DAT-013 Data Protection Impact Assessment
Description
A Data Protection Impact Assessment is conducted before initiating processing activities that are likely to result in high risk to individuals, including large-scale processing of personal data, use of new technologies and systematic profiling. Assessments document the risk, the mitigations and the residual risk, and the results are acted upon before the processing commences. Where an assessment leaves a high residual risk that the organisation cannot mitigate, the supervisory authority is consulted before the processing begins, with the assessment, the responsibilities of the parties, the purposes and means of processing, the safeguards and the data protection officer's contact details supplied, and the authority's written advice and the action taken on it are recorded.
Rationale
Impact assessments are legally required for high-risk processing and are good practice for any AI product, because AI-driven processing frequently meets the threshold. The prior consultation clause closes the assessment loop: without it, an assessment can record a high unmitigated residual risk and the processing proceeds anyway, which is the outcome the assessment exists to prevent. The consultation also has a clock of its own, so a project that discovers it late has lost weeks rather than days.
Applicability (9 profiles)
The deployer uses the information the provider supplies to complete its assessment (Art.26.8), obtained through AIG-034.
Art.26(9) binds both seats: the deployer uses the information the provider supplies under Art.13 to carry out the data protection impact assessment it owes under Art.35 of Regulation (EU) 2016/679 or Art.27 of Directive (EU) 2016/680. Art.27(4) then runs the other way for the Art.27 seat, letting the fundamental rights impact assessment cross-reference the relevant sections of this one. The two stay separate artefacts on separate legal bases and the cross-reference is what stops the overlap being written twice. At a public body the data protection assessment is frequently already on file from the underlying processing, so the order matters: read it first, then write only the fundamental rights elements it does not reach.
Framework Mappings (10)
| DSP-09 | Data Protection Impact Assessment | full |
| DSP-09 | Data Protection Impact Assessment | full |
| EU-AI-Art.26.8 | Deployer Obligations — GDPR Data Protection Impact Assessment Support | full |
| EU-AI-Art.27 | Deployer Obligations — Fundamental Rights Impact Assessment | informative |
| GDPR-Art.35.1 | Data Protection Impact Assessment (DPIA) — Obligation to Conduct | full |
| GDPR-Art.35.7 | Data Protection Impact Assessment (DPIA) — Required Content | partial |
| GDPR-Art.35.9 | Data Subject Consultation in DPIA | partial |
| GDPR-Art.36 | Prior Consultation with Supervisory Authority | partial |
| RA-8 | Privacy Impact Assessments | full |
| MEASURE 2.10 | AI Privacy Risk Examination | partial |
Evidence (3)
Completed DPIA records for high-risk processing activities, documenting risk identification, mitigations applied, and residual risk acceptance.
Example: DPIA report(s) for the primary AI processing features (e.g. user profiling, automated decision-making), each containing: necessity and proportionality assessment, identified risks to data subjects, technical and organisational mitigations, residual risk rating, DPO consultation record, and senior management sign-off
Test: Request DPIAs for the highest-risk processing activities (AI-driven processing, profiling, large-scale personal data processing). Verify: (1) DPIA was completed before the processing commenced, (2) document includes all GDPR Art.35.7 required elements (description, necessity/proportionality assessment, risks, mitigations), (3) DPO was consulted and outcome is recorded, (4) mitigations listed in the DPIA are verifiably implemented.
DPIA policy or procedure defining which processing activities trigger a mandatory DPIA, the methodology to use, and the escalation path for high residual risk.
Example: DPIA Policy (Confluence), approved by DPO, including: trigger criteria (mapping to GDPR Art.35 and ICO/EDPB lists), methodology steps, DPIA template, DPO consultation requirement, mandatory prior consultation criteria for the supervisory authority, and review cycle
Test: Request the DPIA policy and procedure. Verify: (1) defines trigger criteria that include: large-scale processing, systematic profiling, use of new technologies, (2) includes a mandatory DPIA checklist or screening tool, (3) specifies that DPO is consulted on all DPIAs, (4) references when prior consultation with the supervisory authority is required, (5) approved by DPO within 24 months.
Prior consultation records for assessments that left a high residual risk, with the submission, the authority's written advice and the action taken on it.
Example: Prior consultation file, biometric matching pilot, submitted 2026-01-30
Test: Request the impact assessments rated high residual risk and their consultation files. Verify: (1) every assessment whose residual risk was rated high and unmitigated resolves either to a consultation record or to a recorded decision not to proceed, (2) the submission carries the assessment, the responsibilities of the parties, the purposes and means, the safeguards and the data protection officer's contact details, (3) the processing start date follows the date the advice was received or the statutory period expired, (4) the action taken on the advice is recorded against the assessment, (5) the residual risk rating is applied consistently across assessments rather than being avoided by rating downwards.
Questions (3)
Does your organisation conduct Data Protection Impact Assessments (DPIAs) before initiating processing activities that are likely to result in high risk to individuals, including AI-driven processing, large-scale profiling, or use of new technologies?
DPIAs must be completed before high-risk processing commences. GDPR Article 35 mandates them for systematic profiling, large-scale processing of special category data, and use of new technologies. AI-driven features frequently meet this threshold.
What triggers a mandatory DPIA in your organisation?
Trigger criteria should align with the ICO or EDPB list of processing operations requiring a DPIA. AI processing, profiling and special category data must be included. Fixed-interval-only DPIAs without activity triggers indicate a control gap.
Where an impact assessment leaves a high residual risk that cannot be mitigated, is the supervisory authority consulted before the processing begins?
Answer yes only where the consultation happens before processing starts and the authority's written advice is recorded against the assessment. The consultation has a statutory clock of its own, so a project that discovers the requirement late loses weeks. A recorded decision not to proceed also satisfies the clause.