Why AI systems almost automatically fall within DPIA scope
Art. 35(1) GDPR requires a data protection impact assessment (DPIA) whenever processing is “likely, taking into account the nature, scope, context and purposes” to result in a high risk to the rights and freedoms of natural persons – with the “use of new technologies” expressly mentioned. AI systems are the textbook case the legislator had in mind back in 2016. In practice, this means: anyone deploying an AI system that is trained on personal data, or that uses such data to prepare decisions, must actively assess the DPIA obligation – not only once a supervisory authority asks.
The three standard cases under Art. 35(3) – and why AI often triggers them
Art. 35(3) GDPR names three scenarios in which a DPIA is required:
- Point (a): a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, used as a basis for decisions producing legal effects or similarly significantly affecting the individual. Scoring models, automated candidate pre-selection, and creditworthiness assessments carried out by a model typically fall under this.
- Point (b): processing on a large scale of special categories of data under Art. 9(1) or of data relating to criminal convictions under Art. 10. Training data for health, HR or fraud models frequently contains such categories, even where this is not the primary purpose of the processing.
- Point (c): systematic monitoring of publicly accessible areas on a large scale. Relevant, for example, for video analytics systems with facial recognition or behavioural analysis in public spaces.
The typical gap: companies check these criteria once, at project launch, but fail to re-check them when a model is later enriched with additional data sources or repurposed for a new use case. This shifts the risk profile without the DPIA being updated accordingly.
What the impact assessment must actually cover
Art. 35(7) GDPR sets out a binding minimum content:
- a systematic description of the envisaged processing operations and purposes, including, where applicable, the legitimate interest pursued (point (a)),
- an assessment of the necessity and proportionality of the processing operations in relation to the purpose (point (b)),
- an assessment of the risks to the rights and freedoms of data subjects (point (c)),
- the measures envisaged to address the risks, including safeguards, security measures and mechanisms to demonstrate compliance with the GDPR (point (d)).
For AI systems, point 2 – the proportionality assessment – is often dealt with too superficially: it is not enough to describe the business benefit; what is required is a reasoned assessment of whether the chosen degree of automation and data processing is genuinely necessary for the purpose. Similarly, point 3 is often reduced to technical risks (data breach, misclassification), while fundamental-rights risks such as discrimination arising from bias in training data are not systematically captured.
Under Art. 35(2) GDPR, the advice of the data protection officer must also be sought, where a DPO has been appointed – this is not a mere formality, but is intended to give the risk assessment a professional grounding before it is finalised. Under Art. 35(9) GDPR, the views of data subjects or their representatives should also be sought where appropriate, without prejudice to the protection of commercial or public interests.
A DPIA is not a one-off document
Art. 35(11) GDPR requires a review of whether processing is still performed in accordance with the impact assessment, at least where the risk represented by the processing operations changes. For AI systems, this is the norm rather than the exception: models are retrained, data sources are swapped out, use cases are expanded. A DPIA written once at go-live and then filed away does not satisfy paragraph 11. Anyone operating AI systems needs a process that automatically maps model changes against the existing risk assessment.
Don’t lose sight of the time pressure from the EU AI Act
The DPIA obligation under Art. 35 GDPR runs in parallel with the requirements of the EU AI Act, whose deadlines have shifted as a result of the “Digital Omnibus on AI”: the high-risk obligations for systems under Annex III now apply only from 2 December 2027, and the transparency obligations under Art. 50 AI Act from 2 August 2026 (with a grace period until 2 December 2026 for systems already on the market). This shift changes nothing about the GDPR obligation: where an AI system processes personal data and the thresholds of Art. 35(3) GDPR are met, the DPIA is already mandatory today, regardless of the AI Act timeline. Anyone using the additional time before the AI Act deadlines take effect would do well to spend it building a robust DPIA process, rather than waiting for later deadlines.
Whether your AI system meets the thresholds of Art. 35(3) GDPR, and how urgent the need for action is, can be assessed in a few minutes using our free risk check at /einstufung.