Guide GDPR AI Compliance

When AI processing requires a DPIA: what triggers the test and what to put in it

Most organisations have filed a DPIA at some point. Far fewer have run one for their AI tools. GDPR Article 35 requires an assessment before processing that is likely to result in high risk to individuals. Most enterprise AI deployments now meet that threshold, often without anyone realising it.

RD
Ryland Deakin
Lead Consultant, Cyvra
21 July 2026
9 min read

What Article 35 actually requires

GDPR Article 35 requires a Data Protection Impact Assessment before any processing likely to result in a high risk to the rights and freedoms of natural persons. The word "before" matters. This is a prior obligation, not something you can complete retrospectively once a tool is already live. If you have deployed an AI tool that meets the threshold without a completed DPIA, you are in breach until the assessment is done.

The European Data Protection Board's Guidelines 09/2022 translate "likely high risk" into nine operational criteria. Meeting two or more requires a DPIA. Meeting fewer does not automatically mean you are clear: supervisory authorities can still require one, and documenting why you concluded a DPIA was unnecessary is itself good practice.

The nine criteria

These are the EDPB's criteria. Two or more means a DPIA is required before processing begins.

01
Evaluation or scoring, including profiling based on personal data
02
Automated decision-making with significant or legal effects on individuals
03
Systematic monitoring of employees, customers, or public spaces
04
Processing sensitive data: health, financial, biometric, religious, political, or criminal
05
Large-scale data processing
06
Matching or combining datasets from separate sources
07
Processing data of vulnerable individuals, including employees, patients, or children
08
Innovative use of a new technological solution or approach
09
Processing that prevents data subjects from exercising their rights or accessing a service

Criteria 8 applies to virtually every AI tool in an enterprise context. Generative AI, large language models, and AI-powered analytics are all classified as innovative technologies by EU supervisory authorities. Combined with criterion 1, which applies to any system that evaluates or scores individuals, most AI deployments trigger the threshold before you reach criteria 3 through 7.

Where AI tools sit against these criteria

The four scenarios below cover the AI use cases regulators are paying most attention to. Each one identifies which criteria apply and why.

Scenario 1
HR and recruitment AI
AI that screens CVs, scores candidates, or analyses employee performance data hits criteria 1 (scoring), 2 (decisions that affect employment), and 7 (employees are a vulnerable category in most DPA guidance). This is the scenario most commonly deployed without a DPIA.
Scenario 2
Customer profiling and scoring
Retail, financial services, and insurance platforms using AI to profile behaviour, assess creditworthiness, or personalise offers trigger criteria 1 and 5 at minimum. Financial or health data in the profile adds criterion 4. Most implementations also combine datasets from multiple sources, adding criterion 6.
Scenario 3
Employee productivity and communication monitoring
Tools that analyse work patterns, meeting frequency, response times, or document activity to generate insights about individual employees trigger criteria 3 (systematic monitoring), 7 (employees), and 8 (innovative technology). Microsoft Copilot configured to summarise employee activity falls here.
Scenario 4
Automated access and eligibility decisions
AI systems that determine who can access a service, benefit, or resource without human review trigger criterion 2. If the AI is opaque about how it reached the decision, criterion 9 also applies. Fraud detection systems and access control models often sit here.

Does Microsoft Copilot require a DPIA?

For most organisations: yes.

Copilot processes email, Teams conversations, SharePoint documents, and calendar data under the permissions of the signed-in user. It meets criterion 8 immediately (innovative technology) and criterion 3 when used in a context where it analyses or summarises employee communications at scale. If your HR, legal, or management teams use Copilot to review performance information, identify patterns in email threads, or draft assessments based on employee data, criteria 1 and 2 apply too.

A DPIA does not block deployment. It requires you to document the processing, identify risks, and put mitigations in place. The permissions review, sensitivity label configuration, and acceptable use policy covered in our Copilot governance article all count as documented mitigations and belong in the DPIA.

Before vs after deployment

A DPIA completed after deployment is better than no DPIA, but it does not remove the breach that occurred during the gap. If a data incident happens while a tool is running without a mandatory DPIA, regulators treat the absence of the assessment as an aggravating factor in enforcement decisions.

What a DPIA must actually contain

GDPR Article 35(7) specifies four components. Every DPIA must address all four, regardless of format or length.

  1. A systematic description of the processing: what data the AI tool processes, where it comes from, how long it is retained, and the purposes for which it is used
  2. An assessment of necessity and proportionality: why this processing is needed to achieve the stated purpose, and whether a less privacy-intrusive approach could achieve the same result
  3. An assessment of risks to rights and freedoms: specific risks to individuals, with an assessment of likelihood and severity for each
  4. Measures to address each identified risk: technical and organisational safeguards, with a clear mapping between each risk and its mitigation

Where the organisation has a Data Protection Officer, they must be consulted and their advice documented. Where residual risk remains high after mitigations, the supervisory authority must be consulted before processing begins.

What to document: a practical checklist

Processing description. Name the AI tool, the vendor, the data flows, the legal basis for processing, the categories of data involved, and the retention period. Be specific: "Microsoft Copilot for Microsoft 365, processing email and Teams data under legitimate interests, retained per Microsoft's 30-day prompt log policy."
Nine-criteria assessment. Work through each criterion and document whether it applies, with reasoning. If fewer than two apply, record why and keep it on file. If two or more apply, proceed to full DPIA.
Necessity and proportionality test. Articulate what the tool achieves and why that objective requires this level of data access. Document any alternatives considered and why they were not sufficient.
Risk register. List each specific risk with a likelihood (low, medium, high) and severity (low, medium, high) rating. Common AI risks include: data exposure through over-permissioned access, discriminatory outputs from biased training data, and unauthorised re-use of personal data in model outputs.
Mitigations mapped to each risk. For each risk in the register, document the specific control that addresses it. Technical controls (sensitivity labels, access reviews, audit logging) and organisational controls (acceptable use policy, training, DPO review) both count.
DPO consultation. If your organisation has a DPO, document their input and whether they agreed with the risk assessment and proposed mitigations. If they disagreed, record that too: DPOs have independent standing under GDPR and their concerns cannot simply be overruled.
Review date. A DPIA is not a one-time document. Set a review trigger: any significant change to the AI tool's functionality, the data it accesses, or the vendor's terms should prompt a review. Annual review is a sensible default for tools that remain in active use.

DPIA and the EU AI Act: two separate requirements

From 2 December 2027, high-risk AI systems under the EU AI Act Annex III also require a conformity assessment covering accuracy, robustness, transparency, and human oversight. This is separate from a DPIA and serves a different legal framework. Systems that trigger Annex III classification will almost certainly also require a DPIA, but the two assessments address different questions and must be documented separately.

Running both in parallel is more efficient than completing them sequentially. Many of the inputs are shared: the processing description, the data categories, the vendor relationship, and the risk register all feed into both documents.

A DPIA does not have to be a 60-page document. It needs to be honest: specific about what the AI is doing, candid about the risks, and clear about what you are doing to address them.

Where to start

Start with an inventory of AI tools currently in use across the organisation, including those brought in by individual departments without central IT involvement. For each tool, run through the nine-criteria test. Any tool that scores two or more goes onto the DPIA backlog.

Prioritise by exposure: tools that process employee data, customer personal data at scale, or sensitive categories first. For tools already deployed without a DPIA, complete the assessment now and document that it was done retrospectively. Regulators expect organisations to catch up when they discover a gap, and a completed DPIA on file is significantly better than none.

Cyvra supports organisations through the full DPIA process for AI tools: from the initial processing inventory and nine-criteria assessment through to the completed risk register, mitigation mapping, and DPO liaison. Contact us to discuss what your current AI stack requires.

A DPIA sits within the broader GDPR compliance framework. For AI systems that also fall under the EU AI Act Annex III, the conformity assessment runs in parallel with the DPIA and shares much of the same evidence base.

Frequently asked questions

Is a DPIA mandatory for every AI tool?

No, but the threshold is lower than most organisations expect. A DPIA is required when processing is likely to result in high risk to individuals. The EDPB's nine-criteria test is the practical way to assess this: if your AI tool meets two or more of those criteria, a DPIA is required. Most enterprise AI tools meet at least two by default, typically criterion 8 (innovative technology) and criterion 1 (evaluation or scoring). HR AI, customer profiling tools, and employee monitoring systems almost always meet more.

What happens if we deploy AI without a DPIA when one was required?

Deploying without a mandatory DPIA is a breach of GDPR Article 35. Supervisory authorities can impose fines of up to €10 million or 2% of global annual turnover, whichever is higher. Beyond the fine risk, the absence of a DPIA is one of the first things regulators check when investigating an AI-related data incident. A completed DPIA also demonstrates accountability, which regulators weigh when deciding enforcement severity.

Does Microsoft Copilot require a DPIA?

For most organisations, yes. Copilot processes email, Teams conversations, documents, and calendar data under the permissions of the signed-in user. It meets criterion 8 (innovative technology) and criterion 3 (systematic monitoring) when used on employee communications. If HR teams use it to summarise performance data or identify patterns in employee activity, criteria 1 and 2 also apply. The DPIA does not prevent Copilot deployment: it requires you to document the processing, assess the risks, and put mitigations in place before going live.

How long does a DPIA take to complete?

A focused DPIA for a single AI tool typically takes two to four weeks when the organisation already has a processing inventory and data map in place. Without that baseline, scoping the processing description alone can take longer. The DPIA does not need to be long: a well-structured 10-page document that honestly addresses the four required components of GDPR Article 35(7) is more valuable than a 60-page template exercise.

What is the difference between a DPIA and an EU AI Act conformity assessment?

A DPIA is a GDPR obligation focused on data protection risks to individuals. An EU AI Act conformity assessment applies to high-risk AI systems under Annex III and covers accuracy, robustness, transparency, and human oversight requirements. The two overlap but serve different legal frameworks and must be completed separately. For systems that trigger both, running them in parallel is significantly more efficient than completing them sequentially.

How does Cyvra help organisations complete a DPIA for AI tools?

Cyvra runs a structured DPIA process that starts with a processing inventory for the AI tool, applies the EDPB nine-criteria test, and produces a documented risk assessment with mitigations mapped to each identified risk. We work with your DPO where one exists, or advise on external DPO support where required. The output is a DPIA that satisfies supervisory authority expectations and supports the accountability documentation your organisation needs under GDPR.

Ryland Deakin
About the author
Lead Consultant, Cyvra · CISM · CompTIA Security+ · MCP

Ryland has delivered cybersecurity, compliance, and IT management programmes for regulated organisations across the UK and the Netherlands for over 20 years, including senior roles at Microsoft, ING, IPsoft, PPHE and more. View full profile

Work with Cyvra

Need a DPIA for your AI tools?

We run the full assessment: processing inventory, nine-criteria test, risk register, and mitigation mapping, ready for your DPO and supervisory authority.

Disclaimer: This article is for informational purposes only and does not constitute legal, regulatory, or professional advice. Cyvra makes no representations as to the accuracy or completeness of this content. Readers should seek independent professional advice tailored to their specific circumstances.