AI, explained

Do we need a DPIA for AI?

If the AI system touches personal data at scale, makes decisions about people, or uses a new technology in a new way, the answer is almost certainly yes.

Do we need a DPIA for AI? Usually yes. Article 35 of the GDPR requires a data protection impact assessment where processing is likely to result in high risk to individuals, and explicitly names new technologies, systematic evaluation of people, and large scale processing. Most AI deployments touching personal data hit at least one trigger.

The triggers that catch AI systems

Article 35(3) mandates a DPIA in three cases, and supervisory authorities have published lists that expand on them. The ones AI projects hit most often are:

Combining data from multiple sources, processing data of vulnerable individuals such as students, patients or employees, and preventing someone from accessing a service are all additional risk indicators. Two indicators together generally means do the assessment.

What it has to contain

A DPIA is not a form to file. Article 35(7) requires four things: a systematic description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to individuals, and the measures you will take to address those risks. For an AI system, the parts people leave out are the ones that matter: which model and which version, where inference runs, whether inputs are retained or used for training, what the system does when it is unsure, and how a person exercises their rights over an output the system produced.

Practical points that come up

Doing it well is useful, not just compliant

The necessity and proportionality section forces a question projects otherwise skip: does this use case need personal data at all, and at this granularity? A surprising number of builds shrink at that point, which reduces both risk and cost. An AI audit covers the same ground from the build side, so the assessment and the architecture agree with each other.

Frequently asked questions

Do we need a DPIA for an AI system?

In most cases yes. Article 35 of the GDPR requires one where processing is likely to result in high risk, naming systematic evaluation of individuals, large scale special category data, and innovative technology. Regulators have consistently treated machine learning deployments as innovative technology, so the trigger is met even without profiling.

What must a DPIA contain?

Article 35(7) requires a systematic description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to individuals, and the mitigating measures. For AI, add the model and version, where inference runs, retention and training rights over inputs, abstention behaviour, and how individuals exercise their rights.

When does a DPIA need to be redone?

When the processing changes materially: a new model version with different behaviour, an additional data source, an extended use case, or a change in who receives the output. Each of those is different processing. A DPIA written once at launch and never revisited stops describing the system it covers.

Related

AI SEO in LisbonAI agency in LisbonBook an AI audit

Ready to put AI to work?

Book a discovery audit and we will map the highest-ROI AI agents and automations for your business.

Book a discovery audit →