Article 35 GDPR tells controllers that they need a DPIA when processing is likely to result in high risk, but leaves the how almost entirely up to them. The result is a patchwork: national "likely high risk" lists that differ from one Member State to the next, varying supervisory authority guidance and templates, and no shared methodology for scoring risk. For any organisation running processing across more than one Member State, that fragmentation has always been one of the quieter costs of doing business in the EU.
The Digital Omnibus package, published by the Commission on 19 November 2025, proposes to close that gap. And the EDPB, in parallel, has already moved, publishing a harmonised DPIA template months before any legislative mandate requires it. Together, these two tracks are worth understanding now, since organisations can start aligning their DPIA methodology and templates well before the legislative process concludes.
What the Omnibus proposes
The Commission proposal amends Article 35(4)–(6) GDPR in three connected ways:
The intent is to reduce the compliance burden of running DPIAs across multiple jurisdictions and narrow the ambiguity around when a DPIA is triggered, rather than change the underlying obligation to carry one out. That's part of why the DPIA provisions are seen as among the less contentious elements of the Omnibus package. The text will move through the ordinary legislative procedure and can still change materially before adoption.
The EDPB DPIA Templates
The EDPB adopted a first standardised DPIA template on 10 March 2026, published it on 14 April 2026 alongside an explainer document, and opened it for public consultation that closed on 9 June 2026. The accompanying explainer document provides practical guidance on completing the template, clarifies key concepts, and includes a useful annex listing DPIA-related guidance published by supervisory authorities across the EEA. As of this writing, the finalised version has not yet been published.
A few features of the draft are worth knowing regardless of how the legislative process resolves:
Why this matters before either track is final
The Omnibus text could still change during negotiations. But the EDPB template already exists, and it's already shaping how supervisory authorities look at DPIAs. Organisations should therefore monitor both developments in parallel, rather than treating only the legislative track as relevant to their compliance planning.
In conclusion:
Operationalising it now
The direction of travel is clear even if the destination isn't fully mapped: DPIA methodology in the EU is heading toward convergence, not divergence. Organisations that begin working with the EDPB template now, rather than waiting for it to become mandatory, will need far less time to adapt once alignment is formally required.
At Considerati, we are following these developments closely and will keep sharing updates as they land. If you would like to discuss what DPIA standardisation means for your organisation, we are happy to get in contact.
Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.
Our services Contact