In brief
- The DPIA question arises only where personal data is processed, but should then be asked early.
- New technology alone does not automatically trigger a DPIA, although it may increase risk.
- A DPIA describes the processing, risks, safeguards and remaining risk.
- If high residual risk remains despite the planned safeguards, an FDPIC opinion must be obtained before processing, subject to the statutory exception for qualifying private-sector data protection advisers.
Begin with a short screening
A documented screening first establishes whether personal data is processed and whether a potentially high risk is apparent. The answer should not depend solely on the product name or the label AI.
| Decision step | Question | If no | If yes |
|---|---|---|---|
| 1. Personal data | Does the planned processing use information relating to identified or identifiable people? | No DPIA under the FADP for this processing; still assess security, confidentiality and other obligations. | Document the people, data categories, sources and recipients and continue screening. |
| 2. Potentially high risk | Could nature, scope, circumstances, purpose or new technology create a high risk to personality or fundamental rights? | Record the reasoning and ordinary safeguards; define triggers for reassessment. | Carry out a DPIA before deployment. |
| 3. Safeguards | After technical, organisational and contractual measures, has the risk been reduced below a high residual level? | Use the applicable FDPIC consultation route before processing, subject to the statutory private-adviser exception. | Document approval, conditions, evidence and monitoring. |
| 4. Material change | Have purpose, data, people, model, provider or automated effects changed? | Keep the planned review date and operating evidence current. | Repeat screening and update the DPIA where the risk picture may have changed. |
The law names two important high-risk examples
Article 22 FADP requires an overall assessment of nature, scope, circumstances and purpose, particularly where new technologies are used. It also names two situations in which a high risk may arise. They are not an exhaustive checklist: other combinations of reach, sensitivity and possible consequences can also require a DPIA.
- Large-scale processing of sensitive personal data
- Examples can include an AI system analysing extensive health data, biometric identifiers or other sensitive data across many people. A single sensitive field does not decide the issue alone; scale, purpose, access and possible consequences matter together.
- Systematic, large-scale surveillance of public areas
- Examples can include persistent AI-supported camera analysis of a large publicly accessible area or systematic tracking of people there. A limited sensor at one controlled entrance is not automatically equivalent; the actual extent and intervention are decisive.
Two narrow statutory cases can replace a separate DPIA
Article 22 paragraph 5 FADP allows a private controller to refrain from preparing a separate DPIA only in two defined situations: where it uses a system, product or service certified under Article 13 FADP, or where it follows a qualifying code of conduct. The relied-on certification or code must actually cover the planned processing and its relevant risks.
- A qualifying code of conduct must be based on a current DPIA, define protective measures and have been submitted to the FDPIC.
- A certification must be a recognised data-protection certification under Article 13 FADP and cover the relevant system, product or service.
- A generic ISO certificate, security audit or provider assurance does not by itself meet this statutory exception.
- Document the scope, conditions and version relied on and repeat the screening when the processing or evidence changes.
What the DPIA should contain
A DPIA is not a generic description of the provider. It represents the planned processing and risks to people in the organisation’s own context.
- Step 1
Describe the processing
Set out purpose, data, sources, recipients, systems, regions, retention and roles.
- Step 2
Assess necessity
Explain why the processing is suitable and proportionate to the purpose.
- Step 3
Analyse risks
Assess possible impacts on personality and fundamental rights and their likelihood.
- Step 4
Define measures
Map technical, organisational and contractual safeguards to the risks.
- Step 5
Decide on residual risk
Document remaining risk, approval and any required consultation.
Assess AI-specific risks explicitly
Generic privacy checklists may miss typical AI concerns. Depending on the use, data provenance, error rates, bias, explainability, human review and model change need to be considered.
- Unauthorised or unexpected use of inputs and outputs
- Misclassification, discriminatory effects or systematic disadvantage
- A hard-to-understand decision or no effective route to human review
- Disclosure through prompts, logs, RAG sources or tool calls
- Quality shifts after changes to models, prompts or data
High residual risk triggers a decision before use
If the DPIA shows that the planned processing still poses a high risk to personality or fundamental rights despite the safeguards envisaged, the controller must obtain an opinion from the FDPIC before processing. This is not an optional escalation based on project preference.
A private controller may refrain from consulting the FDPIC if it has consulted a data protection adviser who meets the statutory requirements. The assessment, advice and resulting decision should be preserved; merely naming an internal contact is not enough to rely on the exception.
- Record which risks remain after which safeguards.
- Do not put the planned processing into operation while a required prior opinion is outstanding.
- Document whether the FDPIC route or the qualifying private-adviser exception applies.
- Track conditions, additional measures and the final release decision.
Use the DPIA as a project and change artefact
An early DPIA can improve architecture and process rather than become a final approval hurdle. Material changes to purpose, data, people, features or providers require reassessment.
- Record assumptions, data flow and safeguards before a pilot.
- Use real tests to demonstrate whether measures work.
- Include the business function and relevant control functions in the assessment.
- Set change triggers and the next review date.
Example: AI-assisted ranking of job applications
A company wants to rank applications by fit. Screening identifies personal data, effects on employment opportunities and possible bias. The DPIA describes sources and criteria, tests errors across relevant groups, limits the system to recommendations, requires human review and creates a route for questions. The residual risk and legal assessment determine whether and how the system is used.
What to remember
Run a short DPIA screening as soon as an AI initiative touches personal data. If a potentially high risk is apparent, the impact assessment belongs in solution design, not at the end of procurement.
Sources and further reading
These primary sources provide further detail on definitions, technical foundations or responsible use.
Content reviewed
Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.