union institution or body shall designate a DPO; several may share one; the DPO is chosen on professional qualities and expert knowledge of data protection law and practice, must be a staff member, and the contact details must be published and communicated to the EDPS. Article 44: the DPO must be involved “properly and in a timely manner” in all data-protection issues, resourced, free from instructions, protected from dismissal or penalty for doing the job, and must report directly to the highest management level. The term is three to five years, renewable; dismissal is possible only where the DPO no longer fulfils the conditions of the post and “only with the consent of the European Data Protection Supervisor”; and the DPO must be registered with the EDPS after designation.
Three Article 45 tasks are the operational spine of this guide. Article 45(1)(d): advise on whether a breach must be notified or communicated under Articles 34 and 35. Article 45(1)(e): advise on the DPIA and monitor its performance, and consult the EDPS in case of doubt as to whether one is needed. Article 45(1)(f): advise on the need for prior consultation, and consult the EDPS in case of doubt. Article 45(3) requires each institution to adopt implementing rules on the DPO’s tasks, duties and powers — which is where a DPIA sign-off step, a breach escalation path and a prior-consultation decision usually get written down.
Moving between the GDPR and Regulation 2018/1725
For a practitioner who has run DPIAs under the GDPR, the table is the list of things to re-check.
| Element | GDPR | Regulation 2018/1725 | What changes in practice |
|---|---|---|---|
| Supervisory authority | National authority (Art. 55) | The EDPS for every institution | One authority, one form, one set of guidelines. |
| Records | Art. 30; exemption under 250 persons unless risk, non-occasional or special categories | Art. 31; no size exemption; central, publicly accessible register | The register is a public document, so records are written for an outside reader. |
| DPO advice on the DPIA | Art. 35(2): “where designated” | Art. 39(2): unconditional | Every institution has a DPO, so DPO advice is always a required step. |
| Threshold lists | Art. 35(4)–(6): national lists, consistency mechanism | Art. 39(4)–(6): one EDPS list, EDPB examined | Use the EDPS Decision of 16 July 2019: nine criteria, two-or-more rule, positive and negative annexes. |
| Legal-act exception | Art. 35(10): Union or Member State law | Art. 39(10): a legal act adopted on the basis of the Treaties | Only an impact assessment preceding a Treaty-based act displaces the DPIA. |
| Prior consultation | Art. 36(1): high risk absent mitigating measures; Art. 36(2): eight weeks plus six; Art. 36(5): Member State law may require authorisation | Art. 40(1): the same, plus the controller’s opinion that the risk cannot be mitigated by reasonable means, and DPO advice on the need; Art. 40(2): identical clocks; Art. 40(4): Commission implementing act | Document the reasonable-means conclusion and the DPO’s advice on it; watch for an implementing act. |
| Breach rules | Arts. 33 and 34 | Arts. 34 and 35 | Same 72-hour and high-risk tests; the DPO must be informed; the EDPS form and encryption rules apply. |
| The DPO | Arts. 37–39; mandatory for public authorities | Arts. 43–45; staff member, three-to-five-year term, dismissal only with EDPS consent, registered with the EDPS | The post is more protected, and Article 45 adds an express duty to consult the EDPS in case of doubt. |
| Restrictions on rights | Art. 23: Union or Member State law | Art. 25: Treaty-based acts or internal rules adopted at the highest management level and published in the Official Journal | A restriction is only as good as the internal rule it cites, and the data subject must be told the principal reasons and of the right to complain to the EDPS. |
A readiness checklist
- Name the controller for each processing activity at the right level — the DG or unit that determines purposes and means — and keep one Article 31 record per process in the central register.
- Run the EDPS Annex 1 threshold assessment on every new or changed activity; record the criteria met and, where two or more apply and no DPIA is done, the written justification. Go straight to a DPIA for anything on the Annex 2 list.
- Build the DPIA on the Part II Annex 3 report structure, answer all four Article 39(7) contents explicitly, and record the DPO’s advice as a dated step and the data subjects’ views or why they were not sought.
- Write down the Article 40(1) conclusion on whether residual high risk can be mitigated by reasonable means, with the DPO’s advice; assemble the full Article 40(3) package before sending so the eight-week clock is not suspended, and calendar the one-month extension-notice date and week fourteen.
- Set the Article 39(11) review trigger on the record, so a change in the risk represented by the operations reopens the assessment.
- Write the breach procedure to Articles 34 and 35 — the 72-hour clock from awareness, the DPO informed, the EDPS form, phased notification with the case reference, documentation of every breach — and adopt the Article 45(3) rules that make the DPO steps the institution’s written procedure.
Where AccessPoint fits
AccessPoint’s Regulation 2018/1725 pack loads the Regulation as the legal-authority spine with Article 39 DPIAs, Article 25 restrictions linked to internal rules, 72-hour EDPS breach notification and EDPS complaint tracking, in English and French, and everything runs inside the institution’s own Microsoft 365 and Azure tenant.
The Article 31 record on the subject
Each privacy subject carries its record of processing — purpose, lawful basis, categories of personal data, data subjects and recipients, a per-recipient disclosures register, processors and vendors, retention, security measures, hosting location and the international-transfer flag with its safeguards field — and assessments attach to that subject rather than to a blank form.
Screener, then the questionnaire
A template can carry a preliminary screener; a screened-out result produces a lightweight compliance record and everything else instantiates the full section set. Templates are versioned, and each assessment works on its own derived copy so later template edits never rewrite history.
Section delegation and the DPO step
Any section can be handed to the business owner who knows the answers, with autosave, hours and documents; the coordinator approves or requests changes. The configurable review workflow then routes the assessment through the reviewers and senior-official sign-off your Article 45(3) rules name.
Risks, mitigations and commitments
A likelihood-and-impact register with a harm-to-individuals determination, mitigation tasks, and a commitments card that tracks every undertaking to completion — the Article 39(7)(d) measures, with owners and dates.
The prior-consultation file
Key dates include a submitted-to-regulator date, the regulator consultation log records submissions and responses, and the closure tab generates the regulator summary as a document with the assessment’s documents, approvals and activity trail exported as one package.
Breach response on the 72-hour clock
The incident module runs from discovery: containment measures, a risk-of-harm register, and a live notifications checklist with a computed due date, content checklist and legal reference for each obligation; notices are marked sent with a reference number, dismissed only with a recorded rationale, and generated from the regulator-notice or individual-notice template in the chosen language.
Approved assessments are read-only and change goes forward through Re-assess on the same subject; when a subject’s recorded purpose changes, the reassessment date is pulled forward and surfaced on My Day — Article 39(11) with a trigger attached. AccessPoint is distributed through Microsoft AppSource, where it has been reviewed and tested by Microsoft.
Regulation 2018/1725 DPIA questions
When must an EU institution carry out a data protection impact assessment?
What must a DPIA under Regulation 2018/1725 contain?
When is prior consultation of the EDPS required, and how long does it take?
What are the breach notification deadlines for EU institutions?
Does every EU institution need a data protection officer?
How does this regime differ from GDPR Article 35?
Related reading
See how AccessPoint runs the institutions’ data-protection regime on the Regulation 2018/1725 page and its companion Regulation 1049/2001 access-to-documents page, or read about the assessment engine in privacy impact assessment software. The sibling guides cover DPIAs under GDPR Article 35 and access to documents under Regulation 1049/2001. Replacing a broader privacy platform? Compare AccessPoint with OneTrust — or book a live demo on the institutions’ rules.
Sources
- Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies, OJ L 295, 21.11.2018, p. 39 (Articles 2, 3, 25, 31, 34, 35, 39, 40, 43–45, 58 and 99; accessed September 2026)
- Decision of the European Data Protection Supervisor of 16 July 2019 on DPIA lists issued under Articles 39(4) and (5) of Regulation (EU) 2018/1725 (Annexes 1–3)
- EDPS, Accountability on the ground: Guidance on documenting processing operations for EU institutions, bodies and agencies — Part I: Records, Registers and when to do DPIAs and Part II: Data Protection Impact Assessments & Prior Consultation (v1.3, July 2019)
- EDPS, Guidelines on personal data breach notification for the European Union institutions and bodies (21 November 2018) and the EDPS personal data breach notification page (accessed September 2026)
- Regulation (EU) 2016/679 (General Data Protection Regulation), Articles 23, 30, 33–39 (for the comparison; accessed September 2026)
Last reviewed: September 2026. This guide is general information for data-protection practitioners in the Union institutions, not legal advice — rely on the official text of Regulation (EU) 2018/1725, the EDPS’s guidance, your institution’s implementing rules and its DPO and legal service.