GDPR Article 35(1) requires a data protection impact assessment before processing likely to result in a high risk, and Article 35(4) requires supervisory authorities to publish lists of operations that need one.

Checked 2026-10-01

Vendor
not restricted
Product
not restricted
Subsystem
dpia
Deployment
multi-tenant, on-premises
Region
eu-eea
Release range
current as of 2026-10-01
Checked
2026-10-01

Sources

Cite this note

APA

WarmTransfer. (2026, October 1). GDPR for contact centers and call recording: source note gdpr-contact-center-dpia-high-risk. WarmTransfer. https://warmtransfer.net/knowledge/claims/gdpr-contact-center-dpia-high-risk

BibTeX

@misc{warmtransfer-claim-gdpr-contact-center-dpia-high-risk,
  title  = {GDPR for contact centers and call recording: source note gdpr-contact-center-dpia-high-risk},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/gdpr-contact-center-dpia-high-risk},
  note   = {Source note gdpr-contact-center-dpia-high-risk, checked 2026-10-01}
}

Read in context