SIS-licensed ISO clauses and controls·an add-on inside the AI clients and agents you already use
    DPIA trigger coverage

    The source receipt behind a jurisdiction-aware DPIA.

    This register shows which national DPIA trigger source Ansvar can retrieve, how the source is characterised, when it was verified, and whether its dedicated query is named in the deployed DPIA workflow.

    Coverage available

    The source can be retrieved with its publisher, status, and citation intact.

    Workflow-integrated

    The deployed DPIA prompt names the national source query for that jurisdiction.

    Document-grounded

    Customer evidence is pinned to the resulting finding on Team and Company.

    Public source register

    Every jurisdiction keeps its own evidence state.

    Operational does not mean identical. Published lists, indicative material, an advisory draft, and a statutory no-list determination stay distinct.

    JurisdictionNational evidence pathSource statusWorkflow stateKnown limitation
    ATAustriaDatenschutzbehördeDSFA-V, BGBl. II 278/2018, and DSFA-AV, BGBl. II 108/2018ris.bka.gv.at · verified 2026-08-14Operational · published national materialNamed source query deployedAustria serves two instruments: the DSFA-V blacklist and the DSFA-AV exceptions list; an activity matching only the DSFA-AV is exempted.
    BEBelgiumGegevensbeschermingsautoriteit / Autorité de protection des donnéesDecision 01/2019, Belgian Official Gazette numac 2019011184ejustice.just.fgov.be · verified 2026-08-14Operational · published national materialNamed source query deployedThe source is served in Dutch and French; applicability remains a controller and DPO decision.
    BGBulgariaCommission for Personal Data ProtectionList of processing operations under Article 35(4), adopted 13 February 2019cpdp.bg · verified 2026-08-15Operational · published national materialNamed source query deployedThe list carries no gazette number; the authority's published page is the instrument. Rows serve bilingually in Bulgarian and English.
    HRCroatiaAgencija za zaštitu osobnih podatakaDecision on the published list, KLASA 004-04/18-01/01azop.hr · verified 2026-08-15Operational · published national materialNamed source query deployedThe authority's published decision page is itself the instrument; no Narodne novine form exists.
    CYCyprusCommissioner for Personal Data ProtectionIndicative DPIA list submitted under Article 35(4)gov.cy · verified 2026-08-15Operational · advisory draftNamed source query deployedThe published English document predates the EDPB opinion and is not presented as a final adopted list.
    CZCzechiaÚřad pro ochranu osobních údajůArticle 35(4) and 35(5) processing lists, version 1.0uoou.gov.cz · verified 2026-08-15Operational · published national materialNamed source query deployedThe positive list uses parametric criteria rather than a simple enumeration.
    DKDenmarkDatatilsynetList of processing activities always subject to a DPIAdatatilsynet.dk · verified 2026-08-14Operational · published national materialNamed source query deployedCriterion matching depends on the processing facts supplied and confirmed in the run.
    EEEstoniaAndmekaitse InspektsioonIsikuandmete töötleja üldjuhend, chapter 5aki.ee · verified 2026-08-15Operational · indicative authority materialNamed source query deployedThe authority characterises the cross-border list as indicative; Ansvar preserves that status.
    FIFinlandOffice of the Data Protection OmbudsmanDecision listing processing operations that require an impact assessmenttietosuoja.fi · verified 2026-08-14Operational · published national materialNamed source query deployedCriterion matching depends on the processing facts supplied and confirmed in the run.
    FRFranceCommission nationale de l'informatique et des libertésDélibération 2018-327, amended by Délibération 2019-011legifrance.gouv.fr · verified 2026-08-13Operational · published national materialNamed source query deployedThe list is served; the national implementation-act check remains open in the program record.
    DEGermanyDatenschutzkonferenzDSK Muss-Liste under Article 35(4), version 1.1datenschutzkonferenz-online.de · verified 2026-08-13Operational · published national materialNamed source query deployedThe competent German authority still depends on the controller's establishment and processing context.
    GRGreeceHellenic Data Protection AuthorityDecision 65/2018, Government Gazette B 1622/10.05.2019Εθνικό Τυπογραφείο · verified 2026-08-15Operational · published national materialNamed source query deployedThe official gazette issue contains unrelated acts; the served source is isolated to the DPIA decision.
    HUHungaryNemzeti Adatvédelmi és Információszabadság HatóságNAIH Article 35(4) list, revised published formnaih.hu · verified 2026-08-15Operational · published national materialNamed source query deployedTwo published forms differ in the wording of the first two items; the revised PDF is served as canonical.
    ISIcelandPersónuverndAuglýsing nr. 828/2019Stjórnartíðindi · verified 2026-08-14Operational · published national materialNamed source query deployedCriterion matching depends on the processing facts supplied and confirmed in the run.
    IEIrelandData Protection CommissionList of processing operations requiring a DPIA, 15 November 2018dataprotection.ie · verified 2026-08-14Operational · published national materialNamed source query deployedThe published list carries ten operation types; an earlier sixteen-type version was a draft.
    ITItalyGarante per la protezione dei dati personaliProvvedimento 467/2018 and Annex 1gazzettaufficiale.it · verified 2026-08-15Operational · published national materialNamed source query deployedThe official-gazette version is the served source of record.
    LVLatviaDatu valsts inspekcijaOrder 1-2.1/125 of 18 December 2018dvi.gov.lv · verified 2026-08-15Operational · published national materialNamed source query deployedThe Article 35(5) not-required list is a separate document and is not substituted for this source.
    LILiechtensteinDatenschutzstelleList under Article 35(4), version 6 August 2020datenschutzstelle.li · verified 2026-08-16Operational · published national materialNamed source query deployedThe 2020 authority version supersedes the 2019 EDPB register mirror.
    LTLithuaniaValstybinė duomenų apsaugos inspekcijaOrder 1T-35 (1.12.E), TAR code 2019-04104Teisės aktų registras · verified 2026-08-15Operational · published national materialNamed source query deployedSub-triggers serve inside their parent categories, so the list counts ten categories rather than sixteen.
    LULuxembourgCommission nationale pour la protection des donnéesDélibération 34/2019cnpd.public.lu · verified 2026-08-15Authority reuse permission pendingRecorded unavailable · no model-memory substituteThe source has been identified and reviewed; reuse permission is required before reproduction through the gateway.
    MTMaltaInformation and Data Protection CommissionerPublished eight-item Article 35(4) listidpc.org.mt · verified 2026-08-15Authority reuse permission pendingRecorded unavailable · no model-memory substituteThe publisher's terms require permission for commercial reproduction; no model-memory substitute is used.
    NLNetherlandsAutoriteit PersoonsgegevensDecision published as Staatscourant 2019, 64418officielebekendmakingen.nl · verified 2026-08-13Operational · published national materialNamed source query deployedCriterion matching depends on the processing facts supplied and confirmed in the run.
    NONorwayDatatilsynetList of processing activities that always require a DPIAdatatilsynet.no · verified 2026-08-14Operational · published national materialNamed source query deployedCriterion matching depends on the processing facts supplied and confirmed in the run.
    PLPolandPrezes Urzędu Ochrony Danych OsobowychCommunication published as M.P. 2019 item 666api.sejm.gov.pl · verified 2026-08-14Operational · published national materialNamed source query deployedThe 2019 communication repeals the earlier list published as M.P. 2018 item 827.
    PTPortugalComissão Nacional de Proteção de DadosRegulamento 1/2018, published as Regulamento 798/2018Diário da República · verified 2026-08-15Operational · published national materialNamed source query deployedThe official portal exposes no verifiable item permalink; citations point to the pinned published PDF.
    RORomaniaAutoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter PersonalDecision 174/2018, Official Gazette I 919/31.10.2018dataprotection.ro · verified 2026-08-15Operational · published national materialNamed source query deployedDecision 174/2018 lists seven processing types, lettered a) to g) in the Official Gazette form.
    SKSlovakiaÚrad na ochranu osobných údajov Slovenskej republikyDemonstrative list of 13 processing operationsdataprotection.gov.sk · verified 2026-08-15Authority reuse permission pendingRecorded unavailable · no model-memory substituteThe source has been identified and reviewed; the legal basis for commercial reuse remains unconfirmed.
    SISloveniaInformacijski pooblaščenecSmernice o ocenah učinkov, version 1.2, annexes 3 and 4ip-rs.si · verified 2026-08-15Operational · published national materialNamed source query deployedOnly the Slovenian authority text is served; the standalone English form is provenance only.
    ESSpainAgencia Española de Protección de DatosListas DPIA, Article 35(4), 11 criteriaaepd.es · verified 2026-08-14Operational · published national materialNamed source query deployedThe authority describes the list as orientative while publishing it under Article 35(4).
    SESwedenIntegritetsskyddsmyndighetenFörteckning under Article 35(4), DI-2018-13200imy.se · verified 2026-08-13Operational · published national materialNamed source query deployedThe list requires a DPIA when at least two of its criteria are met, subject to its stated conditions.
    CHSwitzerlandFederal Data Protection and Information CommissionerFederal Act on Data Protection, Articles 22 and 23fedlex.admin.ch · verified 2026-08-16Operational · statutory no-list determinationNamed source query deployedSwiss law creates no national-list mechanism; screening uses the statutory high-risk and consultation provisions.
    GBUnited KingdomInformation Commissioner's OfficeExamples of processing likely to result in high riskico.org.uk · verified 2026-08-14Operational · published national materialNamed source query deployedThe UK GDPR and Data Protection Act context must be assessed separately from EU territorial scope.
    Source governance

    Unavailable stays unavailable.

    For Luxembourg, Malta, Slovakia, Ansvar has identified and reviewed the source but does not reproduce it through the gateway. The workflow records the jurisdictional source as unavailable instead of rebuilding it from model memory.

    LuxembourgThe source has been identified and reviewed; reuse permission is required before reproduction through the gateway.
    MaltaThe publisher's terms require permission for commercial reproduction; no model-memory substitute is used.
    SlovakiaThe source has been identified and reviewed; the legal basis for commercial reuse remains unconfirmed.
    Questions buyers ask

    What the coverage claim means.

    Can a DPIA be fully automated?
    No. Ansvar can retrieve the relevant source material, test documented processing facts against recorded criteria, and assemble the assessment file. The controller and DPO retain the decisions on territorial scope, necessity, proportionality, residual risk, and sign-off.
    How does Ansvar check national Article 35 DPIA lists?
    The workflow starts with the GDPR baseline, then queries the official national source named for each confirmed jurisdiction. A result records the publisher, source status, citation, verification context, and whether the supplied facts match a documented criterion.
    Which European jurisdictions are operational?
    29 of the 32 jurisdictions in this program have an operational evidence path. Luxembourg, Malta, and Slovakia remain unavailable for reproduction while authority reuse permission or its legal basis is pending.
    What happens when authority material is advisory or draft?
    The result keeps that status. Indicative guidance and an advisory draft are not presented as adopted mandatory lists, and a reviewer sees the qualification beside any surfaced criterion.
    What happens when Ansvar cannot legally reproduce a source?
    The workflow records the national source as unavailable. It does not reconstruct the source from model memory or substitute generic GDPR guidance without saying so.
    Does Ansvar replace the controller or DPO?
    No. Ansvar assembles cited evidence and applies the documented workflow gates. The controller and DPO own applicability, professional judgment, risk acceptance, and approval.
    Can the same processing activity be screened across multiple countries?
    Yes, once the user or DPO confirms the jurisdictions to assess. The output keeps a separate evidence receipt for each jurisdiction instead of collapsing national sources into one generic result.
    Can the DPIA be grounded in our RoPA, contracts, and policies?
    Team and Company can bind supported workflow findings to customer documents with paragraph-level citations. The pricing page states the document and audit-receipt boundaries for each plan.