DPIA — Data Protection Impact Assessment for AI Systems

Definition

A Data Protection Impact Assessment (DPIA) is a structured process required by GDPR Article 35 for processing activities that are likely to result in a high risk to the rights and freedoms of natural persons. It is a systematic evaluation of the nature, scope, context, and purposes of processing, the risks it creates, and the measures to address those risks — conducted before the processing begins, not retrospectively.

For AI systems, the DPIA obligation is frequently triggered. Systematic and extensive evaluation of personal aspects using automated processing (Article 35(3)(a)) — which includes AI-driven profiling, scoring, and decision-making — requires a DPIA. Large-scale processing of special categories of data such as health data, biometric data, or political opinions requires a DPIA. Processing data about individuals in publicly accessible areas (including AI surveillance applications) requires a DPIA.

A DPIA must include: a description of the processing operations and their purposes; an assessment of the necessity and proportionality of the processing; an assessment of risks to individuals; and measures to address those risks. Where risks cannot be adequately mitigated, the controller must consult with the supervisory authority before proceeding.

Why it matters operationally

The DPIA matters for AI governance because it is the primary mechanism through which data protection obligations connect to AI system design. A well-executed DPIA forces organizations to document what data they are processing, why, what the privacy risks are, and what mitigations they have implemented — creating the documentation foundation for both GDPR compliance and EU AI Act technical file requirements.

Organizations that deploy AI systems processing personal data without conducting required DPIAs face enforcement action from data protection authorities. In several EU jurisdictions, data protection authorities have issued fines specifically for failure to conduct DPIAs before deploying AI-based profiling or scoring systems. The DPIA is not optional documentation — it is a legal prerequisite for certain categories of AI processing.

Regulatory framework

Framework DPIA obligations
GDPR — Art. 35 Required for: (1) systematic and extensive evaluation of individuals using automated processing (includes AI-based profiling and scoring); (2) large-scale processing of special category data; (3) systematic large-scale monitoring of publicly accessible areas.
EU AI Act For high-risk systems processing personal data, the GDPR DPIA and EU AI Act FRIA are complementary assessments that can be integrated into a single process.
ISO/IEC 27701 The ISO 27701 privacy management system includes privacy impact assessment processes as a component of the PIMS.
EDPB Guidelines 4/2019 European data protection authority guidance on what processing requires a DPIA, including specific criteria for AI systems.

How Zertia evaluates it

Zertia addresses DPIA requirements through two services. ISO/IEC 27701 certification includes evaluation of the organization’s privacy impact assessment processes — whether the PIMS includes systematic identification of high-risk processing, triggered DPIA procedures, and documentation of DPIA outcomes and mitigations. The EU AI Act Assessment identifies where AI systems trigger DPIA obligations under GDPR and where the Fundamental Rights Impact Assessment (FRIA) under the EU AI Act creates additional evaluation requirements, supporting integrated compliance planning.

[ISO 27701 Certification] · EU AI Act Assessment

Definitions that hold up under audit.

Does this term apply to your certification project? Let's talk 30 minutes, no commercial pressure.