GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DAT-013 Data Protection Impact Assessment

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A Data Protection Impact Assessment is conducted before initiating processing activities that are likely to result in high risk to individuals, including large-scale processing of personal data, use of new technologies and systematic profiling. Assessments document the risk, the mitigations and the residual risk, and the results are acted upon before the processing commences. Where an assessment leaves a high residual risk that the organisation cannot mitigate, the supervisory authority is consulted before the processing begins, with the assessment, the responsibilities of the parties, the purposes and means of processing, the safeguards and the data protection officer's contact details supplied, and the authority's written advice and the action taken on it are recorded.

Rationale

Impact assessments are legally required for high-risk processing and are good practice for any AI product, because AI-driven processing frequently meets the threshold. The prior consultation clause closes the assessment loop: without it, an assessment can record a high unmitigated residual risk and the processing proceeds anyway, which is the outcome the assessment exists to prevent. The consultation also has a clock of its own, so a project that discovers it late has lost weeks rather than days.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore

The deployer uses the information the provider supplies to complete its assessment (Art.26.8), obtained through AIG-034.

GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredrole duty

Art.26(9) binds both seats: the deployer uses the information the provider supplies under Art.13 to carry out the data protection impact assessment it owes under Art.35 of Regulation (EU) 2016/679 or Art.27 of Directive (EU) 2016/680. Art.27(4) then runs the other way for the Art.27 seat, letting the fundamental rights impact assessment cross-reference the relevant sections of this one. The two stay separate artefacts on separate legal bases and the cross-reference is what stops the overlap being written twice. At a public body the data protection assessment is frequently already on file from the underlying processing, so the order matters: read it first, then write only the fundamental rights elements it does not reach.

DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (10)

DSP-09Data Protection Impact Assessmentfull
DSP-09Data Protection Impact Assessmentfull
EU-AI-Art.26.8Deployer Obligations — GDPR Data Protection Impact Assessment Supportfull
EU-AI-Art.27Deployer Obligations — Fundamental Rights Impact Assessmentinformative
GDPR-Art.35.1Data Protection Impact Assessment (DPIA) — Obligation to Conductfull
GDPR-Art.35.7Data Protection Impact Assessment (DPIA) — Required Contentpartial
GDPR-Art.35.9Data Subject Consultation in DPIApartial
GDPR-Art.36Prior Consultation with Supervisory Authoritypartial
RA-8Privacy Impact Assessmentsfull
MEASURE 2.10AI Privacy Risk Examinationpartial

Evidence (3)

recorddocumentmanual

Completed DPIA records for high-risk processing activities, documenting risk identification, mitigations applied, and residual risk acceptance.

Example: DPIA report(s) for the primary AI processing features (e.g. user profiling, automated decision-making), each containing: necessity and proportionality assessment, identified risks to data subjects, technical and organisational mitigations, residual risk rating, DPO consultation record, and senior management sign-off

Test: Request DPIAs for the highest-risk processing activities (AI-driven processing, profiling, large-scale personal data processing). Verify: (1) DPIA was completed before the processing commenced, (2) document includes all GDPR Art.35.7 required elements (description, necessity/proportionality assessment, risks, mitigations), (3) DPO was consulted and outcome is recorded, (4) mitigations listed in the DPIA are verifiably implemented.

policydocumentmanual

DPIA policy or procedure defining which processing activities trigger a mandatory DPIA, the methodology to use, and the escalation path for high residual risk.

Example: DPIA Policy (Confluence), approved by DPO, including: trigger criteria (mapping to GDPR Art.35 and ICO/EDPB lists), methodology steps, DPIA template, DPO consultation requirement, mandatory prior consultation criteria for the supervisory authority, and review cycle

Test: Request the DPIA policy and procedure. Verify: (1) defines trigger criteria that include: large-scale processing, systematic profiling, use of new technologies, (2) includes a mandatory DPIA checklist or screening tool, (3) specifies that DPO is consulted on all DPIAs, (4) references when prior consultation with the supervisory authority is required, (5) approved by DPO within 24 months.

recorddocumentmanual

Prior consultation records for assessments that left a high residual risk, with the submission, the authority's written advice and the action taken on it.

Example: Prior consultation file, biometric matching pilot, submitted 2026-01-30

Test: Request the impact assessments rated high residual risk and their consultation files. Verify: (1) every assessment whose residual risk was rated high and unmitigated resolves either to a consultation record or to a recorded decision not to proceed, (2) the submission carries the assessment, the responsibilities of the parties, the purposes and means, the safeguards and the data protection officer's contact details, (3) the processing start date follows the date the advice was received or the statutory period expired, (4) the action taken on the advice is recorded against the assessment, (5) the residual risk rating is applied consistently across assessments rather than being avoided by rating downwards.

Questions (3)

boolean

Does your organisation conduct Data Protection Impact Assessments (DPIAs) before initiating processing activities that are likely to result in high risk to individuals, including AI-driven processing, large-scale profiling, or use of new technologies?

DPIAs must be completed before high-risk processing commences. GDPR Article 35 mandates them for systematic profiling, large-scale processing of special category data, and use of new technologies. AI-driven features frequently meet this threshold.

multi

What triggers a mandatory DPIA in your organisation?

Large-scale processing of personal dataSystematic profiling of individualsUse of AI or automated decision-making that significantly affects individualsProcessing of special categories of data (e.g. health, biometric)Introduction of a new technology or significant change to an existing processing activityDPIAs are conducted at a fixed periodic interval only, not triggered by activity typeNone of the above

Trigger criteria should align with the ICO or EDPB list of processing operations requiring a DPIA. AI processing, profiling and special category data must be included. Fixed-interval-only DPIAs without activity triggers indicate a control gap.

boolean

Where an impact assessment leaves a high residual risk that cannot be mitigated, is the supervisory authority consulted before the processing begins?

Answer yes only where the consultation happens before processing starts and the authority's written advice is recorded against the assessment. The consultation has a statutory clock of its own, so a project that discovers the requirement late loses weeks. A recorded decision not to proceed also satisfies the clause.