GDPR Article 35 Compliant DPIA Template
Describe the AI system and its data processing activities
Describe what data is processed, how, and for what purpose
List all types of personal data processed by the AI system
Who are the individuals whose data is being processed?
Assess whether the processing is necessary and proportionate
What specific purposes does the AI system serve?
Why is AI processing necessary to achieve these purposes?
Is the data collected proportionate to the purpose?
How are data subject rights ensured?
Identify risks to data subject rights and freedoms
Assess risks to individuals from the AI system's processing of their personal data.
Risk of discriminatory outcomes based on protected characteristics
Risk of automated decisions affecting individuals without meaningful human oversight
Risk of excessive monitoring or intrusion into private life
Risk of unauthorized access, breach, or data loss
Risk of errors in AI outputs leading to harmful decisions
Risk of opaque decision-making that cannot be explained to data subjects
Define measures to address identified risks
Security, encryption, access controls, anonymization techniques
Policies, training, governance structures
Fairness testing, diverse training data, regular audits
Human-in-the-loop, review processes, escalation procedures
Explainability, notice to data subjects, documentation
What risks remain after mitigation measures are applied?
Determine if prior consultation is required
Complete the risk identification step to see summary.
When will this DPIA be reviewed?