Towards a single DPIA approach across the EU

Article 35 GDPR tells controllers that they need a DPIA when processing is likely to result in high risk, but leaves the how almost entirely up to them. The result is a patchwork: national "likely high risk" lists that differ from one Member State to the next, varying supervisory authority guidance and templates, and no shared methodology for scoring risk. For any organisation running processing across more than one Member State, that fragmentation has always been one of the quieter costs of doing business in the EU. 

The Digital Omnibus package, published by the Commission on 19 November 2025, proposes to close that gap. And the EDPB, in parallel, has already moved, publishing a harmonised DPIA template months before any legislative mandate requires it. Together, these two tracks are worth understanding now, since organisations can start aligning their DPIA methodology and templates well before the legislative process concludes. 

What the Omnibus proposes 

The Commission proposal amends Article 35(4)–(6) GDPR in three connected ways: 

  • One EU-wide list of high-risk processing. Rather than each Member State setting out its own view of when a DPIA is required, the EDPB would prepare a single list applying across the EU.  
  • A corresponding list of processing that falls outside the requirement. Supervisory authorities may already publish such a list. The Dutch AP is one of the authorities that consulted this summer on a draft list of nine categories. Such lists remain national in scope, so they offer certainty only within the jurisdiction of the authority that issued them. Under the proposal, a single EU-wide list would allow controllers to document why an assessment was not required on a single guidance rather than jurisdiction by jurisdiction. 
  • A common template and methodology. The EDPB would also develop a standardised DPIA template and methodology, again subject to Commission adoption via an implementing act. 
  • Periodic review. Both the lists and the template/methodology would be reviewed at least every three years to keep pace with technological change. 

The intent is to reduce the compliance burden of running DPIAs across multiple jurisdictions and narrow the ambiguity around when a DPIA is triggered, rather than change the underlying obligation to carry one out. That's part of why the DPIA provisions are seen as among the less contentious elements of the Omnibus package. The text will move through the ordinary legislative procedure and can still change materially before adoption. 

The EDPB DPIA Templates 

The EDPB adopted a first standardised DPIA template on 10 March 2026, published it on 14 April 2026 alongside an explainer document, and opened it for public consultation that closed on 9 June 2026. The accompanying explainer document provides practical guidance on completing the template, clarifies key concepts, and includes a useful annex listing DPIA-related guidance published by supervisory authorities across the EEA. As of this writing, the finalised version has not yet been published. 

 

A few features of the draft are worth knowing regardless of how the legislative process resolves: 

  • Inherent risk vs. incident-driven risk:  Section 3.1 of the template covers risk that exists even when the processing works exactly as designed and everyone follows the rules. Section 4.1.1 separately covers risk that arises from non-default, accidental, unlawful, or abnormal events. The template treats these as two distinct risk categories, assessed and documented separately. 
  • Voluntary for now, but not indefinitely. Use of the EDPB template is not currently mandatory. But the EDPB is explicit that once finalised, national supervisory authorities will adopt it either as their sole standard or as a 'meta-template' to which national templates must align. If the Omnibus provisions are adopted roughly as proposed, that alignment could become a legal requirement rather than a supervisory practice. 

 

Why this matters before either track is final 

The Omnibus text could still change during negotiations. But the EDPB template already exists, and it's already shaping how supervisory authorities look at DPIAs. Organisations should therefore monitor both developments in parallel, rather than treating only the legislative track as relevant to their compliance planning. 

In conclusion:  

  • Multi-jurisdictional consistency is one of the aims of this part of the proposal. If your DPIAs currently sit alongside country-by-country checks on trigger lists and local guidance, this is the direction things are heading: EU-wide lists and a single meta-template. 
  • Supervisory expectations tend to move faster than legislation. Even absent a legal mandate, an EDPB-endorsed template becomes a reference point DPAs will informally measure DPIAs against during a review or an Article 36 GDPR prior consultation. 

Operationalising it now 

  • Map your current DPIA template's sections against the EDPB template's fields, and adjust your template where necessary, paying particular attention to the design-risk/incident-risk split. 
  • Track the finalised template and the trilogue text separately. The EDPB template's finalisation and the Omnibus's progress through Parliament and Council are on different clocks. 

The direction of travel is clear even if the destination isn't fully mapped: DPIA methodology in the EU is heading toward convergence, not divergence. Organisations that begin working with the EDPB template now, rather than waiting for it to become mandatory, will need far less time to adapt once alignment is formally required. 

At Considerati, we are following these developments closely and will keep sharing updates as they land. If you would like to discuss what DPIA standardisation means for your organisation, we are happy to get in contact.

Begüm Canoglu Consultant Legal & Compliance

Do you want to know more?

Do you have any questions about the above or are you looking for strategic Legal advice? Contact Considerati, we offer specialised advice and tailored support.

Our services orContact