DPIA for AI Systems — GDPR Article 35 + EU AI Act
When AI systems require a DPIA under GDPR Article 35, how it overlaps with EU AI Act Article 27 FRIA, and how to avoid duplication.
A Data Protection Impact Assessment (DPIA) is required under GDPR Article 35 when an AI system involves systematic large-scale processing of personal data, uses automated profiling with significant effects on individuals, or processes special category data. AI systems can trigger multiple DPIA obligations simultaneously. DPIAs must be completed before processing begins, are reviewed by the Data Protection Officer, and must be updated when the system changes materially. Failure to conduct a required DPIA carries GDPR fines of up to €10 million or 2% of global turnover.
When Does an AI System Require a DPIA?
GDPR Article 35(3) specifies three automatic triggers. Most supervisory authorities have also published lists of processing types that always require a DPIA in their jurisdiction.
Systematic, large-scale profiling or automated decision-making
AI systems that profile individuals at scale or make automated decisions with significant legal or similarly significant effects (Art 35(3)(a)). This includes credit scoring AI, fraud detection, employment screening, and insurance pricing algorithms.
Large-scale processing of special category data
AI systems processing health data, biometric data for unique identification, racial or ethnic origin, political opinions, religious beliefs, genetic data, or trade union membership at scale (Art 35(3)(b) + Art 9).
Systematic monitoring of publicly accessible areas
AI systems that systematically monitor people in public spaces using video, audio, or other surveillance technologies at large scale (Art 35(3)(c)). Includes smart city monitoring, CCTV analytics, and behaviour tracking.
DPIA vs FRIA: Understanding the Overlap
When a high-risk AI system both processes personal data (triggering a DPIA) and is deployed by a public-sector body (triggering a FRIA under Art 27), organisations face two overlapping assessment obligations. The EU AI Act explicitly permits combining or coordinating these assessments to reduce duplication — but they remain legally distinct.
A DPIA focuses narrowly on personal data processing risks. A FRIA covers broader fundamental rights impacts including non-discrimination, dignity, fair trial, and access to services — many of which are not data-protection rights. Combining assessments is permissible but the FRIA elements must be documented separately to satisfy Art 27.
DPIA (GDPR Art 35)
- →Triggered by: personal data processing risk
- →Scope: data protection rights
- →Mandatory DPO consultation
- →May require supervisory authority prior consultation (Art 36)
- →Applies to all organisations (public and private)
FRIA (AI Act Art 27)
- →Triggered by: high-risk AI + public-sector deployment
- →Scope: all EU Charter fundamental rights
- →Workers' representative consultation encouraged
- →Must be registered in EU AI Act database
- →Applies only to public-sector / delegated deployers
6-Step DPIA Process for AI Systems
Describe the Processing and Its Purposes
Document what personal data is processed, how it is collected, the processing purpose and legal basis, data retention periods, and who has access. For AI systems, include model inputs/outputs, training data sources, and inference pipeline data flows.
Assess Necessity and Proportionality
Demonstrate that the personal data processing is necessary and proportionate to the AI system's purpose. Consider data minimisation, purpose limitation, and whether less privacy-invasive alternatives exist.
Identify and Assess Privacy Risks
Enumerate privacy risks: unlawful disclosure, unauthorised access, model inversion attacks, re-identification risk from AI outputs, discriminatory profiling, and function creep. Rate each by likelihood and severity.
Implement Technical and Organisational Measures
Document the measures that mitigate identified risks: encryption, access controls, differential privacy, audit logging, data minimisation in training, model output sanitisation, and breach response procedures.
Consult the DPO and Affected Parties
Article 35(2) requires consulting the DPO where one has been designated. Article 35(9) requires seeking the views of affected data subjects or their representatives where appropriate. Document both consultations.
Document Residual Risks and Obtain Sign-off
Record any residual risks that cannot be fully mitigated and whether they are acceptable to the controller. If residual risks remain high, prior consultation with the supervisory authority (Art 36) may be required before processing begins.
How Scanara Supports DPIA Compliance
DPIA trigger detection
Scanara flags AI system characteristics that trigger DPIA obligations under GDPR Art 35 — biometric processing, profiling at scale, automated decision-making with significant effects.
Data flow documentation
Scan results identify data processing patterns in your AI codebase — model inputs, outputs, training data pipelines — providing the factual foundation for DPIA Step 1.
FRIA/DPIA overlap flag
When both a DPIA and FRIA are triggered, Scanara identifies the overlap and suggests a coordinated assessment plan to satisfy both obligations with minimum duplication.
Frequently Asked Questions
How Scanara Helps
Scanara automates EU AI Act compliance from code to dossier. Connect your GitHub repos and get compliance reports in minutes.