compliance

Data Protection Impact Assessment (DPIA): When AI Products Need One and How to Do It

A structured process required under GDPR for identifying and mitigating privacy risks before launching new processing activities, especially AI systems.

A Data Protection Impact Assessment is not optional for many AI products - GDPR Article 35 mandates one before you begin certain types of processing. The rule of thumb is simple: if your AI system is likely to result in a high risk to the rights and freedoms of individuals, you must complete a DPIA before processing begins, not after launch. The challenge is that AI products are particularly prone to triggering DPIA requirements because they often involve automated decision-making, large-scale processing, systematic profiling, or novel use of data. Understanding when a DPIA is required, what it must cover, and how it intersects with EU AI Act obligations is one of the most important compliance decisions an AI product team makes during scoping. The ICO publishes a mandatory list of processing types that always require a DPIA under UK GDPR, and AI-driven decision-making for employment, credit, or essential services sits squarely on that list. Founders targeting NHS or local authority contracts should expect DPIA completion to be a contractual requirement, not just a regulatory best practice. SpeedMVPs builds DPIA-ready logging, audit trails, and human oversight touchpoints into AI MVPs during the initial two to three week build, which means founders arrive at procurement with the documentation already in place rather than commissioning it as a separate legal project.

When a DPIA Is Mandatory

GDPR Article 35 identifies three categories of processing that always require a DPIA. First, systematic and extensive profiling of individuals based on automated processing where the results produce significant effects, such as decisions about credit, employment, or access to services. Second, large-scale processing of special categories of data (health, biometrics, political opinions, religious beliefs, sexual orientation, and so on). Third, systematic monitoring of publicly accessible areas at large scale. The ICO, as the UK supervisory authority, has published a list of processing types that always require a DPIA under UK GDPR. This list includes processing biometric data to uniquely identify individuals, using AI systems to make or support significant decisions about individuals, profiling individuals at large scale, and processing health data for purposes beyond direct care. For AI products, the practical trigger is almost always automated decision-making or profiling. If your AI product makes or materially influences decisions that affect individuals - approval of applications, scoring of performance, allocation of resources, personalisation at scale - a DPIA is required.

What a DPIA Must Cover

A GDPR-compliant DPIA is not a brief form - it is a substantive analysis structured around six core elements. First, a systematic description of the processing: what data is collected, from whom, how it is processed, who has access, how long it is retained, and what third parties receive it. Second, an assessment of the necessity and proportionality of the processing: is the purpose legitimate, is the processing limited to what is necessary, are data subjects' rights supported? Third, an assessment of the risks to rights and freedoms: what could go wrong, how likely is it, how severe would the impact be on individuals? Fourth, the measures you plan to take to address those risks: technical controls, policy controls, contractual protections. Fifth, consultation with affected stakeholders where appropriate. Sixth, for high-risk processing that cannot be adequately mitigated, prior consultation with the ICO or relevant EU supervisory authority before processing begins. The DPIA must be a living document updated when the processing changes significantly.

DPIA and EU AI Act Alignment

If your AI product falls into a high-risk category under the EU AI Act, the technical documentation required by the Act overlaps significantly with a DPIA. Both require a description of the system's purpose and intended use, an assessment of foreseeable risks, documentation of the data used in training, and an explanation of how human oversight is implemented. Running both processes concurrently rather than sequentially reduces duplication significantly. The EU AI Act also requires a fundamental rights impact assessment for certain high-risk AI systems deployed by public bodies. UK organisations subject to the EU AI Act and UK GDPR should coordinate their DPIA with their EU AI Act conformity assessment, particularly on the shared topics of data quality, bias assessment, and risk documentation. SpeedMVPs builds this documentation coordination into the delivery process for AI products that require it.

Automated Decision-Making Under GDPR Article 22

Article 22 of GDPR creates specific rights for individuals subject to automated decision-making that produces legal or similarly significant effects. If your AI product makes such decisions without human review, individuals have the right to request human intervention, express their point of view, and contest the decision. You must also be able to provide a meaningful explanation of the logic involved. This explainability requirement is one of the most challenging technical requirements for modern deep learning systems. Products using black-box models for significant decisions need either interpretability layers, post-hoc explanation tools such as SHAP or LIME, or a hybrid architecture where AI produces ranked options and a human makes the final decision. Your DPIA should explicitly address how you satisfy Article 22 requirements, either by demonstrating that human oversight is always present, or by documenting how automated decisions are contestable and explainable.

Consulting the ICO: When Prior Consultation Is Required

If you complete a DPIA and conclude that the residual risk remains high after implementing all planned mitigation measures, GDPR Article 36 requires you to consult with the supervisory authority before beginning processing. In the UK, that authority is the ICO. In EU member states, it is the relevant national data protection authority. Prior consultation is not a fast process. The ICO must respond within eight weeks, extendable by a further six weeks for complex cases. This means a DPIA that concludes prior consultation is required could add fourteen weeks to your launch timeline. Building DPIA into your project timeline early, with enough time to complete it and address findings before your target launch, is essential for AI products that involve high-risk processing. The ICO also provides a DPIA consultation service for novel or complex processing scenarios, which can be a useful resource even when prior consultation is not strictly required.

Practical DPIA Process for AI Startups

Here is a practical approach to DPIA that works at startup scale. Start by identifying whether your processing is likely to trigger the requirement using the ICO's high-risk list and the EU AI Act Annex III. If there is genuine doubt, err on the side of completing a DPIA - it is good practice even when not strictly required, and demonstrates accountability to regulators and enterprise customers. Assign ownership of the DPIA to a specific person, typically the CTO or product lead at early stage, or a designated Data Protection Officer if one is appointed. Complete the DPIA before build begins on the specific processing activity, not before the whole product launches. Update the DPIA when you change your data model, add new ML features, change your LLM provider, or significantly expand your user base. Retain completed DPIAs as they form part of your accountability documentation under GDPR Article 5(2) and can be requested by the ICO during an investigation.

Frequently Asked Questions

Does every AI product need a DPIA?+

Not every AI product requires a DPIA, but many do. The trigger is processing that is likely to result in high risk to individuals' rights and freedoms. Any AI product that uses automated decision-making with significant individual effects, processes biometric or health data, profiles users at scale, or uses AI in an employment, credit, or essential services context will almost certainly require a DPIA. General-purpose business productivity tools or AI assistants with no profiling element and no sensitive data are less likely to require one, but a quick screening exercise to confirm is always worthwhile.

What is the difference between a DPIA and an EU AI Act conformity assessment?+

A DPIA is a GDPR instrument focused on privacy risks to individuals from data processing activities. An EU AI Act conformity assessment is a broader evaluation of an AI system's compliance with the Act's requirements, covering not just privacy but also accuracy, robustness, human oversight, and transparency. For high-risk AI systems, both are required. They overlap in areas such as data quality, bias, and risk documentation, so completing them together or in sequence is more efficient than treating them as entirely separate exercises.

Can I do a DPIA myself or do I need a lawyer?+

You can conduct a DPIA internally. The ICO provides a free DPIA template and detailed guidance on completing one. For straightforward processing activities, an internal DPIA completed by a product lead or CTO using the ICO template is usually sufficient. For novel processing, high-risk use cases, or products where GDPR compliance is a commercial prerequisite such as NHS Digital contracts, involving a specialist solicitor or data protection consultant to review the DPIA before you proceed is advisable and a cost-effective use of legal budget.

How long does a DPIA take to complete?+

A straightforward DPIA for a well-defined processing activity with standard risk factors typically takes two to four days of focused work. A complex DPIA for a novel AI system with multiple data sources, third-party processors, and sensitive data categories can take two to four weeks, particularly if it involves stakeholder consultation or if the conclusions require significant design changes to the processing architecture. Build this into your project timeline, especially for products in regulated sectors such as healthtech, fintech, or edtech.

What happens if I launch without completing a required DPIA?+

Launching without a required DPIA is a GDPR breach. The ICO can investigate, issue enforcement notices requiring you to suspend processing, and levy fines of up to GBP 17.5 million or 4% of global annual turnover under UK GDPR. In practice, the ICO's enforcement focus has been on organisations that cause actual harm to data subjects, but the absence of a DPIA is also a discovery that can emerge during a wider investigation triggered by a data breach or a subject access complaint. The reputational and commercial risk of a regulatory investigation generally exceeds the time cost of completing the DPIA.

Building an AI product that needs a GDPR-compliant architecture from the ground up? Get a free consultation at speedmvps.co.uk

Get a Free Quote