Conducting Prior Consultation with Supervisory Authority
Overview
Article 36(1) requires the controller to consult the supervisory authority prior to processing where a DPIA under Art. 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. Prior consultation is the final safety net when a DPIA reveals risks that cannot be adequately mitigated through technical, organisational, or contractual measures. The supervisory authority has up to 8 weeks (extendable by 6 weeks) to provide written advice. Processing must not commence until the supervisory authority's response is received and addressed.
When Prior Consultation Is Required
Art. 36(1) Trigger
Prior consultation is mandatory when:
- A DPIA has been conducted under Art. 35
- The DPIA identifies that processing would result in high risk
- The controller cannot sufficiently mitigate the risk through available measures
- Residual risk remains High or Very High despite all reasonable mitigations
Residual Risk Assessment
| Residual Risk Level |
Action |
| Low |
No prior consultation needed. Processing may proceed. |
| Medium |
No prior consultation required, but DPO should document the acceptance rationale. |
| High |
Prior consultation recommended. Processing should not proceed without SA review. |
| Very High |
Prior consultation mandatory under Art. 36(1). Processing must not proceed. |
Practical Examples Triggering Prior Consultation
- Large-scale biometric identification in publicly accessible areas where encryption with exporter-held key is not feasible
- AI system making automated decisions about access to essential services (credit, insurance, healthcare) where residual discrimination risk cannot be fully eliminated
- Processing of genetic data for a novel purpose where no existing Art. 9(2) exemption clearly applies
- Employee monitoring system where proportionality concerns remain despite all mitigations
- International transfer to a country with Very High government access risk where the processing requires clear-text data access
Art. 36(3) Required Documentation
The controller must provide the supervisory authority with the following information:
| Document |
Content |
Art. 36(3) Reference |
| DPIA report |
Complete DPIA per Art. 35(7) including systematic description, necessity/proportionality, risk assessment, and mitigation measures |
Art. 36(3)(a) — implicit |
| Controller and processor responsibilities |
Clear documentation of which entity is responsible for which processing operations and security measures |
Art. 36(3)(a) |
| Measures and safeguards |
All technical, organisational, and contractual measures implemented to protect data subjects |
Art. 36(3)(b) |
| DPO contact details |
Contact details of the Data Protection Officer |
Art. 36(3)(c) |
| Additional information requested |
Any further information the supervisory authority requests during the consultation |
Art. 36(3)(d) |
Supplementary Documentation (Best Practice)
| Document |
Purpose |
| Executive summary |
1-2 page summary of the processing, identified risks, and reasons for prior consultation |
| Data flow diagram |
Visual representation of personal data flows through the processing |
| Risk register |
Detailed risk register with inherent and residual risk levels |
| Mitigation measures schedule |
Implementation status and timeline for all mitigations |
| DPO advice letter |
Written DPO advice per Art. 35(2) and whether it was followed |
| Legitimate interest assessment |
If processing relies on Art. 6(1)(f), the documented LIA |
| Art. 35(9) consultation evidence |
Documentation of data subject views sought |
Consultation Process
Step 1: Preparation (Weeks 1-2)
- DPO confirms that prior consultation is required based on DPIA residual risk assessment.
- Processing owner compiles the Art. 36(3) documentation package.
- DPO reviews the package for completeness and accuracy.
- Legal counsel reviews for legal accuracy and strategic considerations.
- Senior management is briefed on the prior consultation and its implications (processing pause).
Step 2: Submission (Week 3)
- Identify the competent supervisory authority:
- Lead SA under one-stop-shop mechanism (Art. 56) for cross-border processing
- Local SA for purely national processing
- Submit the consultation package through the SA's designated channel (online portal, registered mail, or both per SA requirements).
- Confirm receipt and obtain a case reference number.
- Document the submission date — this starts the 8-week clock.
Step 3: Supervisory Authority Review Period (Weeks 3-11)
Art. 36(2) timeline:
- Standard period: Up to 8 weeks from receipt of the complete consultation request
- Extension: The SA may extend the period by up to 6 weeks for complex cases, with notification to the controller within the first month
- Total maximum: 14 weeks (8 + 6)
During this period:
- The SA may request additional information under Art. 36(3)(d). The 8-week clock pauses until the information is provided.
- The DPO serves as the point of contact for SA communications.
- Processing must not commence during the consultation period.
- The controller should continue implementing mitigation measures in preparation.
Step 4: Outcome Management
| SA Response |
Controller Action |
| Written advice with no concerns |
Document the SA's response. Proceed with processing. Update DPIA with SA clearance. |
| Written advice with recommendations |
Implement the SA's recommendations. Update DPIA. Proceed with processing once recommendations are addressed. |
| Written advice indicating GDPR infringement |
Do not proceed with processing as described. Review processing design to address SA concerns. Consider re-submission after modifications. |
| No response within the statutory period |
SA silence does not constitute approval. The controller bears responsibility for demonstrating compliance. Proceed with caution, documenting the SA's non-response. |
| Request for more information |
Provide the requested information promptly. The clock pauses. |
Step 5: Post-Consultation
- Document the entire consultation process and outcome in the DPIA register.
- Update the DPIA with any SA recommendations or requirements.
- If processing proceeds, implement all SA-recommended measures.
- Schedule an accelerated DPIA review (6 months post-processing commencement).
- Maintain the consultation documentation for supervisory authority inspection.
National Supervisory Authority Consultation Procedures
| SA |
Submission Method |
Specific Requirements |
| ICO (UK) |
Online consultation request form |
Include DPIA, data flow diagram, DPO contact, description of why risk cannot be mitigated |
| CNIL (France) |
Online portal (teleservice.cnil.fr) |
DPIA in CNIL format; French language required |
| BfDI (Germany) |
Written submission to the competent state or federal DPA |
German language; DPIA must reference BDSG provisions |
| Garante (Italy) |
PEC (certified email) |
Italian language; include DPIA, processor agreements, security measures documentation |
| AEPD (Spain) |
Sede Electronica portal |
Spanish language; include DPIA and all supporting documentation |
| DPC Ireland |
Online submission through DPC website |
English language; include DPIA and all Art. 36(3) documentation |
Common Prior Consultation Mistakes
- Consulting too early: Submitting before completing the DPIA and implementing all feasible mitigations. The SA expects to see that all reasonable measures have been taken.
- Consulting too late: Beginning processing before the SA responds. Processing must not start during the consultation period.
- Incomplete documentation: Submitting without all Art. 36(3) required documents, causing delays for information requests.
- No DPO involvement: Submitting without documented DPO advice per Art. 35(2).
- Treating SA silence as approval: SA non-response does not constitute approval or endorsement.
- Failing to implement SA recommendations: Proceeding with processing without addressing SA feedback.
Enforcement Context
- Art. 36(1) non-compliance (failure to consult when required) can result in administrative fines up to EUR 10 million or 2% of annual worldwide turnover under Art. 83(4)(a).
- Swedish DPA vs Karolinska (2019): Fine included failure to conduct DPIA and consequent failure to identify need for prior consultation.
- Norwegian DPA vs Municipality (2020): Enforcement action for proceeding with high-risk processing without prior consultation.
1---2name: prior-consultation-dpa3description: Guides the Art. 36 prior consultation process when a DPIA indicates high residual risk that cannot be mitigated. Covers required documentation per Art. 36(3), the 8-week DPA response timeline, outcome management, and interaction protocols with supervisory authorities. Keywords: prior consultation, Art. 36, supervisory authority, DPA, high residual risk, DPIA escalation, consultation documentation.4license: Apache-2.05---67# Conducting Prior Consultation with Supervisory Authority89## Overview1011Article 36(1) requires the controller to consult the supervisory authority prior to processing where a DPIA under Art. 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. Prior consultation is the final safety net when a DPIA reveals risks that cannot be adequately mitigated through technical, organisational, or contractual measures. The supervisory authority has up to 8 weeks (extendable by 6 weeks) to provide written advice. Processing must not commence until the supervisory authority's response is received and addressed.1213## When Prior Consultation Is Required1415### Art. 36(1) Trigger1617Prior consultation is mandatory when:181. A DPIA has been conducted under Art. 35192. The DPIA identifies that processing would result in high risk203. The controller cannot sufficiently mitigate the risk through available measures214. Residual risk remains High or Very High despite all reasonable mitigations2223### Residual Risk Assessment2425| Residual Risk Level | Action |26|---------------------|--------|27| Low | No prior consultation needed. Processing may proceed. |28| Medium | No prior consultation required, but DPO should document the acceptance rationale. |29| High | Prior consultation recommended. Processing should not proceed without SA review. |30| Very High | Prior consultation mandatory under Art. 36(1). Processing must not proceed. |3132### Practical Examples Triggering Prior Consultation3334- Large-scale biometric identification in publicly accessible areas where encryption with exporter-held key is not feasible35- AI system making automated decisions about access to essential services (credit, insurance, healthcare) where residual discrimination risk cannot be fully eliminated36- Processing of genetic data for a novel purpose where no existing Art. 9(2) exemption clearly applies37- Employee monitoring system where proportionality concerns remain despite all mitigations38- International transfer to a country with Very High government access risk where the processing requires clear-text data access3940## Art. 36(3) Required Documentation4142The controller must provide the supervisory authority with the following information:4344| Document | Content | Art. 36(3) Reference |45|----------|---------|---------------------|46| DPIA report | Complete DPIA per Art. 35(7) including systematic description, necessity/proportionality, risk assessment, and mitigation measures | Art. 36(3)(a) — implicit |47| Controller and processor responsibilities | Clear documentation of which entity is responsible for which processing operations and security measures | Art. 36(3)(a) |48| Measures and safeguards | All technical, organisational, and contractual measures implemented to protect data subjects | Art. 36(3)(b) |49| DPO contact details | Contact details of the Data Protection Officer | Art. 36(3)(c) |50| Additional information requested | Any further information the supervisory authority requests during the consultation | Art. 36(3)(d) |5152### Supplementary Documentation (Best Practice)5354| Document | Purpose |55|----------|---------|56| Executive summary | 1-2 page summary of the processing, identified risks, and reasons for prior consultation |57| Data flow diagram | Visual representation of personal data flows through the processing |58| Risk register | Detailed risk register with inherent and residual risk levels |59| Mitigation measures schedule | Implementation status and timeline for all mitigations |60| DPO advice letter | Written DPO advice per Art. 35(2) and whether it was followed |61| Legitimate interest assessment | If processing relies on Art. 6(1)(f), the documented LIA |62| Art. 35(9) consultation evidence | Documentation of data subject views sought |6364## Consultation Process6566### Step 1: Preparation (Weeks 1-2)67681. DPO confirms that prior consultation is required based on DPIA residual risk assessment.692. Processing owner compiles the Art. 36(3) documentation package.703. DPO reviews the package for completeness and accuracy.714. Legal counsel reviews for legal accuracy and strategic considerations.725. Senior management is briefed on the prior consultation and its implications (processing pause).7374### Step 2: Submission (Week 3)75761. Identify the competent supervisory authority:77 - Lead SA under one-stop-shop mechanism (Art. 56) for cross-border processing78 - Local SA for purely national processing792. Submit the consultation package through the SA's designated channel (online portal, registered mail, or both per SA requirements).803. Confirm receipt and obtain a case reference number.814. Document the submission date — this starts the 8-week clock.8283### Step 3: Supervisory Authority Review Period (Weeks 3-11)8485Art. 36(2) timeline:86- **Standard period**: Up to 8 weeks from receipt of the complete consultation request87- **Extension**: The SA may extend the period by up to 6 weeks for complex cases, with notification to the controller within the first month88- **Total maximum**: 14 weeks (8 + 6)8990During this period:911. The SA may request additional information under Art. 36(3)(d). The 8-week clock pauses until the information is provided.922. The DPO serves as the point of contact for SA communications.933. Processing must not commence during the consultation period.944. The controller should continue implementing mitigation measures in preparation.9596### Step 4: Outcome Management9798| SA Response | Controller Action |99|-------------|------------------|100| **Written advice with no concerns** | Document the SA's response. Proceed with processing. Update DPIA with SA clearance. |101| **Written advice with recommendations** | Implement the SA's recommendations. Update DPIA. Proceed with processing once recommendations are addressed. |102| **Written advice indicating GDPR infringement** | Do not proceed with processing as described. Review processing design to address SA concerns. Consider re-submission after modifications. |103| **No response within the statutory period** | SA silence does not constitute approval. The controller bears responsibility for demonstrating compliance. Proceed with caution, documenting the SA's non-response. |104| **Request for more information** | Provide the requested information promptly. The clock pauses. |105106### Step 5: Post-Consultation1071081. Document the entire consultation process and outcome in the DPIA register.1092. Update the DPIA with any SA recommendations or requirements.1103. If processing proceeds, implement all SA-recommended measures.1114. Schedule an accelerated DPIA review (6 months post-processing commencement).1125. Maintain the consultation documentation for supervisory authority inspection.113114## National Supervisory Authority Consultation Procedures115116| SA | Submission Method | Specific Requirements |117|----|------------------|----------------------|118| ICO (UK) | Online consultation request form | Include DPIA, data flow diagram, DPO contact, description of why risk cannot be mitigated |119| CNIL (France) | Online portal (teleservice.cnil.fr) | DPIA in CNIL format; French language required |120| BfDI (Germany) | Written submission to the competent state or federal DPA | German language; DPIA must reference BDSG provisions |121| Garante (Italy) | PEC (certified email) | Italian language; include DPIA, processor agreements, security measures documentation |122| AEPD (Spain) | Sede Electronica portal | Spanish language; include DPIA and all supporting documentation |123| DPC Ireland | Online submission through DPC website | English language; include DPIA and all Art. 36(3) documentation |124125## Common Prior Consultation Mistakes1261271. **Consulting too early**: Submitting before completing the DPIA and implementing all feasible mitigations. The SA expects to see that all reasonable measures have been taken.1282. **Consulting too late**: Beginning processing before the SA responds. Processing must not start during the consultation period.1293. **Incomplete documentation**: Submitting without all Art. 36(3) required documents, causing delays for information requests.1304. **No DPO involvement**: Submitting without documented DPO advice per Art. 35(2).1315. **Treating SA silence as approval**: SA non-response does not constitute approval or endorsement.1326. **Failing to implement SA recommendations**: Proceeding with processing without addressing SA feedback.133134## Enforcement Context135136- Art. 36(1) non-compliance (failure to consult when required) can result in administrative fines up to EUR 10 million or 2% of annual worldwide turnover under Art. 83(4)(a).137- **Swedish DPA vs Karolinska (2019)**: Fine included failure to conduct DPIA and consequent failure to identify need for prior consultation.138- **Norwegian DPA vs Municipality (2020)**: Enforcement action for proceeding with high-risk processing without prior consultation.