Skip to main content
Category: Impact Assessments & Documentation

Whitelist of Processing Not Requiring a DPIA

Also known as: DPIA White List, White List (DPIA), List of processing operations not requiring a DPIA
Simply put

A whitelist is a list, published by a data protection authority, of processing activities that are considered unlikely to result in a high risk to individuals and therefore generally do not require a Data Protection Impact Assessment (DPIA). It is intended to give organisations clarity about which routine operations they can carry out without conducting a DPIA. Being on such a list does not guarantee lawfulness of the processing overall; it only addresses the DPIA obligation, and the position can differ between jurisdictions.

Formal definition

A whitelist (or 'list of processing operations not requiring a DPIA') is a list adopted by a supervisory authority identifying processing operations that are unlikely to result in a high risk to the rights and freedoms of natural persons, and for which a DPIA is accordingly not mandated. It functions as the counterpart to the 'blacklist' of processing likely to result in high risk (for which a DPIA is required). Whitelists are jurisdiction-specific: their content and existence can vary between EU member states and the UK, and a blacklist entry in the relevant jurisdiction can override a whitelist exemption. Inclusion on a whitelist addresses only the threshold question of whether a DPIA is triggered; it does not establish a lawful basis under Article 6, satisfy any additional Article 9 condition for special category data, or otherwise render the processing compliant. Processing not covered by a blacklist may still require a DPIA where it is likely to result in high risk. Readers should verify the current published lists for each applicable jurisdiction against official authority sources, as these may be updated over time.

Why it matters

The DPIA obligation under the GDPR is a threshold question that organisations must resolve before undertaking many processing activities, and getting it wrong in either direction carries cost. Conducting a full assessment for genuinely low-risk, routine processing wastes limited compliance resources, while failing to conduct one where the processing is likely to result in a high risk exposes the organisation to regulatory criticism. A whitelist published by a supervisory authority gives organisations a degree of certainty that specific, well-understood operations can generally proceed without a DPIA, allowing teams to prioritise their assessment efforts where risk is more likely to arise.

The value of a whitelist is bounded, and misreading its scope is a common trap. Inclusion on a whitelist addresses only whether a DPIA is triggered; it does not establish a lawful basis under Article 6, satisfy any additional condition required for special category data under Article 9, or otherwise render the processing compliant. An organisation can correctly conclude no DPIA is required and still be processing unlawfully for other reasons. Treating a whitelist entry as a general clearance for an activity is therefore a mistake that a well-run compliance programme should guard against.

Whitelists are also jurisdiction-specific, which matters for any organisation operating across borders. Their content and even their existence can vary between EU member states and the UK, and a blacklist entry in the relevant jurisdiction can override a whitelist exemption drawn from elsewhere. Processing that appears on no blacklist may still require a DPIA where it is likely to result in a high risk. Because these lists can be updated over time, organisations should verify the current published lists against official authority sources rather than relying on a past snapshot.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams use whitelists to calibrate their organisation's DPIA screening process, directing assessment effort toward higher-risk operations while documenting why routine, listed activities were exempted. They should confirm they are relying on the current, jurisdiction-appropriate list and remain alert to the fact that a whitelist entry does not resolve lawful basis or special category conditions.
Compliance and governance functions
Teams responsible for accountability and governance can incorporate whitelist references into internal DPIA policies and screening templates. They should build in checks for blacklist overrides in the relevant jurisdiction and avoid presenting whitelist inclusion to the business as general clearance for an activity.
Legal advisers and multinational operators
Lawyers advising organisations that process personal data across the EU and UK need to account for the jurisdiction-specific nature of these lists, since content and existence can vary between member states and the UK. They should verify the applicable published lists against official authority sources, particularly where a single activity spans multiple jurisdictions with differing positions.
Engineers and product teams
Those designing systems and features benefit from early clarity on whether a proposed processing operation is likely to require a DPIA. A whitelist can indicate that certain routine operations generally do not, but engineers should escalate novel uses of technology or activities not clearly covered by a list, as these may still require assessment where high risk is likely.

Inside Whitelist of Processing Not Requiring a DPIA

Article 35(5) legal basis
The GDPR provides that a supervisory authority may, and shall make public, an optional list of the kinds of processing operations for which no data protection impact assessment (DPIA) is required. This is the counterpart to the mandatory 'blacklist' under Article 35(4). Practitioners should verify the exact wording and cross-references against the current official text.
Optional, authority-specific nature
Unlike the Article 35(4) list of processing requiring a DPIA (which supervisory authorities must establish), the whitelist under Article 35(5) is discretionary. As a result, not every member state supervisory authority has published one, and content can diverge between authorities.
Processing operations 'not likely to result in a high risk'
The whitelist identifies types or categories of processing that, in the authority's assessment, do not meet the high-risk threshold that triggers the DPIA obligation. Inclusion reflects a generalised risk assessment rather than a guarantee for any specific processing activity.
Consistency mechanism involvement
Where a list may affect processing that relates to the provision of goods or services to data subjects, or the monitoring of behaviour, in several member states, or otherwise has cross-border relevance, the relevant cooperation and consistency procedures involving the European Data Protection Board can apply before adoption. Practitioners should confirm the applicable procedure for the authority in question.
Relationship to the broader DPIA framework
A whitelist entry addresses only whether a DPIA is required; it does not remove other GDPR obligations such as identifying an Article 6 legal basis, meeting any additional Article 9 condition for special category data, applying data protection by design and by default, and maintaining records of processing.

Common questions

Answers to the questions practitioners most commonly ask about Whitelist of Processing Not Requiring a DPIA.

Does the existence of a whitelist mean the listed processing is automatically compliant with the GDPR?
No. A whitelist (sometimes called a list of processing operations not requiring a Data Protection Impact Assessment) addresses only whether the specific obligation to carry out a DPIA under Article 35 is triggered. It does not exempt a controller from any other GDPR obligation, such as identifying a valid Article 6 legal basis, meeting Article 9 conditions for special category data, honouring data subject rights, or applying data protection by design. Appearing on the list generally means a DPIA is not mandatory for that operation, not that the processing is fully compliant, which remains a context-dependent assessment.
Is a single EU-wide whitelist in force that applies uniformly across all member states?
Not in the way that phrasing suggests. Under Article 35, supervisory authorities may establish and publish lists of processing operations for which a DPIA is not required, and these are adopted at the national level. As a result, the content of such lists can differ between member states, and not every authority has published one. Where processing crosses borders, the consistency mechanism and cooperation between authorities are relevant. You should verify the position with each relevant supervisory authority rather than assume a harmonised list, and note that lists can be revised over time.
How should we check whether our processing falls within a whitelist entry?
Identify the supervisory authority or authorities competent for your processing, then review any list of operations not requiring a DPIA that they have published. Compare the precise scope, purpose, data categories, and safeguards described in the list entry against your actual operation. Whitelist entries are typically narrowly framed, so a superficial match to a category label is generally insufficient. If your operation deviates in scope or introduces additional risk factors, it may fall outside the entry. Document the comparison, and where the fit is uncertain, treat the entry as not conclusively applicable.
Should we still document our decision when a whitelist entry applies?
Yes, as a matter of good practice consistent with the accountability principle. Even where a DPIA is not mandatory, recording why you concluded the operation falls within a listed entry, and confirming that no other DPIA trigger under Article 35 applies, helps demonstrate that the decision was reasoned. This record is generally distinct from a DPIA itself and is usually lighter in form, but it supports your ability to justify the position to a supervisory authority on request.
If our processing appears on a whitelist, can we skip assessing risk altogether?
Generally no. The whitelist affects the formal DPIA obligation, but controllers remain subject to broader risk-based duties, including implementing appropriate technical and organisational measures and applying data protection by design and by default. In most cases a proportionate risk consideration is still advisable, particularly because the factors that placed an operation on a list may change if you alter its scope, add data categories, or introduce new technologies. A material change may take the operation outside the entry and reintroduce a DPIA requirement.
What should we do if our processing partly matches a whitelist entry but includes additional elements?
Treat a partial match cautiously. Whitelist entries are typically defined by specific conditions, and additional elements, such as broader data categories, larger scale, more intrusive techniques, or use of special category data, may take the operation beyond the listed scope. Where the fit is not clear, the prudent approach is generally to assess whether the standard Article 35 criteria for a DPIA are met and, if in doubt, to carry out or begin a DPIA. Documenting the reasoning behind either conclusion supports accountability. Where uncertainty remains, consider consulting the relevant supervisory authority's current guidance.

Common misconceptions

If a processing activity appears on a whitelist, it is fully compliant and no further privacy work is needed.
A whitelist entry generally means only that a DPIA is not required for that type of processing. All other applicable GDPR obligations continue to apply, and the controller remains responsible for demonstrating compliance. Whether an activity truly falls within an entry is subject to assessment of the specific circumstances.
There is a single EU-wide whitelist that applies uniformly across all member states.
The list under Article 35(5) is optional and authority-specific. Not all supervisory authorities have adopted one, and their contents can differ. The position may also vary under the UK GDPR and national implementing law, so the applicable authority's own list should be consulted.
Appearing on a whitelist permanently exempts an activity from ever needing a DPIA.
The exemption is not absolute or fixed. Changes to the processing, the technology, or the risk profile can move an activity outside an entry, and authorities can revise their lists. A reassessment is generally advisable when circumstances change.

Best practices

Consult the whitelist published by the supervisory authority actually competent for your processing, and verify its current wording and scope against the official source rather than relying on a copy or summary.
Document a short assessment showing why a specific activity genuinely falls within a whitelist entry, since inclusion depends on the facts and remains the controller's responsibility to justify.
Continue to satisfy all other applicable obligations independently of the DPIA question, including identifying an Article 6 legal basis, meeting any additional Article 9 condition for special category data, and applying data protection by design and by default.
Treat the absence of a DPIA requirement as provisional: re-evaluate whenever the processing, technology, scale, or risk profile changes, or where cross-border relevance may bring in cooperation procedures.
For processing spanning multiple member states, check whether differing national lists apply and confirm the applicable position, as coverage and content can diverge.
Where uncertainty exists about whether an entry applies, err toward conducting a DPIA or seeking guidance, since compliance is context and risk dependent.