What is a DPIA, and why does the AI Act make it more urgent?

The Data Protection Impact Assessment (DPIA) is the analysis GDPR Article 35 requires before starting a processing operation that's likely to result in a high risk to people's rights. It isn't a form you fill in and file away — it's the document data protection authorities ask to see first when investigating a high-risk processing operation, and its absence has been cited as an aggravating factor in multiple enforcement decisions.

Spain's AEPD has been explicit that AI systems capable of acting autonomously — agents that make decisions or take actions without human intervention at every step — disrupt the usual data flows and make the impact assessment even more necessary before deployment, not less.

When is it mandatory?

The general rule under Article 35.1 is "likely high risk" — deliberately broad wording. But Article 35.3 sets three cases where a DPIA is always mandatory, with no case-by-case judgment call needed:

  • Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, that leads to decisions producing legal effects or similarly significantly affecting the person.
  • Large-scale processing of special categories of data (health, ethnicity, biometrics, etc.) or data on criminal convictions and offences.
  • Systematic monitoring of a publicly accessible area on a large scale — think video surveillance with behavioral analytics, not just cameras recording footage.

Beyond these three cases from the Regulation itself, data protection authorities publish their own lists of processing types that require a DPIA (Art. 35.4), and lists of exempt ones (Art. 35.5) — worth checking both before assuming a given processing operation does or doesn't need one.

The direct bridge to the AI Act

Here's the connection most companies miss: if an AI system processes personal data — and the vast majority of Annex III high-risk systems do, since we're talking about HR, credit scoring, education, or biometrics — its high-risk classification under the AI Act is almost always, in practice, a sign that one of the GDPR Article 35 triggers is also met. Treating the AI Act and GDPR as two separate exercises duplicates work that, framed correctly, is essentially the same analysis documented twice.

What a DPIA must include (Art. 35.7)

ElementWhat it answers
Systematic descriptionWhat's being processed, for what purposes, and on what legal basis.
Necessity and proportionalityIs this processing necessary for the stated purpose, or is there a less invasive way?
Risk assessmentWhat specific risks exist for the rights and freedoms of the people affected.
Mitigation measuresWhat's being done to bring those risks down to an acceptable level.

When prior consultation with the regulator is required (Art. 36)

If, after applying the planned mitigation measures, the DPIA itself concludes that the residual risk remains high, GDPR Article 36 requires prior consultation with the supervisory authority before starting the processing. This isn't the usual path — it's the exception for when an honest assessment concludes the risk can't be brought down enough on your own. Skipping this consultation when it applies is, on its own, an additional compliance failure beyond the underlying processing itself.

DPIA Template The bridge between the AI Act and GDPR in a single document: screening, risk matrix, mitigation measures and sign-off. €9.99.
View product →

The case that explains it better than any regulation

In 2021, Spain's AEPD fined supermarket chain Mercadona €2.52 million over a facial recognition system deployed in stores without a solid prior impact assessment. The case sums up the real risk well: it isn't necessarily that the technology itself was unlawful — it's that it went live without first documenting why it was necessary, what risks it carried, and how those risks would be mitigated. That's exactly what a DPIA requires you to answer before you start, not after something goes wrong.