Privacy Threshold Analysis Before The DPIA
A supervisory authority asks why your new recruitment tool never had a data protection impact assessment. You believe the answer is that it was low risk. Can you show the reasoning, dated, from before the tool went live. The privacy threshold analysis exists for exactly that moment, and it is the stage most programmes skip.
The privacy threshold analysis comes from US practice
The term is not European. It comes from the way US federal agencies implement their own assessment duty.
The Department of Homeland Security runs a privacy threshold analysis on every new project. DHS describes it as “an internal DHS questionnaire used to identify if personally identifiable information (PII) is collected, maintained, used, or disseminated by a form, new project, pilot, program, rule, information collection, or system”. The same document is “the formal mechanism used by the DHS Privacy Office to determine if a program/system is privacy sensitive; and if additional privacy compliance documentation, such as a Privacy Act Statement, Privacy Impact Assessment (PIA) and/or System of Records Notice (SORN), is required”.
Three features are worth carrying into any exam answer. The programme manager completes it with the component privacy officer, so the business owns the input. Adjudication sits with the privacy office, so the specialist owns the conclusion. Recertification falls due every three years, because the document expires.
Other agencies run the same idea under other names. GSA calls its version a privacy threshold assessment. Justice calls its own an Initial Privacy Assessment, “the first step in a process developed by OPCL to assist DOJ components in the development and use of information systems”.
The statute never asked for it
Here is the part candidates find surprising. Section 208 of the E-Government Act of 2002 tells agencies to conduct a privacy impact assessment. The duty bites before they develop or procure information technology handling information in identifiable form. It says nothing about a threshold step. No statute mentions a privacy threshold analysis at all.
Agencies invented the privacy threshold analysis because the statutory duty is conditional. Every conditional duty produces two decisions. Only one of them generates a document, unless somebody builds an instrument for the other.
The GDPR has the same gap
Article 35(1) works the same way. Where processing “is likely to result in a high risk to the rights and freedoms of natural persons”, the controller shall carry out an assessment before the processing. High risk is the trigger. No trigger, no DPIA.
Three cases appear in Article 35(3) as requiring an assessment in particular. Systematic and extensive automated evaluation producing legal or similarly significant effects. Large-scale processing of special category or criminal offence data. Systematic monitoring of a publicly accessible area on a large scale. Article 35(4) then requires each supervisory authority to publish a list of processing that needs one. Article 35(5) lets it publish a list of processing that does not, which is a privacy threshold analysis performed by the regulator on your behalf.
Read Article 35 from end to end and you will find no privacy threshold analysis in it. Nothing there obliges you to record why the trigger was not met. That silence is where programmes come unstuck.
The nine criteria, and the two-criteria rule
The screening test everyone actually uses is older than any of this. It came from the Article 29 Working Party in October 2017, and the European Data Protection Board endorsed those guidelines in May 2018. The ICO sets out the nine criteria as:
- Evaluation or scoring
- Automated decision-making with legal or similar significant effect
- Systematic monitoring
- Sensitive data or data of a highly personal nature
- Data processed on a large scale
- Matching or combining datasets
- Data concerning vulnerable data subjects
- Innovative use or applying new technological or organisational solutions
- Preventing data subjects from exercising a right or using a service or contract
The counting rule is where CIPM items get their teeth. Quoting the guidelines, the EDPB says a controller can usually treat two criteria as requiring a DPIA. It then adds that “in some cases a data controller can consider that a processing meeting only one of these criteria requires a DPIA”. The ICO puts it more briefly. Two factors usually indicate the need, and no strict rule applies.
So a privacy threshold analysis produces a judgement, not an arithmetic result. That is precisely why the judgement needs recording.
Which article demands the privacy threshold analysis
Article 35(1) does not require you to document a negative conclusion. Two other provisions do the work.
Article 5(2) makes the controller “responsible for, and be able to demonstrate compliance with” the principles. Article 24(1) goes further. The controller’s measures must ensure and “be able to demonstrate that processing is performed in accordance with this Regulation”. A privacy threshold analysis satisfies the demonstrate limb of both, cheaply.
Regulators say so directly. You may justify a decision not to carry out a DPIA, on the ICO’s view, where you are confident the processing is unlikely to result in high risk. Then comes the qualifier: “but you should document your reasons”. Its screening checklist ends with the line that matters. “If we decide not to carry out a DPIA, we document our reasons.”
The Irish Data Protection Commission raises the bar in its guide to DPIAs_Oct19.pdf). Suppose a processing operation meets at least two criteria and the controller still judges it low risk. That controller “should thoroughly document the reasons for not carrying out a DPIA”. A thin privacy threshold analysis will not survive that standard.
What may change
The Commission’s Digital Omnibus proposal of November 2025 would harmonise the Article 35(4) and 35(5) lists at EU level. It would also add a common template and methodology for assessments. The EDPB and EDPS supported that harmonisation in a joint opinion in February 2026.
Treat it as a proposal and nothing more. As at August 2026 it sits at first reading, unadopted, so Article 35 reads exactly as it always has. Answer from the adopted text.
How CIPM frames it
The Body of Knowledge is the IAPP’s published map of what each exam covers, and this material sits in the domain on sustaining programme performance, alongside the other assessment types. You are expected to sequence them. A privacy threshold analysis comes first. A full assessment follows where the threshold is crossed, and the specialist assessments for transfers and legitimate interests come after that.
Scenario questions usually attack the sequence rather than the definitions. Run straight to a DPIA on everything and the programme becomes unsustainable. Run one on nothing and there is no evidence. A privacy threshold analysis is what separates those two failures. The privacy threshold analysis is what makes the middle position defensible, which is the same instinct that decides which governance model fits an organisation and drives privacy due diligence in acquisitions.
If you want to know whether the assessment family is costing you marks, sit the CIPM trial exam and look at where the sequencing items fell. Where the problem is reading the question rather than knowing the material, the CIPM Exam Question Masterclass is the faster fix.
