Skip to main content
Category: Breach and Risk Assessment

Prior Consultation

Simply put

Prior consultation is a step in which an organization contacts its data protection regulator before starting a data processing activity that could pose a high risk to people, to get the regulator's input before proceeding. It generally arises when the organization's own risk assessment cannot bring that risk down to an acceptable level. The evidence provided does not describe the specific mechanics, triggers, or timelines of this obligation, so those details are out of scope here.

Formal definition

Prior consultation generally refers to a process in which a controller engages the competent supervisory authority in advance of processing, typically where a data protection impact assessment indicates that the processing would result in a high residual risk in the absence of mitigating measures. It reflects a broader legal pattern, noted in the evidence, of inserting an external assessment into a decision-maker's process before action is taken in order to identify and reduce potential harms. The evidence packet does not supply authoritative detail on the precise statutory basis, procedural steps, response periods, or the division of obligations between controller and authority; those elements are jurisdiction- and instrument-specific and are not established by the sources provided. Treatment of any equivalent mechanism differs across regimes and should not be assumed to be uniform.

Why it matters

Prior consultation matters because it operates as a checkpoint for processing activities that carry a high risk to individuals, engaging an external authority before an organization commits to a course of action that could cause harm. As the evidence notes, this reflects a broader legal pattern of inserting an assessment of external costs into a decision-maker's process, so that potential harms can be identified and reduced before action is taken rather than remediated afterward. For controllers, this means that certain high-risk processing decisions are not left solely to internal judgment.

The mechanism is generally significant where an organization's own risk assessment cannot bring residual risk down to an acceptable level. In that situation, engaging the regulator in advance shifts part of the review outside the organization, which can surface concerns the controller may not have weighed adequately on its own. This is consistent with the general framing of consultation as seeking expert advice and stakeholder input to inform decisions and improve outcomes.

It is important to be clear about the limits of what can be said here. The evidence provided does not establish the specific statutory basis, triggers, procedural steps, response periods, or the precise division of obligations between a controller and an authority. Those details are jurisdiction- and instrument-specific and should not be assumed to be uniform across regimes. Organizations should confirm the applicable requirements for their own jurisdiction rather than treating prior consultation as a single, universal process.

Who it's relevant to

Data Protection Officers and Privacy Leads
Those advising on high-risk processing need to recognize when an internal risk assessment fails to reduce residual risk to an acceptable level, since that is generally the point at which engaging the regulator may become relevant. The specific triggers and timelines applicable to their jurisdiction are out of scope here and should be confirmed against the governing instrument.
Data Controllers
As the party that determines the purposes and means of processing, a controller generally bears the accountability for deciding whether a processing activity requires engaging the supervisory authority in advance. This entry does not establish how obligations divide between controller and authority in any specific regime; that allocation is instrument-specific.
Compliance and Legal Teams
Teams responsible for demonstrating accountability should treat prior consultation as one external checkpoint within a broader risk-management process, and should document the basis for any decision to consult or not to consult. Note that accountability generally requires demonstrable evidence rather than stated intent, and the procedural detail must be sourced from the applicable law.

Inside Prior Consultation

Trigger Condition
Prior consultation is generally required under the EU GDPR when a data protection impact assessment indicates that processing would result in a high residual risk to the rights and freedoms of individuals in the absence of measures taken by the controller to mitigate that risk. It is not triggered by every processing activity, nor by every DPIA.
Supervisory Authority Engagement
The process involves the controller consulting the competent supervisory authority before the processing begins, so that the authority can review the intended processing and the associated risk assessment.
Controller Obligation
The obligation to initiate prior consultation typically rests with the data controller, who determines the purposes and means of processing. A processor acting on the controller's behalf does not generally carry this obligation, though it may support the controller with relevant information.
Supporting Documentation
Prior consultation generally requires the controller to provide the supervisory authority with information about the intended processing, including the DPIA and details of the risk mitigation measures considered, so the authority can assess the residual risk.
Authority Response
Where the supervisory authority is of the view that the intended processing would infringe applicable requirements, it may provide written advice to the controller and may exercise its powers accordingly. The specifics of timelines and powers depend on the applicable regime and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about Prior Consultation.

Is prior consultation required every time a data protection impact assessment (DPIA) is carried out?
No. A DPIA and prior consultation are distinct steps. Prior consultation with the supervisory authority is generally triggered only where a DPIA indicates that the processing would result in a high residual risk in the absence of measures taken by the controller to mitigate that risk. In most cases, a completed DPIA that identifies and adequately mitigates the risks does not require consultation. Treating consultation as an automatic follow-on to every DPIA overstates the obligation. This entry does not cover the specific criteria each supervisory authority applies when deciding whether to engage, which can vary in practice.
Does obtaining a supervisory authority's response through prior consultation guarantee that the processing is compliant?
No. Prior consultation is a procedural safeguard, not a compliance guarantee. The controller generally remains accountable for the lawfulness of the processing and for demonstrating that safeguard, and the authority's engagement does not transfer that accountability or serve as blanket approval. A response should be understood as advice or the exercise of the authority's powers in relation to the specific proposal presented, not as certification of ongoing compliance. This entry does not address enforcement outcomes or penalties.
Who is responsible for initiating prior consultation, the controller or the processor?
The obligation to consult generally rests with the controller, as the party that determines the purposes and means of processing and that carries out the DPIA. A processor may need to provide supporting information and assistance under its arrangement with the controller, but the decision to consult and the accountability for it typically remain with the controller. This entry does not cover the contractual detail governing processor assistance.
What information should generally be prepared before approaching the supervisory authority?
In most cases the controller should have the completed DPIA available, along with a description of the processing, the purposes, the roles of any controllers, joint controllers, and processors, the measures and safeguards intended to protect data subjects, and an articulation of the residual high risk that prompted consultation. Having demonstrable documentation aligns with the accountability principle, which requires evidence rather than stated intent. The exact submission requirements and formats are set by each supervisory authority and are out of scope here.
How should the timing of prior consultation fit into a project timeline?
Prior consultation is intended to occur before the high-risk processing begins, so it should be planned as a step that can precede go-live rather than one addressed retrospectively. Because the authority may take time to respond and may request further information, teams generally build in scheduling contingency. This entry does not state any specific statutory response period, as those can vary by regime and authority.
How does prior consultation relate to broader governance and record-keeping practices?
Prior consultation is primarily a data protection compliance step, but it intersects with governance in that the underlying DPIA, the correspondence with the authority, and the resulting decisions should be retained as demonstrable evidence within the organization's accountability documentation. This is distinct from, though it may draw on, governance artefacts such as data catalogs, lineage records, and records of processing activities; a records of processing obligation is not the same as running a data inventory tool. This entry does not cover retention periods for such records or security controls applied to them.

Common misconceptions

Every data protection impact assessment must be followed by prior consultation with the supervisory authority.
Prior consultation is generally only required where a DPIA indicates a high residual risk that the controller has not been able to mitigate through appropriate measures. Many DPIAs conclude that risks are adequately reduced, in which case consultation is not typically required.
Prior consultation is a general approval or certification that guarantees the processing is compliant.
Consulting the supervisory authority does not, on its own, guarantee compliance. The controller remains accountable for the lawfulness of the processing, and the authority's advice does not transfer that accountability. Compliance depends on context, jurisdiction, and implementation.
Prior consultation is a universal requirement that applies identically across privacy regimes.
The prior consultation mechanism described here is framed by the EU GDPR. Other frameworks, such as the UK GDPR, the CCPA and CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework, do not necessarily impose an equivalent obligation, and treatment differs across jurisdictions.

Best practices

Complete and document a data protection impact assessment first, and use its residual risk conclusion to determine whether prior consultation is genuinely required rather than treating consultation as automatic.
Confirm which party is the data controller for the processing, since the obligation to consult generally rests with the controller, and clarify any supporting role expected of processors in providing information.
Prepare a complete consultation package for the supervisory authority, including the DPIA and a clear account of the risk mitigation measures considered and why residual risk remains high.
Retain demonstrable evidence of the assessment, the decision on whether to consult, and any authority correspondence, since accountability requires evidence rather than stated intent.
Do not begin the high-risk processing until the consultation process is appropriately concluded in line with the applicable regime, and track any written advice received from the authority.
Verify the specific requirements, timelines, and authority powers under the applicable jurisdiction, as this entry does not cover cross-border transfer mechanics, retention rules, or enforcement penalties.