Skip to main content

DPIA for AI Systems — GDPR Article 35 + EU AI Act

When AI systems require a DPIA under GDPR Article 35, how it overlaps with EU AI Act Article 27 FRIA, and how to avoid duplication.

A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 when an AI system involves systematic large-scale processing of personal data, uses automated profiling with significant effects on individuals, or processes special category data. AI systems can trigger multiple DPIA obligations simultaneously. DPIAs must be completed before processing begins, are reviewed by the Data Protection Officer, and must be updated when the system changes materially. Failure to conduct a required DPIA carries GDPR fines of up to €10 million or 2% of global turnover.

When Does an AI System Require a DPIA?

GDPR Article 35(3) specifies three automatic triggers. Most supervisory authorities have also published lists of processing types that always require a DPIA in their jurisdiction.

Systematic, large-scale profiling or automated decision-making

AI systems that profile individuals at scale or make automated decisions with significant legal or similarly significant effects (Art 35(3)(a)). This includes credit scoring AI, fraud detection, employment screening, and insurance pricing algorithms.

Credit scoring modelsHR candidate ranking AIInsurance risk AILoan approval automation

Large-scale processing of special category data

AI systems processing health data, biometric data for unique identification, racial or ethnic origin, political opinions, religious beliefs, genetic data, or trade union membership at scale (Art 35(3)(b) + Art 9).

Medical diagnosis AIFacial recognition systemsMental health monitoring AIBiometric authentication

Systematic monitoring of publicly accessible areas

AI systems that systematically monitor people in public spaces using video, audio, or other surveillance technologies at large scale (Art 35(3)(c)). Includes smart city monitoring, CCTV analytics, and behaviour tracking.

Smart city surveillanceRetail footfall analysisBehavioural analyticsPublic CCTV with AI

DPIA vs FRIA: Understanding the Overlap

When a high-risk AI system both processes personal data (triggering a DPIA) and is deployed by a public-sector body (triggering a FRIA under Art 27), organisations face two overlapping assessment obligations. The EU AI Act explicitly permits combining or coordinating these assessments to reduce duplication — but they remain legally distinct.

A DPIA focuses narrowly on personal data processing risks. A FRIA covers broader fundamental rights impacts including non-discrimination, dignity, fair trial, and access to services — many of which are not data-protection rights. Combining assessments is permissible but the FRIA elements must be documented separately to satisfy Art 27.

DPIA (GDPR Art 35)

  • Triggered by: personal data processing risk
  • Scope: data protection rights
  • Mandatory DPO consultation
  • May require supervisory authority prior consultation (Art 36)
  • Applies to all organisations (public and private)

FRIA (AI Act Art 27)

  • Triggered by: high-risk AI + public-sector deployment
  • Scope: all EU Charter fundamental rights
  • Workers' representative consultation encouraged
  • Must be registered in EU AI Act database
  • Applies only to public-sector / delegated deployers

6-Step DPIA Process for AI Systems

1

Describe the Processing and Its Purposes

Document what personal data is processed, how it is collected, the processing purpose and legal basis, data retention periods, and who has access. For AI systems, include model inputs/outputs, training data sources, and inference pipeline data flows.

2

Assess Necessity and Proportionality

Demonstrate that the personal data processing is necessary and proportionate to the AI system's purpose. Consider data minimisation, purpose limitation, and whether less privacy-invasive alternatives exist.

3

Identify and Assess Privacy Risks

Enumerate privacy risks: unlawful disclosure, unauthorised access, model inversion attacks, re-identification risk from AI outputs, discriminatory profiling, and function creep. Rate each by likelihood and severity.

4

Implement Technical and Organisational Measures

Document the measures that mitigate identified risks: encryption, access controls, differential privacy, audit logging, data minimisation in training, model output sanitisation, and breach response procedures.

5

Consult the DPO and Affected Parties

Article 35(2) requires consulting the DPO where one has been designated. Article 35(9) requires seeking the views of affected data subjects or their representatives where appropriate. Document both consultations.

6

Document Residual Risks and Obtain Sign-off

Record any residual risks that cannot be fully mitigated and whether they are acceptable to the controller. If residual risks remain high, prior consultation with the supervisory authority (Art 36) may be required before processing begins.

How Scanara Supports DPIA Compliance

DPIA trigger detection

Scanara flags AI system characteristics that trigger DPIA obligations under GDPR Art 35 — biometric processing, profiling at scale, automated decision-making with significant effects.

Data flow documentation

Scan results identify data processing patterns in your AI codebase — model inputs, outputs, training data pipelines — providing the factual foundation for DPIA Step 1.

FRIA/DPIA overlap flag

When both a DPIA and FRIA are triggered, Scanara identifies the overlap and suggests a coordinated assessment plan to satisfy both obligations with minimum duplication.

See DPIA automation in Scanara →

Frequently Asked Questions


How Scanara Helps

Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.