A Data Protection Impact Assessment is not required simply because a project uses AI, but AI can introduce characteristics that make a DPIA necessary or sensible — particularly where personal data is used in new, extensive or higher-risk ways.
Start with the processing, not the label
Describe what personal data is used, whose data it is, the purpose, data sources, recipients, retention and the effect on individuals.
Look for higher-risk characteristics
- Systematic or significant evaluation of people
- Use of sensitive or special-category information
- Large-scale monitoring or profiling
- New combinations of datasets
- Automated decisions with meaningful effects
- Processing involving vulnerable people or significant power imbalance
Map the AI data flow
Understand what reaches the model or provider, what is logged, what is retained, whether information is reused and which sub-processors are involved.
Document mitigations
Data minimisation, access controls, human review, transparency, retention limits, supplier terms and testing should be linked to the specific risks identified.
A practical next step
Complete the assessment early enough to change the design. A DPIA completed after deployment has much less value.