The source can be retrieved with its publisher, status, and citation intact.
DPIA trigger coverage
The source receipt behind a jurisdiction-aware DPIA.
This register shows which national DPIA trigger source Ansvar can retrieve, how the source is characterised, when it was verified, and whether its dedicated query is named in the deployed DPIA workflow.
The deployed DPIA prompt names the national source query for that jurisdiction.
Customer evidence is pinned to the resulting finding on Team and Company.
Public source register
Every jurisdiction keeps its own evidence state.
Operational does not mean identical. Published lists, indicative material, an advisory draft, and a statutory no-list determination stay distinct.
| Jurisdiction | National evidence path | Source status | Workflow state | Known limitation |
|---|---|---|---|---|
| ATAustriaDatenschutzbehörde | DSFA-V, BGBl. II 278/2018, and DSFA-AV, BGBl. II 108/2018ris.bka.gv.at · verified 2026-08-14 | Operational · published national material | Named source query deployed | Austria serves two instruments: the DSFA-V blacklist and the DSFA-AV exceptions list; an activity matching only the DSFA-AV is exempted. |
| BEBelgiumGegevensbeschermingsautoriteit / Autorité de protection des données | Decision 01/2019, Belgian Official Gazette numac 2019011184ejustice.just.fgov.be · verified 2026-08-14 | Operational · published national material | Named source query deployed | The source is served in Dutch and French; applicability remains a controller and DPO decision. |
| BGBulgariaCommission for Personal Data Protection | List of processing operations under Article 35(4), adopted 13 February 2019cpdp.bg · verified 2026-08-15 | Operational · published national material | Named source query deployed | The list carries no gazette number; the authority's published page is the instrument. Rows serve bilingually in Bulgarian and English. |
| HRCroatiaAgencija za zaštitu osobnih podataka | Decision on the published list, KLASA 004-04/18-01/01azop.hr · verified 2026-08-15 | Operational · published national material | Named source query deployed | The authority's published decision page is itself the instrument; no Narodne novine form exists. |
| CYCyprusCommissioner for Personal Data Protection | Indicative DPIA list submitted under Article 35(4)gov.cy · verified 2026-08-15 | Operational · advisory draft | Named source query deployed | The published English document predates the EDPB opinion and is not presented as a final adopted list. |
| CZCzechiaÚřad pro ochranu osobních údajů | Article 35(4) and 35(5) processing lists, version 1.0uoou.gov.cz · verified 2026-08-15 | Operational · published national material | Named source query deployed | The positive list uses parametric criteria rather than a simple enumeration. |
| DKDenmarkDatatilsynet | List of processing activities always subject to a DPIAdatatilsynet.dk · verified 2026-08-14 | Operational · published national material | Named source query deployed | Criterion matching depends on the processing facts supplied and confirmed in the run. |
| EEEstoniaAndmekaitse Inspektsioon | Isikuandmete töötleja üldjuhend, chapter 5aki.ee · verified 2026-08-15 | Operational · indicative authority material | Named source query deployed | The authority characterises the cross-border list as indicative; Ansvar preserves that status. |
| FIFinlandOffice of the Data Protection Ombudsman | Decision listing processing operations that require an impact assessmenttietosuoja.fi · verified 2026-08-14 | Operational · published national material | Named source query deployed | Criterion matching depends on the processing facts supplied and confirmed in the run. |
| FRFranceCommission nationale de l'informatique et des libertés | Délibération 2018-327, amended by Délibération 2019-011legifrance.gouv.fr · verified 2026-08-13 | Operational · published national material | Named source query deployed | The list is served; the national implementation-act check remains open in the program record. |
| DEGermanyDatenschutzkonferenz | DSK Muss-Liste under Article 35(4), version 1.1datenschutzkonferenz-online.de · verified 2026-08-13 | Operational · published national material | Named source query deployed | The competent German authority still depends on the controller's establishment and processing context. |
| GRGreeceHellenic Data Protection Authority | Decision 65/2018, Government Gazette B 1622/10.05.2019Εθνικό Τυπογραφείο · verified 2026-08-15 | Operational · published national material | Named source query deployed | The official gazette issue contains unrelated acts; the served source is isolated to the DPIA decision. |
| HUHungaryNemzeti Adatvédelmi és Információszabadság Hatóság | NAIH Article 35(4) list, revised published formnaih.hu · verified 2026-08-15 | Operational · published national material | Named source query deployed | Two published forms differ in the wording of the first two items; the revised PDF is served as canonical. |
| ISIcelandPersónuvernd | Auglýsing nr. 828/2019Stjórnartíðindi · verified 2026-08-14 | Operational · published national material | Named source query deployed | Criterion matching depends on the processing facts supplied and confirmed in the run. |
| IEIrelandData Protection Commission | List of processing operations requiring a DPIA, 15 November 2018dataprotection.ie · verified 2026-08-14 | Operational · published national material | Named source query deployed | The published list carries ten operation types; an earlier sixteen-type version was a draft. |
| ITItalyGarante per la protezione dei dati personali | Provvedimento 467/2018 and Annex 1gazzettaufficiale.it · verified 2026-08-15 | Operational · published national material | Named source query deployed | The official-gazette version is the served source of record. |
| LVLatviaDatu valsts inspekcija | Order 1-2.1/125 of 18 December 2018dvi.gov.lv · verified 2026-08-15 | Operational · published national material | Named source query deployed | The Article 35(5) not-required list is a separate document and is not substituted for this source. |
| LILiechtensteinDatenschutzstelle | List under Article 35(4), version 6 August 2020datenschutzstelle.li · verified 2026-08-16 | Operational · published national material | Named source query deployed | The 2020 authority version supersedes the 2019 EDPB register mirror. |
| LTLithuaniaValstybinė duomenų apsaugos inspekcija | Order 1T-35 (1.12.E), TAR code 2019-04104Teisės aktų registras · verified 2026-08-15 | Operational · published national material | Named source query deployed | Sub-triggers serve inside their parent categories, so the list counts ten categories rather than sixteen. |
| LULuxembourgCommission nationale pour la protection des données | Délibération 34/2019cnpd.public.lu · verified 2026-08-15 | Recorded unavailable · no model-memory substitute | The source has been identified and reviewed; reuse permission is required before reproduction through the gateway. | |
| MTMaltaInformation and Data Protection Commissioner | Published eight-item Article 35(4) listidpc.org.mt · verified 2026-08-15 | Recorded unavailable · no model-memory substitute | The publisher's terms require permission for commercial reproduction; no model-memory substitute is used. | |
| NLNetherlandsAutoriteit Persoonsgegevens | Decision published as Staatscourant 2019, 64418officielebekendmakingen.nl · verified 2026-08-13 | Operational · published national material | Named source query deployed | Criterion matching depends on the processing facts supplied and confirmed in the run. |
| NONorwayDatatilsynet | List of processing activities that always require a DPIAdatatilsynet.no · verified 2026-08-14 | Operational · published national material | Named source query deployed | Criterion matching depends on the processing facts supplied and confirmed in the run. |
| PLPolandPrezes Urzędu Ochrony Danych Osobowych | Communication published as M.P. 2019 item 666api.sejm.gov.pl · verified 2026-08-14 | Operational · published national material | Named source query deployed | The 2019 communication repeals the earlier list published as M.P. 2018 item 827. |
| PTPortugalComissão Nacional de Proteção de Dados | Regulamento 1/2018, published as Regulamento 798/2018Diário da República · verified 2026-08-15 | Operational · published national material | Named source query deployed | The official portal exposes no verifiable item permalink; citations point to the pinned published PDF. |
| RORomaniaAutoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal | Decision 174/2018, Official Gazette I 919/31.10.2018dataprotection.ro · verified 2026-08-15 | Operational · published national material | Named source query deployed | Decision 174/2018 lists seven processing types, lettered a) to g) in the Official Gazette form. |
| SKSlovakiaÚrad na ochranu osobných údajov Slovenskej republiky | Demonstrative list of 13 processing operationsdataprotection.gov.sk · verified 2026-08-15 | Recorded unavailable · no model-memory substitute | The source has been identified and reviewed; the legal basis for commercial reuse remains unconfirmed. | |
| SISloveniaInformacijski pooblaščenec | Smernice o ocenah učinkov, version 1.2, annexes 3 and 4ip-rs.si · verified 2026-08-15 | Operational · published national material | Named source query deployed | Only the Slovenian authority text is served; the standalone English form is provenance only. |
| ESSpainAgencia Española de Protección de Datos | Listas DPIA, Article 35(4), 11 criteriaaepd.es · verified 2026-08-14 | Operational · published national material | Named source query deployed | The authority describes the list as orientative while publishing it under Article 35(4). |
| SESwedenIntegritetsskyddsmyndigheten | Förteckning under Article 35(4), DI-2018-13200imy.se · verified 2026-08-13 | Operational · published national material | Named source query deployed | The list requires a DPIA when at least two of its criteria are met, subject to its stated conditions. |
| CHSwitzerlandFederal Data Protection and Information Commissioner | Federal Act on Data Protection, Articles 22 and 23fedlex.admin.ch · verified 2026-08-16 | Operational · statutory no-list determination | Named source query deployed | Swiss law creates no national-list mechanism; screening uses the statutory high-risk and consultation provisions. |
| GBUnited KingdomInformation Commissioner's Office | Examples of processing likely to result in high riskico.org.uk · verified 2026-08-14 | Operational · published national material | Named source query deployed | The UK GDPR and Data Protection Act context must be assessed separately from EU territorial scope. |
Source governance
Unavailable stays unavailable.
For Luxembourg, Malta, Slovakia, Ansvar has identified and reviewed the source but does not reproduce it through the gateway. The workflow records the jurisdictional source as unavailable instead of rebuilding it from model memory.
Questions buyers ask
What the coverage claim means.
- Can a DPIA be fully automated?
- No. Ansvar can retrieve the relevant source material, test documented processing facts against recorded criteria, and assemble the assessment file. The controller and DPO retain the decisions on territorial scope, necessity, proportionality, residual risk, and sign-off.
- How does Ansvar check national Article 35 DPIA lists?
- The workflow starts with the GDPR baseline, then queries the official national source named for each confirmed jurisdiction. A result records the publisher, source status, citation, verification context, and whether the supplied facts match a documented criterion.
- Which European jurisdictions are operational?
- 29 of the 32 jurisdictions in this program have an operational evidence path. Luxembourg, Malta, and Slovakia remain unavailable for reproduction while authority reuse permission or its legal basis is pending.
- What happens when authority material is advisory or draft?
- The result keeps that status. Indicative guidance and an advisory draft are not presented as adopted mandatory lists, and a reviewer sees the qualification beside any surfaced criterion.
- What happens when Ansvar cannot legally reproduce a source?
- The workflow records the national source as unavailable. It does not reconstruct the source from model memory or substitute generic GDPR guidance without saying so.
- Does Ansvar replace the controller or DPO?
- No. Ansvar assembles cited evidence and applies the documented workflow gates. The controller and DPO own applicability, professional judgment, risk acceptance, and approval.
- Can the same processing activity be screened across multiple countries?
- Yes, once the user or DPO confirms the jurisdictions to assess. The output keeps a separate evidence receipt for each jurisdiction instead of collapsing national sources into one generic result.
- Can the DPIA be grounded in our RoPA, contracts, and policies?
- Team and Company can bind supported workflow findings to customer documents with paragraph-level citations. The pricing page states the document and audit-receipt boundaries for each plan.