AI Data Protection Impact Assessment

GDPR Article 35 Compliant DPIA Template

1
Processing Description
2
Necessity & Proportionality
3
Risk Identification
4
Risk Mitigation
5
Consultation
📋

Processing Description

Describe the AI system and its data processing activities

Describe what data is processed, how, and for what purpose

List all types of personal data processed by the AI system

Who are the individuals whose data is being processed?

⚖️

Necessity & Proportionality

Assess whether the processing is necessary and proportionate

What specific purposes does the AI system serve?

Why is AI processing necessary to achieve these purposes?

Is the data collected proportionate to the purpose?

Purpose Limitation
Data is collected for specified, explicit, and legitimate purposes
Data Minimization
Only data necessary for the purpose is collected
Accuracy
Measures are in place to ensure data accuracy and updates
Storage Limitation
Data retention periods are defined and enforced

How are data subject rights ensured?

⚠️

Risk Identification

Identify risks to data subject rights and freedoms

Assess risks to individuals from the AI system's processing of their personal data.

Discrimination or Bias

Risk of discriminatory outcomes based on protected characteristics

Loss of Autonomy

Risk of automated decisions affecting individuals without meaningful human oversight

Privacy & Surveillance

Risk of excessive monitoring or intrusion into private life

Data Security

Risk of unauthorized access, breach, or data loss

Inaccurate Decisions

Risk of errors in AI outputs leading to harmful decisions

Lack of Transparency

Risk of opaque decision-making that cannot be explained to data subjects

🛡️

Risk Mitigation Measures

Define measures to address identified risks

Security, encryption, access controls, anonymization techniques

Policies, training, governance structures

Fairness testing, diverse training data, regular audits

Human-in-the-loop, review processes, escalation procedures

Explainability, notice to data subjects, documentation

What risks remain after mitigation measures are applied?

👥

Supervisory Authority Consultation

Determine if prior consultation is required

Risk Assessment Summary

Complete the risk identification step to see summary.

High Risk Processing
The processing is likely to result in high risk to rights and freedoms
Large Scale Processing
Processing involves large volumes of data or many data subjects
Special Category Data
Processing involves sensitive personal data (health, biometric, racial, etc.)
Automated Decision-Making
Decisions with legal or significant effects are made without human intervention
Systematic Monitoring
The AI system involves systematic monitoring of individuals

When will this DPIA be reviewed?