Search

What are you looking for?

Search our services, use cases and practical insights.

Enter at least 2 characters

Popular starting points

Data & governance

When does an AI project need a data protection impact assessment?

Not every AI project requires a formal data protection impact assessment. When planned personal-data processing may create a high risk, however, the question must be assessed systematically before deployment.

The short answer

Under Swiss data protection law, a DPIA is required where planned processing of personal data is likely to result in a high risk to the personality or fundamental rights of data subjects, subject to the narrow statutory exceptions available to private controllers. The nature, scope, circumstances, purpose and technology of the specific processing determine the assessment.

In brief

  • The DPIA question arises only where personal data is processed, but should then be asked early.
  • New technology alone does not automatically trigger a DPIA, although it may increase risk.
  • A DPIA describes the processing, risks, safeguards and remaining risk.
  • If high residual risk remains despite the planned safeguards, an FDPIC opinion must be obtained before processing, subject to the statutory exception for qualifying private-sector data protection advisers.

Begin with a short screening

A documented screening first establishes whether personal data is processed and whether a potentially high risk is apparent. The answer should not depend solely on the product name or the label AI.

Begin with a short screening
Decision stepQuestionIf noIf yes
1. Personal dataDoes the planned processing use information relating to identified or identifiable people?No DPIA under the FADP for this processing; still assess security, confidentiality and other obligations.Document the people, data categories, sources and recipients and continue screening.
2. Potentially high riskCould nature, scope, circumstances, purpose or new technology create a high risk to personality or fundamental rights?Record the reasoning and ordinary safeguards; define triggers for reassessment.Carry out a DPIA before deployment.
3. SafeguardsAfter technical, organisational and contractual measures, has the risk been reduced below a high residual level?Use the applicable FDPIC consultation route before processing, subject to the statutory private-adviser exception.Document approval, conditions, evidence and monitoring.
4. Material changeHave purpose, data, people, model, provider or automated effects changed?Keep the planned review date and operating evidence current.Repeat screening and update the DPIA where the risk picture may have changed.

The law names two important high-risk examples

Article 22 FADP requires an overall assessment of nature, scope, circumstances and purpose, particularly where new technologies are used. It also names two situations in which a high risk may arise. They are not an exhaustive checklist: other combinations of reach, sensitivity and possible consequences can also require a DPIA.

Large-scale processing of sensitive personal data
Examples can include an AI system analysing extensive health data, biometric identifiers or other sensitive data across many people. A single sensitive field does not decide the issue alone; scale, purpose, access and possible consequences matter together.
Systematic, large-scale surveillance of public areas
Examples can include persistent AI-supported camera analysis of a large publicly accessible area or systematic tracking of people there. A limited sensor at one controlled entrance is not automatically equivalent; the actual extent and intervention are decisive.

Two narrow statutory cases can replace a separate DPIA

Article 22 paragraph 5 FADP allows a private controller to refrain from preparing a separate DPIA only in two defined situations: where it uses a system, product or service certified under Article 13 FADP, or where it follows a qualifying code of conduct. The relied-on certification or code must actually cover the planned processing and its relevant risks.

  • A qualifying code of conduct must be based on a current DPIA, define protective measures and have been submitted to the FDPIC.
  • A certification must be a recognised data-protection certification under Article 13 FADP and cover the relevant system, product or service.
  • A generic ISO certificate, security audit or provider assurance does not by itself meet this statutory exception.
  • Document the scope, conditions and version relied on and repeat the screening when the processing or evidence changes.

What the DPIA should contain

A DPIA is not a generic description of the provider. It represents the planned processing and risks to people in the organisation’s own context.

  1. Step 1

    Describe the processing

    Set out purpose, data, sources, recipients, systems, regions, retention and roles.

  2. Step 2

    Assess necessity

    Explain why the processing is suitable and proportionate to the purpose.

  3. Step 3

    Analyse risks

    Assess possible impacts on personality and fundamental rights and their likelihood.

  4. Step 4

    Define measures

    Map technical, organisational and contractual safeguards to the risks.

  5. Step 5

    Decide on residual risk

    Document remaining risk, approval and any required consultation.

Assess AI-specific risks explicitly

Generic privacy checklists may miss typical AI concerns. Depending on the use, data provenance, error rates, bias, explainability, human review and model change need to be considered.

  • Unauthorised or unexpected use of inputs and outputs
  • Misclassification, discriminatory effects or systematic disadvantage
  • A hard-to-understand decision or no effective route to human review
  • Disclosure through prompts, logs, RAG sources or tool calls
  • Quality shifts after changes to models, prompts or data

High residual risk triggers a decision before use

If the DPIA shows that the planned processing still poses a high risk to personality or fundamental rights despite the safeguards envisaged, the controller must obtain an opinion from the FDPIC before processing. This is not an optional escalation based on project preference.

A private controller may refrain from consulting the FDPIC if it has consulted a data protection adviser who meets the statutory requirements. The assessment, advice and resulting decision should be preserved; merely naming an internal contact is not enough to rely on the exception.

  • Record which risks remain after which safeguards.
  • Do not put the planned processing into operation while a required prior opinion is outstanding.
  • Document whether the FDPIC route or the qualifying private-adviser exception applies.
  • Track conditions, additional measures and the final release decision.

Use the DPIA as a project and change artefact

An early DPIA can improve architecture and process rather than become a final approval hurdle. Material changes to purpose, data, people, features or providers require reassessment.

  • Record assumptions, data flow and safeguards before a pilot.
  • Use real tests to demonstrate whether measures work.
  • Include the business function and relevant control functions in the assessment.
  • Set change triggers and the next review date.
Example from day-to-day business

Example: AI-assisted ranking of job applications

A company wants to rank applications by fit. Screening identifies personal data, effects on employment opportunities and possible bias. The DPIA describes sources and criteria, tests errors across relevant groups, limits the system to recommendations, requires human review and creates a route for questions. The residual risk and legal assessment determine whether and how the system is used.

What to remember

Run a short DPIA screening as soon as an AI initiative touches personal data. If a potentially high risk is apparent, the impact assessment belongs in solution design, not at the end of procurement.

Sources and further reading

These primary sources provide further detail on definitions, technical foundations or responsible use.

Content reviewed

Reviewed 17 July 2026. General information, not legal advice. The specific legal position and applicable scope must be assessed for each use case.

Would you like to apply this to your situation?

Together, we clarify what makes sense for your process, data and systems – in plain language and without unnecessary complexity.

Discuss Your Project