What Article 35 actually requires
GDPR Article 35 requires a Data Protection Impact Assessment before any processing likely to result in a high risk to the rights and freedoms of natural persons. The word "before" matters. This is a prior obligation, not something you can complete retrospectively once a tool is already live. If you have deployed an AI tool that meets the threshold without a completed DPIA, you are in breach until the assessment is done.
The European Data Protection Board's Guidelines 09/2022 translate "likely high risk" into nine operational criteria. Meeting two or more requires a DPIA. Meeting fewer does not automatically mean you are clear: supervisory authorities can still require one, and documenting why you concluded a DPIA was unnecessary is itself good practice.
The nine criteria
These are the EDPB's criteria. Two or more means a DPIA is required before processing begins.
Criteria 8 applies to virtually every AI tool in an enterprise context. Generative AI, large language models, and AI-powered analytics are all classified as innovative technologies by EU supervisory authorities. Combined with criterion 1, which applies to any system that evaluates or scores individuals, most AI deployments trigger the threshold before you reach criteria 3 through 7.
Where AI tools sit against these criteria
The four scenarios below cover the AI use cases regulators are paying most attention to. Each one identifies which criteria apply and why.
Does Microsoft Copilot require a DPIA?
For most organisations: yes.
Copilot processes email, Teams conversations, SharePoint documents, and calendar data under the permissions of the signed-in user. It meets criterion 8 immediately (innovative technology) and criterion 3 when used in a context where it analyses or summarises employee communications at scale. If your HR, legal, or management teams use Copilot to review performance information, identify patterns in email threads, or draft assessments based on employee data, criteria 1 and 2 apply too.
A DPIA does not block deployment. It requires you to document the processing, identify risks, and put mitigations in place. The permissions review, sensitivity label configuration, and acceptable use policy covered in our Copilot governance article all count as documented mitigations and belong in the DPIA.
A DPIA completed after deployment is better than no DPIA, but it does not remove the breach that occurred during the gap. If a data incident happens while a tool is running without a mandatory DPIA, regulators treat the absence of the assessment as an aggravating factor in enforcement decisions.
What a DPIA must actually contain
GDPR Article 35(7) specifies four components. Every DPIA must address all four, regardless of format or length.
- A systematic description of the processing: what data the AI tool processes, where it comes from, how long it is retained, and the purposes for which it is used
- An assessment of necessity and proportionality: why this processing is needed to achieve the stated purpose, and whether a less privacy-intrusive approach could achieve the same result
- An assessment of risks to rights and freedoms: specific risks to individuals, with an assessment of likelihood and severity for each
- Measures to address each identified risk: technical and organisational safeguards, with a clear mapping between each risk and its mitigation
Where the organisation has a Data Protection Officer, they must be consulted and their advice documented. Where residual risk remains high after mitigations, the supervisory authority must be consulted before processing begins.
What to document: a practical checklist
DPIA and the EU AI Act: two separate requirements
From 2 December 2027, high-risk AI systems under the EU AI Act Annex III also require a conformity assessment covering accuracy, robustness, transparency, and human oversight. This is separate from a DPIA and serves a different legal framework. Systems that trigger Annex III classification will almost certainly also require a DPIA, but the two assessments address different questions and must be documented separately.
Running both in parallel is more efficient than completing them sequentially. Many of the inputs are shared: the processing description, the data categories, the vendor relationship, and the risk register all feed into both documents.
A DPIA does not have to be a 60-page document. It needs to be honest: specific about what the AI is doing, candid about the risks, and clear about what you are doing to address them.
Where to start
Start with an inventory of AI tools currently in use across the organisation, including those brought in by individual departments without central IT involvement. For each tool, run through the nine-criteria test. Any tool that scores two or more goes onto the DPIA backlog.
Prioritise by exposure: tools that process employee data, customer personal data at scale, or sensitive categories first. For tools already deployed without a DPIA, complete the assessment now and document that it was done retrospectively. Regulators expect organisations to catch up when they discover a gap, and a completed DPIA on file is significantly better than none.
Cyvra supports organisations through the full DPIA process for AI tools: from the initial processing inventory and nine-criteria assessment through to the completed risk register, mitigation mapping, and DPO liaison. Contact us to discuss what your current AI stack requires.
A DPIA sits within the broader GDPR compliance framework. For AI systems that also fall under the EU AI Act Annex III, the conformity assessment runs in parallel with the DPIA and shares much of the same evidence base.