Guides GDPR Art. 36 prior consultation with supervisory authorities after DPIA identifies unmitigable high residual risk. Covers Art. 36(3) documentation, 8-week timelines, and response protocols.
npx claudepluginhub mukul975/privacy-data-protection-skills --plugin privacy-skills-completeThis skill uses the workspace's default tool permissions.
Article 36(1) requires the controller to consult the supervisory authority prior to processing where a DPIA under Art. 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. Prior consultation is the final safety net when a DPIA reveals risks that cannot be adequately mitigated through technical, organisational, or c...
Conducts multi-round deep research on GitHub repos via API and web searches, generating markdown reports with executive summaries, timelines, metrics, and Mermaid diagrams.
Dynamically discovers and combines enabled skills into cohesive, unexpected delightful experiences like interactive HTML or themed artifacts. Activates on 'surprise me', inspiration, or boredom cues.
Generates images from structured JSON prompts via Python script execution. Supports reference images and aspect ratios for characters, scenes, products, visuals.
Article 36(1) requires the controller to consult the supervisory authority prior to processing where a DPIA under Art. 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. Prior consultation is the final safety net when a DPIA reveals risks that cannot be adequately mitigated through technical, organisational, or contractual measures. The supervisory authority has up to 8 weeks (extendable by 6 weeks) to provide written advice. Processing must not commence until the supervisory authority's response is received and addressed.
Prior consultation is mandatory when:
| Residual Risk Level | Action |
|---|---|
| Low | No prior consultation needed. Processing may proceed. |
| Medium | No prior consultation required, but DPO should document the acceptance rationale. |
| High | Prior consultation recommended. Processing should not proceed without SA review. |
| Very High | Prior consultation mandatory under Art. 36(1). Processing must not proceed. |
The controller must provide the supervisory authority with the following information:
| Document | Content | Art. 36(3) Reference |
|---|---|---|
| DPIA report | Complete DPIA per Art. 35(7) including systematic description, necessity/proportionality, risk assessment, and mitigation measures | Art. 36(3)(a) — implicit |
| Controller and processor responsibilities | Clear documentation of which entity is responsible for which processing operations and security measures | Art. 36(3)(a) |
| Measures and safeguards | All technical, organisational, and contractual measures implemented to protect data subjects | Art. 36(3)(b) |
| DPO contact details | Contact details of the Data Protection Officer | Art. 36(3)(c) |
| Additional information requested | Any further information the supervisory authority requests during the consultation | Art. 36(3)(d) |
| Document | Purpose |
|---|---|
| Executive summary | 1-2 page summary of the processing, identified risks, and reasons for prior consultation |
| Data flow diagram | Visual representation of personal data flows through the processing |
| Risk register | Detailed risk register with inherent and residual risk levels |
| Mitigation measures schedule | Implementation status and timeline for all mitigations |
| DPO advice letter | Written DPO advice per Art. 35(2) and whether it was followed |
| Legitimate interest assessment | If processing relies on Art. 6(1)(f), the documented LIA |
| Art. 35(9) consultation evidence | Documentation of data subject views sought |
Art. 36(2) timeline:
During this period:
| SA Response | Controller Action |
|---|---|
| Written advice with no concerns | Document the SA's response. Proceed with processing. Update DPIA with SA clearance. |
| Written advice with recommendations | Implement the SA's recommendations. Update DPIA. Proceed with processing once recommendations are addressed. |
| Written advice indicating GDPR infringement | Do not proceed with processing as described. Review processing design to address SA concerns. Consider re-submission after modifications. |
| No response within the statutory period | SA silence does not constitute approval. The controller bears responsibility for demonstrating compliance. Proceed with caution, documenting the SA's non-response. |
| Request for more information | Provide the requested information promptly. The clock pauses. |
| SA | Submission Method | Specific Requirements |
|---|---|---|
| ICO (UK) | Online consultation request form | Include DPIA, data flow diagram, DPO contact, description of why risk cannot be mitigated |
| CNIL (France) | Online portal (teleservice.cnil.fr) | DPIA in CNIL format; French language required |
| BfDI (Germany) | Written submission to the competent state or federal DPA | German language; DPIA must reference BDSG provisions |
| Garante (Italy) | PEC (certified email) | Italian language; include DPIA, processor agreements, security measures documentation |
| AEPD (Spain) | Sede Electronica portal | Spanish language; include DPIA and all supporting documentation |
| DPC Ireland | Online submission through DPC website | English language; include DPIA and all Art. 36(3) documentation |