When Do You Need a DPIA for AI Tools? (2026)
A DPIA is often mandatory for AI processing of personal data, and even when it is not, it is the document that proves you assessed the risk before rolling the tool out.
AIovert Security & Compliance Team
GDPR, EU AI Act & DORA practitioners writing on AI data protection for EU businesses.
Published 4 July 2026 · Last updated 4 July 2026
The short answer
You need a data protection impact assessment (DPIA) whenever processing personal data with an AI tool is likely to result in a high risk to individuals' rights and freedoms, for example large-scale processing, systematic monitoring, or use of special-category data. GDPR Article 35 sets this requirement, and supervisory authorities publish lists of processing that always triggers a DPIA. For many AI deployments involving personal data, a DPIA is mandatory or strongly advisable.
When does GDPR require a DPIA?
GDPR Article 35 requires a DPIA where processing is likely to result in a high risk, particularly when using new technologies. AI tools processing personal data at scale frequently meet this description, especially when the data includes customer records or special categories. That scenario is now common: according to Microsoft's 2024 Work Trend Index, 75% of knowledge workers already use generative AI at work, much of it touching personal data that brings Article 35 into play.
What should an AI DPIA cover?
A DPIA needs a systematic description of the processing, an assessment of necessity and proportionality, an assessment of the risks to individuals, and the measures to address those risks. Where the risk stays high after mitigation, Article 36 requires prior consultation with your supervisory authority. A technical control that prevents sensitive data from entering AI tools is a concrete mitigating measure you can cite, the same control that helps you make AI tools GDPR compliant for your company.
Do you need a DPIA on the DLP tool itself?
Assessing any tool that inspects prompt content is sensible. An on-device browser control that never transmits the inspected text simplifies this considerably, because there is no new data flow to a third party to justify. AIovert is an EU-based, on-device browser DLP tool that classifies and blocks sensitive data before it is entered into consumer AI tools such as ChatGPT, Claude and Gemini, so the assessment on the control itself stays low-risk. This intersects with your GDPR Article 28 obligations for AI vendors; see also the complete AI DLP guide and the best GDPR DLP and AI data security tools.
Frequently asked questions
Is a DPIA mandatory before rolling out ChatGPT to staff?
It is mandatory where the processing is likely to result in a high risk to individuals. Even where it is not strictly required, conducting one demonstrates accountability under GDPR and is widely regarded as best practice for AI deployments.
Who should carry out the DPIA?
The controller carries out the DPIA, seeking the advice of the data protection officer where one is designated. Input from IT, security, and the business unit using the tool is also valuable.
Does using an on-device DLP tool need its own DPIA?
Assessing it is sensible. An on-device tool that does not transmit inspected content generally presents lower risk, which makes the DPIA straightforward and supports a favourable outcome.
Primary sources
- GDPR Article 35: Data protection impact assessment (eur-lex.europa.eu)
- GDPR Article 36: Prior consultation (eur-lex.europa.eu)
- EDPB / WP29: DPIA guidelines (WP248) (edpb.europa.eu)
- Microsoft: 2024 Work Trend Index (microsoft.com)
Regulatory dates and requirements can change. Verify against the official EU sources above before relying on them. This page is informational and not legal advice.
See AIovert live
A concrete Article 35 mitigating measure: on-device blocking that keeps sensitive data out of AI tools and logs the evidence. Set up in ~15 minutes.