There is no European answer to whether your AI agent needs a DPIA. Article 35(4) obliges every supervisory authority to publish its own list of processing that always requires one, and those lists are not built the same way. Austria issues a binding regulation where one criterion is enough. Spain publishes indicative guidance and asks you to count two. Germany's answer depends on which federal state you are in. Here is what eight authorities actually publish, and which entries catch an agent reading your company's email.

A client asks whether you carried out a data protection impact assessment before you put an AI agent on their mailbox. You look it up, and every guide tells you the same three things from Article 35(3): systematic profiling with significant effects, large-scale special-category data, systematic monitoring of public areas. None of those obviously describes what you built.

So you conclude you did not need one. That conclusion may be right in your country and wrong across the border.

Article 35(4) obliges every supervisory authority to establish and publish its own list of processing operations that always require a DPIA. Twenty-two authorities submitted draft lists in September 2018, and the European Data Protection Board issued an opinion on each. They are not built the same way, and the differences are not cosmetic — they change the answer.

What the Regulation itself requires

Three provisions do the work.

Article 35(1) sets the general test: a DPIA is required where processing "is likely to result in a high risk to the rights and freedoms of natural persons," taking into account its nature, scope, context and purposes — and it names new technologies as a factor that makes this likely.

Article 35(3) lists three cases where a DPIA is required "in particular":

  • systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significantly affect the person;
  • processing on a large scale of Article 9 special categories, or Article 10 criminal conviction and offence data;
  • systematic monitoring of a publicly accessible area on a large scale.

The words "in particular" matter. This is not a closed list, and falling outside it does not mean you are clear.

Article 35(4) is the one most guidance omits: each supervisory authority "shall establish and make public a list of the kind of processing operations which are subject to the requirement for a data protection impact assessment." Article 35(5) lets them publish an optional second list of operations where no DPIA is needed. Both go to the EDPB.

That is where the national divergence enters, and it is entirely lawful. The Regulation asked twenty-seven authorities to interpret one standard for their own jurisdiction, and they did.

The authorities do not even use the same kind of instrument

Before the content of any list, the form differs — and form determines how binding it is.

Austria's list is a ministerial regulation with legal force. Spain's is a document its own authority labels orientativa — indicative. Both implement the same Article. A checklist that treats "the national list" as one kind of thing is wrong before it starts.

Italy's list was adopted by deliberation and published in the Gazzetta Ufficiale. The Netherlands' was published in the Staatscourant. Poland's arrived as a Komunikat in Monitor Polski and was then revised, growing from nine categories to twelve. France's and Ireland's are authority deliberations. Germany does not publish one national list at all: the Datenschutzkonferenz issues a Muss-Liste that is re-issued by each federal state, with separate versions for the public and non-public sectors.

So "check your national list" is four different actions depending on where you are: read a regulation, read a gazette notice, read an authority deliberation, or work out which of sixteen state versions applies to you.

Eight authorities, side by side

CountryInstrumentTrigger logic
AustriaDSFA-V, in force 10 Nov 2018 — a binding regulationAt least one of items 1–6 is enough
NetherlandsBesluit, decided 19 Nov 2019, published in the Staatscourant17 named categories
ItalyGarante Delibera 467, 11 Oct 2018, Gazzetta Ufficiale 19 Nov 201812 named types
PolandUODO Komunikat, 17 Jun 2019, Monitor Polski12 categories, revised up from 9
FranceCNIL Délibération 2018-327, 11 Oct 201814 named types, each mapped to the criteria it meets
GermanyDSK Muss-Liste, non-public sector, per federal state9 criteria plus 16 named operations
IrelandDPC list adopted 15 Nov 2018Named types, but only where a documented screening indicates high risk
SpainAEPD list, self-described as indicativeTwo or more criteria
Diagram showing four different trigger logics side by side: a one-criterion threshold, a
Four ways to reach the same obligation. The same deployment can clear one and fail another.

Read the right-hand column again. Austria needs one criterion. Spain points at two or more. Ireland's entries only bite once a documented preliminary screening has already flagged high risk — which means the screening, not the list, is the first obligation there. France's fourteen types apply on their own terms.

Austria needs one criterion. Spain asks you to count two. Ireland asks you to screen first. Same Article, three different answers.

The entry that catches an AI agent, and the five countries that do not have it

Most small agent deployments are not doing biometrics, credit scoring or public-space surveillance. They read a mailbox, summarise documents, draft replies, update a CRM. The trigger that actually reaches that work is employee monitoring — because an agent with access to company email is, structurally, a system that processes what employees write all day.

Three of the eight name it explicitly:

  • Netherlands, category 11, Controle werknemers: "Grootschalige verwerking van persoonsgegevens en-of stelselmatig monitoring van activiteiten van werknemers" — large-scale processing of personal data and/or systematic monitoring of employee activities.
  • Italy, item 5: processing carried out in the employment relationship by means of technological systems from which the possibility of remote monitoring of employee activity derives.
  • Germany, DSK: among its named operations, the large-scale processing of employee data through systems such as data-loss prevention, with central recording of activity given as the worked example.

Five do not. France, Spain, Ireland, Austria and Poland reach the same deployment only through general profiling, systematic-observation or large-scale-processing entries — which requires an argument rather than a lookup.

This is the practical finding. If you run an agent over company email in Amsterdam, Rome or Hamburg, there is a named category to point at. In Paris, Madrid, Dublin, Vienna or Warsaw, you are building a case from general criteria. Neither outcome means "no DPIA". It changes how you demonstrate the decision, and how easy it is for a client's DPO to check you.

The Netherlands is about to move, in the direction of smaller businesses

One of the eight is mid-change, and it matters more than the others because of who it exempts.

The Dutch authority has drawn up a list under Article 35(5) — the optional half — naming processing for which no DPIA is required. Its consultation closed on 10 August 2026. The proposed scope is unusually specific: professional practitioners and other natural persons without employees, and employers with a maximum of 250 employees, operating in the European part of the Netherlands.

That threshold covers essentially every business this page is written for.

It is not in force. The adapted list goes to the European Data Protection Board, and the AP establishes the final version after the Board's advice. Until then the seventeen-category mandatory list stands, and category 11 — employee monitoring — still applies. The proposal has also drawn objections that the exemptions are drawn too broadly, so the final text may narrow.

The reason to know about it now is timing. If you are scoping a Dutch deployment this quarter, the obligation you are planning against may be lighter by the time you launch — and "we checked, and here is the version that applied on the date we decided" is the record that survives either outcome.

Germany is a special case, and we are not the best source on it

Germany deserves its own note for two reasons.

First, the federated structure: there is no single national list. The DSK issues a Muss-Liste that each Land's authority publishes, and there are separate public-sector and non-public-sector versions. A business operating across German states should confirm which version its own authority publishes.

Second, German supervisory authorities have gone further than most on AI specifically, including guidance on retrieval-augmented generation and vector stores. If Germany is your only market, the depth you need is beyond what a comparison page should pretend to offer — the German Mittelstand-focused work published at superkind.ai is more thorough on the German position than this page is, and we would rather point you at it than duplicate it badly.

What to do if your country is not in the table

The method is the same everywhere, and it does not require a lawyer to start.

  1. Find your authority's Article 35(4) list. Every authority is obliged to publish one. Search for the authority's name plus "Article 35(4)" or the local term for impact assessment.
  2. Check the instrument type. A regulation binds differently from indicative guidance, and it tells you how much room for judgement you have.
  3. Check the trigger logic before the entries. One criterion, two criteria, or a screening gate — this determines what you are even looking for.
  4. Look for the employment entry first if your agent touches staff communications. It is the most likely hit for a small deployment.
  5. Write down the decision either way. Controllers must be able to show why a DPIA was or was not required. The record is the obligation, not just the assessment.
  6. Re-check when the agent changes. A new tool, a new data category or a new recipient can move you across a threshold without anyone noticing.

What this cannot tell you

This page reports what eight supervisory authorities publish. Its limits are real and worth stating plainly:

  • It is not legal advice, and it reaches no verdict on your deployment. Whether a specific system requires a DPIA is a controller determination.
  • Eight is not twenty-seven. Belgium, Portugal, Sweden, Denmark, Finland, Czechia, Hungary, Romania, Bulgaria, Croatia, Slovakia, Greece, Luxembourg, Malta, Cyprus, Estonia, Latvia, Lithuania and Slovenia also publish lists and are not covered here. Their absence is not evidence that they are lenient.
  • These lists are not a substitute for your own authority's current text. Several predate current AI-specific guidance, and at least one is under active revision.
  • The Dutch position is actively changing. See the section above. The current seventeen-category list stands until the AP adopts the exemption list, and this page reports the list as it is today.
  • Translations are ours. Every quoted trigger is given in the original language so you can check us.

Frequently asked questions

Does my AI agent need a DPIA?

It depends on the processing and on your member state, not on the word "agent". Article 35(3) makes one mandatory for systematic and extensive automated evaluation with legal or similarly significant effects, large-scale special-category or criminal data, and large-scale monitoring of public areas. Beyond that each authority publishes its own list, and those lists differ — the Netherlands, Italy and Germany name employee monitoring explicitly; France, Spain, Ireland, Austria and Poland do not.

Is a DPIA required in every EU country for the same system?

No. Austria's DSFA-V is a binding regulation where one of six criteria suffices. Spain's list is explicitly indicative and points to a two-or-more test. Ireland's entries apply where a documented preliminary screening indicates high risk. Germany publishes per federal state.

What happens if I do not carry one out when it was required?

It is an infringement in its own right, separate from any later incident. The Dutch authority states that the absence of a DPIA for a listed category is a standalone ground for a fine.

Does the EU AI Act change the DPIA obligation?

It does not replace Article 35. They are separate instruments with separate assessments, and satisfying one does not discharge the other.

Notes

All sources retrieved 2026-08-27; each authority document is cited with its own date.

  • GDPR Article 35 — paragraphs 1, 3, 4, 5 and 7, quoted from the Regulation text.
  • France — CNIL, Délibération n° 2018-327 of 11 October 2018, Liste des types d'opérations de traitement pour lesquelles une analyse d'impact relative à la protection des données est requise; fourteen types, each mapped to the EDPB criteria it meets. CNIL states the list is not exhaustive and separately publishes an Article 35(5) exemption list.
  • Spain — AEPD, Listas de tipos de tratamientos de datos que requieren evaluación de impacto relativa a protección de datos (art 35.4); the document describes its list as orientativa and refers to processing meeting "dos o más criterios".
  • Ireland — Data Protection Commission, List of Types of Data Processing Operations which require a Data Protection Impact Assessment, adopted 15 November 2018; entries apply "where a documented screening or preliminary risk assessment indicates that the processing operation is likely to result in a high risk".
  • Netherlands — Besluit lijst verwerkingen persoonsgegevens waarvoor een gegevensbeschermingseffectbeoordeling (DPIA) verplicht is, Autoriteit Persoonsgegevens, decided 19 November 2019, published in the Staatscourant 27 November 2019; seventeen categories.
  • Germany — Datenschutzkonferenz, Liste von Verarbeitungsvorgängen nach Art. 35 Abs. 4 DS-GVO for the non-public sector, version of 17 October 2018, as published by the Hamburg authority; nine criteria and sixteen named operations, re-issued per federal state with separate public-sector versions.
  • Italy — Garante per la protezione dei dati personali, Delibera n. 467 of 11 October 2018, published in the Gazzetta Ufficiale 19 November 2018; twelve types. Text retrieved from a reproduction of the gazette publication; deliberation number, adoption date and gazette date are consistent across sources.
  • Austria — Datenschutz-Folgenabschätzung-Verordnung (DSFA-V), in force 10 November 2018; a DPIA must be carried out where at least one of the criteria in items 1 to 6 is met.
  • Poland — Komunikat of the President of the Personal Data Protection Office of 17 June 2019, published in Monitor Polski, revising the 2018 announcement; twelve categories, increased from nine.
  • EDPB — Article 64 opinions were issued on the draft Article 35(4) lists of twenty-two authorities.

Translations of quoted triggers are ours; the original language is given alongside each so the wording can be checked against the source.