AI, explained
Do we need a DPIA for AI?
If the AI system touches personal data at scale, makes decisions about people, or uses a new technology in a new way, the answer is almost certainly yes.
The triggers that catch AI systems
Article 35(3) mandates a DPIA in three cases, and supervisory authorities have published lists that expand on them. The ones AI projects hit most often are:
- Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions produce legal or similarly significant effects. Recruitment screening, credit decisioning and fraud scoring land here.
- Large scale processing of special category data, which catches health, biometric and some HR use cases.
- Systematic monitoring of a publicly accessible area.
- Use of innovative technology, which regulators have consistently applied to machine learning deployments even where the other triggers are absent.
Combining data from multiple sources, processing data of vulnerable individuals such as students, patients or employees, and preventing someone from accessing a service are all additional risk indicators. Two indicators together generally means do the assessment.
What it has to contain
A DPIA is not a form to file. Article 35(7) requires four things: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to individuals, and the measures you will take to address those risks. For an AI system, the parts people leave out are the ones that matter: which model and which version, where inference runs, whether inputs are retained or used for training, what the system does when it is unsure, and how a person exercises their rights over an output the system produced.
Practical points that come up
- Do it before deployment. A DPIA written after go-live is remediation, and it reads that way to a regulator.
- Your data protection officer advises, but the controller signs. That is your organisation, not the vendor.
- If residual risk stays high after mitigation, Article 36 requires prior consultation with the supervisory authority.
- Revisit it when the model version changes, when a new data source is added, or when you extend the use case. Those are not the same processing.
- An AI Act conformity assessment for a high risk system does not replace the DPIA. They overlap and both apply.
Doing it well is useful, not just compliant
The necessity and proportionality section forces a question projects otherwise skip: does this use case need personal data at all, and at this granularity? A surprising number of builds shrink at that point, which reduces both risk and cost. An AI audit covers the same ground from the build side, so the assessment and the architecture agree with each other.
Frequently asked questions
Do we need a DPIA for an AI system?
In most cases yes. Article 35 of the GDPR requires one where processing is likely to result in high risk, naming systematic evaluation of individuals, large scale special category data, and innovative technology. Regulators have consistently treated machine learning deployments as innovative technology, so the trigger is met even without profiling.
What must a DPIA contain?
Article 35(7) requires a systematic description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the mitigating measures. For AI, add the model and version, where inference runs, retention and training rights over inputs, abstention behaviour, and how individuals exercise their rights.
When does a DPIA need to be redone?
When the processing changes materially: a new model version with different behaviour, an additional data source, an extended use case, or a change in who receives the output. Each of those is different processing. A DPIA written once at launch and never revisited stops describing the system it covers.
Related
Ready to put AI to work?
Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.
Book a discovery audit →