Back to Publications
Regulatory Brief · GDPR

GDPR Article 35 DPIA for AI Systems: Step-by-Step Guide for DPOs

23 May 2026By NexCyber Editorial GDPR

The integration of Artificial Intelligence (AI) systems into business processes that involve personal data processing necessitates a careful examination of compliance obligations under the General Data Protection Regulation (GDPR). Specifically, Article 35 of the GDPR mandates a Data Protection Impact Assessment (DPIA) in certain circumstances. This guide provides a comprehensive overview for Data Protection Officers (DPOs) on when a DPIA is required for AI systems, how to structure it, and the

The integration of Artificial Intelligence (AI) systems into business processes that involve personal data processing necessitates a careful examination of compliance obligations under the General Data Protection Regulation (GDPR). Specifically, Article 35 of the GDPR mandates a Data Protection Impact Assessment (DPIA) in certain circumstances. This guide provides a comprehensive overview for Data Protection Officers (DPOs) on when a DPIA is required for AI systems, how to structure it, and the interplay with the EU AI Act.

When Does an AI System Trigger a DPIA?

Understanding GDPR Article 35

Under GDPR Article 35, a DPIA is required when data processing is "likely to result in a high risk to the rights and freedoms of natural persons." This is particularly relevant for AI systems that process personal data, as they often involve complex data processing operations that can significantly impact individuals' privacy.

EDPB Guidelines and High-Risk Criteria

The European Data Protection Board (EDPB) has outlined criteria that indicate when a DPIA is necessary. For AI systems, the following scenarios are particularly pertinent:

  • Systematic and extensive evaluation of personal aspects based on automated processing, including profiling.
  • Processing on a large scale of special categories of data, such as health or biometric data.
  • Use of new technologies that may impact privacy.

DPOs should assess their AI systems against these criteria to determine the necessity of a DPIA.

DPIA Structure for AI: Necessity, Proportionality, Risks

Establishing Necessity and Proportionality

A DPIA should begin with a clear articulation of why the AI system is necessary and how it aligns with the organization's objectives. The assessment should demonstrate that the processing is proportionate to the aims pursued, ensuring that data minimization principles are adhered to.

Identifying and Mitigating Risks

The core of the DPIA involves identifying potential risks to data subjects' rights and freedoms. For AI systems, this includes assessing risks related to algorithmic bias, data security, and the potential for unintended consequences. The DPIA should outline measures to mitigate these risks, such as implementing robust security protocols and regular auditing of AI outputs.

Automated Decision-Making (Art.22) — Special DPIA Requirements

Understanding Article 22 Implications

GDPR Article 22 provides specific conditions around automated decision-making, including profiling, that significantly affects individuals. When an AI system engages in such processing, the DPIA must address these unique concerns.

Ensuring Transparency and Fairness

The DPIA should ensure that individuals are informed about the automated decision-making process and its potential impacts. It should also evaluate whether the AI system provides mechanisms for individuals to contest decisions and seek human intervention, thereby ensuring compliance with Article 22.

AI Act + GDPR Dual Assessment — Avoiding Duplication

Harmonizing Compliance Efforts

The upcoming EU AI Act introduces additional compliance requirements for AI systems, particularly those classified as high-risk. DPOs must ensure that their DPIA processes align with the AI Act's conformity assessment requirements to avoid duplication of efforts.

Coordinating Assessments

To streamline compliance, organizations should integrate AI Act assessments with GDPR DPIAs. This involves mapping AI Act requirements, such as risk management and transparency obligations, onto the DPIA framework. By doing so, DPOs can create a unified assessment process that satisfies both regulatory regimes.

DPIA Template Sections for AI Deployments

Key Components of a DPIA

A well-structured DPIA for AI systems should include the following sections:

  • Description of Processing Activities: Detailed overview of the AI system's data processing operations.
  • Assessment of Necessity and Proportionality: Justification of the processing activities in relation to the organization's objectives.
  • Risk Assessment: Identification and evaluation of potential risks to data subjects.
  • Mitigation Measures: Strategies to address identified risks, including technical and organizational safeguards.
  • Consultation Process: Documentation of consultations with stakeholders and, if applicable, the supervisory authority.

Customizing for AI

Given the unique challenges posed by AI systems, DPOs should tailor these sections to address specific AI-related risks, such as algorithmic transparency and data quality.

DPO Sign-Off and Prior Consultation with Supervisory Authority

Role of the DPO

The DPO plays a crucial role in the DPIA process, ensuring that it is conducted thoroughly and that all regulatory requirements are met. The DPO must review and sign off on the DPIA, confirming that the assessment adequately addresses all potential risks.

Engaging with Supervisory Authorities

In cases where the DPIA indicates a high risk that cannot be mitigated, the organization must consult with the relevant supervisory authority before proceeding with the processing. This prior consultation process is crucial for obtaining guidance and ensuring compliance.

Next Step with NexCyber

For organizations deploying AI systems, conducting a comprehensive DPIA is not just a regulatory obligation but a critical step in safeguarding data subjects' rights. NexCyber offers a streamlined platform to assist DPOs in conducting DPIAs that align with both GDPR and the upcoming AI Act requirements. Explore our tools and resources to ensure your AI deployments are compliant and secure. Visit [NexCyber's DPIA assessment tool](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=gdpr-article-35-dpia-ai-systems-guide) to get started.