On an episode of CZ and Friends, GC AI's podcast hosted by CEO Cecilia Ziniti, Cecilia gave her first example of AI working inside a legal department, and it was a data protection impact assessment:
"I'm using it for my job in legal. I'm doing a data privacy impact assessment. I'm going to have AI help me specifically go through a checklist."
The guest she said it to was Nicole Altman, Senior Counsel at Instacart, who leads AI governance, privacy, security, and IP for a public company. The DPIA is the document privacy and in-house counsel reach for when a new vendor, a new feature, or a new dataset crosses the line into "this could be high risk." Under GDPR Article 35, running one is mandatory for certain processing. Getting the trigger wrong is how a routine product launch turns into a regulator conversation.
GDPR Article 35 requires a data protection impact assessment whenever processing is likely to result in a high risk to people's rights and freedoms, and always in three cases: large-scale profiling with significant effects, large-scale processing of special-category or criminal-offense data, and systematic monitoring of public areas. The controller owns the obligation, and the nine-criteria screen below decides every case the mandatory triggers miss.
What Is a Data Protection Impact Assessment?
A data protection impact assessment (DPIA) is a documented process for identifying and minimizing the data protection risks of a processing activity before it starts. It is required under Article 35 of the GDPR whenever a type of processing, particularly one using new technology, is "likely to result in a high risk to the rights and freedoms of natural persons."
Three things separate a DPIA from a generic risk memo:
It is forward-looking. The assessment happens before processing begins, while the design can still change.
It is structured. Article 35(7) prescribes what it has to contain.
It is accountable. The controller has to be able to show the regulator the assessment on request.
The UK ICO and the EU supervisory authorities treat a missing or inadequate DPIA as a compliance failure in its own right, separate from whatever risk the processing goes on to create.
For in-house counsel, the DPIA is also a forcing function. It is the one moment in a product cycle where legal, security, and the business sit down and answer "do we need all this data, and what happens if it leaks." That conversation, documented before launch, is the point of the exercise.
When Is a DPIA Required Under GDPR Article 35?
A DPIA is required whenever processing is likely to result in a high risk to individuals' rights and freedoms. Article 35(3) names three cases where a DPIA is always mandatory. For everything else, the EDPB-endorsed nine criteria do the sorting.
The Three Mandatory Triggers in Article 35(3)
Under Article 35(3), three kinds of processing always require a DPIA:
Systematic and extensive automated evaluation or profiling with legal or similarly significant effects
Large-scale processing of special-category or criminal-offense data
Systematic monitoring of a publicly accessible area on a large scale
Here is where each one bites in practice.
Systematic and extensive profiling with significant effects. Credit scoring, automated hiring screens, and most AI-driven eligibility decisions sit here. The trigger is the combination: automated evaluation plus an outcome that changes what someone can get or do.
Large-scale special-category or criminal-offense data. Special categories under Article 9 include health, biometric, genetic, racial or ethnic, religious, and sexual-orientation data. A health app, an HR system holding disability records, or a platform running criminal-background checks at scale falls in.
Systematic monitoring of public areas at scale. CCTV networks, license-plate readers, and location tracking across public spaces are the textbook examples.
Match any one of these and the screening is over. You run the assessment.
The Screening Test for Everything Else: The Nine Criteria
Plenty of processing falls outside the three mandatory cases, so the Article 29 Working Party's WP248 rev.01 guidelines, endorsed by the EDPB and mirrored in ICO guidance, give nine criteria that signal likely high risk. Hit two or more and the working rule says you run a DPIA. Here are the nine:
Evaluation or scoring, including profiling
Automated decision-making with legal or similarly significant effect
Systematic monitoring
Sensitive data or data of a highly personal nature
Data processed on a large scale
Matching or combining datasets
Data concerning vulnerable data subjects
Innovative use or application of new technology
Processing that prevents people from exercising a right or using a service or contract
On a real vendor intake, the criteria look like this:
Evaluation or scoring covers profiling and predicting behavior, interests, performance, or health. A vendor that ranks your customers by likelihood to churn is scoring people.
Automated decision-making with legal or similarly significant effect is the loan approval, the insurance quote, or the hiring screen where no human meaningfully intervenes before the outcome lands.
Systematic monitoring includes employee-productivity tracking and any methodical observation of people, including in public spaces.
Sensitive data or data of a highly personal nature reaches beyond the Article 9 special categories to financial data, location history, and private communications.
Data processed on a large scale is judged by data volume, number of people, duration, and geographic reach.
Matching or combining datasets catches enrichment: joining your CRM to a purchased demographic file, or merging two user bases after an acquisition.
Data concerning vulnerable data subjects includes employees, children, and patients, anywhere a power imbalance limits how freely someone can object.
Innovative use or application of new technology is the criterion doing the most work in 2026: facial recognition, IoT sensors, and AI models applied to personal data.
Processing that prevents people from exercising a right or using a service or contract covers screening tools that gate access to a loan, a job, or an account.
Two criteria together is the standard threshold, and the guidance is explicit that a single criterion can be enough when the risk is high. When in doubt, the cheaper move is to run the assessment.
Why the Nine Criteria Now Catch Almost Every AI Project
Read the list again with an AI deployment in mind. A vendor that scores candidates hits evaluation, automated decision-making, and innovative technology in one stroke. A customer-support model trained on chat logs touches large-scale processing, matching datasets, and new technology. The criteria were written in 2017, and AI adoption has walked most legal departments straight into them.
AI regulation and governance work now runs through this one document more than any other, which is why a fast, repeatable DPIA process matters more than it used to.
The enforcement risk is concrete on two levels. Skipping a required DPIA is an independent GDPR infringement, fineable up to 10 million euros or 2% of total worldwide annual turnover under Article 83(4), whichever is higher. And regulators use it.
Sweden's first GDPR fine, SEK 200,000 against a Skellefteå school board, landed on a three-week facial recognition pilot that tracked attendance for 22 students. The Swedish DPA cited Articles 5, 9, 35, and 36: biometric data on vulnerable subjects, an inadequate impact assessment, and a missing prior consultation. A three-week pilot with 22 students earned Sweden's first GDPR fine; screen every AI project against the nine criteria before it starts.
How to Run a Data Protection Impact Assessment: Step by Step
A defensible DPIA follows the structure Article 35(7) requires; the five steps below fold the ICO's longer process checklist into a sequence an in-house team can run:
Describe the processing
Assess necessity and proportionality
Identify and score the risks
Identify measures to mitigate each risk
Consult, sign off, and keep it living
Timing and the room matter as much as the sequence. Run the screen at vendor intake or product kickoff. That timing is the leverage: the design can still change, and a mitigation you name in the DPIA can still ship before launch. Legal chairs the assessment, the business owner of the processing supplies the facts, and security scores the technical risks with you.
Step 1: Describe the Processing
Write a plain-language description of what you are doing with the data: the nature, scope, context, and purposes of the processing. Capture what data you collect, how, where it flows, who has access, how long you keep it, and which third parties or sub-processors touch it. A data-flow map beats prose here. This section is also where you record your lawful basis under Article 6.
Step 2: Assess Necessity and Proportionality
Article 35(7)(b) requires an honest answer to "do we need all of this." Document why the processing is necessary to achieve the stated purpose, whether a less intrusive option would work, and how you are honoring data minimization, retention limits, and data-subject rights. This is the step the business resists and the regulator reads first.
Step 3: Identify and Score the Risks
List the risks to individuals: unauthorized access, loss, discrimination from a biased model, loss of control over personal data, reputational or financial harm. For each, score likelihood and severity. The ICO is explicit that high risk is a function of both, so a low-probability catastrophic outcome still counts.
Step 4: Identify Measures to Mitigate Each Risk
For every risk above your tolerance, name a control: encryption, pseudonymization, access restrictions, retention limits, a data processing agreement with the vendor, human review of automated decisions, or dropping a data field entirely. Record the residual risk after the control is applied.
Step 5: Consult, Sign Off, and Keep It Living
Article 35(2) requires you to seek the advice of your data protection officer where one is designated, and Article 35(9) says you should, where appropriate, seek the views of the people whose data you process. If a high residual risk remains that you cannot mitigate, Article 36 requires prior consultation with your supervisory authority before you begin. Then get the sign-off documented, and revisit the DPIA when the processing changes. Treat the DPIA as a living record you update each time the processing shifts. A high residual risk you cannot mitigate means, under Article 36, the regulator hears about the project before your users do.
A DPIA Template You Can Copy
The structure below maps each section to the Article 35(7) requirement it satisfies and puts the nine-criteria screen at the top, so you can decide in five minutes whether a DPIA is even required. Copy it into your own doc, rename it per project, and keep the completed versions in one place so your accountability trail is ready when a regulator asks.
1. Screening (do we even need a DPIA?)
List which of the nine criteria the processing hits. Two or more, or any single high-risk criterion, means you run the full assessment below.
2. Describe the processing (Article 35(7)(a))
Nature, scope, context, and purposes. Data collected, how it flows, who has access, retention period, sub-processors, and your lawful basis under Article 6. Attach a data-flow map.
3. Necessity and proportionality (Article 35(7)(b))
Why the processing is necessary for the stated purpose, whether a less intrusive option exists, and how you honor data minimization, retention limits, and data-subject rights.
4. Risk register (Article 35(7)(c))
One row per risk to individuals, with columns for the risk, its likelihood, its severity, the mitigation applied, and the residual risk that remains.
5. Measures and sign-off (Article 35(7)(d))
The controls that address each risk, the DPO's advice under Article 35(2), any data-subject views sought under Article 35(9), and a dated sign-off. Note any high residual risk that triggers Article 36 prior consultation.
Keep the completed file living. Revisit it whenever the processing changes. Even a screen that ends "no DPIA required" belongs in the file; the documented reason is the accountability record.
DPIA Requirements Beyond GDPR: US State Privacy Laws
US state privacy laws now require DPIA-equivalent assessments, and the newest rules took effect January 1, 2026. A GDPR-grade DPIA process covers the state requirements with light adaptation. Teams that skipped the discipline because they hold no EU data now face the same duty at home.
California. The CPPA's updated CCPA regulations require a risk assessment before initiating any processing that presents significant risk to consumers' privacy, including selling or sharing personal information for targeted advertising and processing sensitive data such as precise geolocation, biometrics, or health information. New processing needs an assessment from January 1, 2026; pre-existing activities have until December 31, 2027; businesses submit assessment information to the agency by April 1, 2028 and review each assessment at least every three years.
Colorado. The Colorado Privacy Act requires data protection assessments for processing that presents a heightened risk of harm: targeted advertising, profiling, selling personal data, and sensitive-data processing. The attorney general can demand the assessment and give you 30 days to produce it.
The rest of the map. Most comprehensive state privacy laws, including Virginia's and Connecticut's, carry an equivalent assessment duty for targeted advertising, sales, profiling, and sensitive data.
The practical move is one assessment framework with a jurisdiction field. Screen once, record which regimes the processing touches, and let the GDPR version ask the hardest questions; the state versions ride along.
Where Legal AI Helps You Run the Assessment
The duties in GDPR Article 35 belong to the controller and the lawyer signing off on the assessment, and no platform can discharge them for you. What a legal AI platform can do is take the slow, mechanical parts off your plate so you spend your hours on the judgment calls.
This is the workflow Cecilia named in that podcast clip.
On a new vendor DPIA, a privacy lawyer can:
Run the nine-criteria screen as a saved checklist in the Skill Library, so the intake question ("do we even need a DPIA?") takes minutes instead of a meeting.
Pull the vendor's DPA and privacy policy into Files and analyze them against your standards.
Confirm the current ICO or EDPB position on a processing type with Research, cited to primary sources.
Trace every flagged risk to the contract's exact words with Exact Quote, which pulls the supporting clause with character-level citation.
If you want the checklist Cecilia described, it is one prompt: "Here are the nine WP248 criteria. Here is the vendor's DPA and privacy policy. Score the processing against each criterion and quote the clause that supports every hit." Save it once, and every vendor screen after that starts warm.
For the contract review that often runs alongside a vendor DPIA, GC AI includes a pre-built Playbook for DPAs and can analyze a data protection clause against your positions
Watch a live Playbook review where a solutions attorney catches a DPA incorporated by hyperlink instead of exhibit, the kind of finding a DPIA risk register exists to record. And because the assessment has to track the processing as it changes, Automations can schedule the periodic re-screen, so the review that keeps it current runs on a calendar instead of a memory.
Privacy counsel will run the vendor screen on the AI platform itself before loading a single document, and the platform should welcome the scrutiny. GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with its model providers wherever feasible, and AES-256 encryption. How a legal AI platform handles data security belongs in your assessment the same way any vendor's posture does.
KT Farley, Chief Privacy Officer and Associate General Counsel at Helix, described the compliance version of this:
"A partner asked me to quickly draft a response to a HIPAA compliance question. Usually this would take me an hour, switching context, creating a doc, writing it up. With GC AI it was much faster. I am still saying, 'here are the two HIPAA points I want to make' but can then finalize quickly without derailing the rest of my workload."
The lawyer still makes the two points. Andrea Peters, Senior Counsel and Global Head of Compliance at Interface, uses the research layer the same way for cross-border work, asking GC AI to surface what a regulatory requirement says before she drafts around it.
As of September 2026, more than 2,100 legal teams across 47 countries use GC AI, including 300-plus public companies, many of them running privacy and compliance work like this every week.
Start with your next vendor onboarding. Run the nine-criteria screen on it this week, complete the assessment if two or more criteria hit, and keep the completed DPIA where your accountability trail lives. By the third one, the process takes an afternoon instead of a week.
Frequently Asked Questions
What Is the Difference Between a DPIA and a PIA?
A DPIA is the GDPR-specific privacy impact assessment defined in Article 35, with mandatory triggers and required contents under EU and UK data protection law. A PIA, or privacy impact assessment, is the broader, older term used in many jurisdictions for any structured review of privacy risk. Every DPIA is a PIA; the DPIA adds the mandatory triggers, required contents, and enforcement exposure that GDPR attaches to it.
Who Is Responsible for Carrying Out a DPIA?
The data controller is responsible for carrying out a DPIA and for ensuring it gets done. Under Article 35(2), the controller must seek the advice of the data protection officer where one is designated. In-house legal and privacy teams typically run the assessment, with input from security, engineering, and the business owner of the processing activity. The accountability for the result stays with the controller.
Do You Need a DPIA for AI Tools?
You likely need a DPIA for an AI tool when it scores or profiles people, makes or supports automated decisions with significant effects, processes personal data at scale, or applies new technology to personal data, because each of these is one of the nine high-risk criteria. Many AI deployments hit two or more criteria at once, which is the standard threshold for running a DPIA. Screen the specific use case against the nine criteria before deployment; the screen itself takes minutes.
When Is a DPIA Not Required?
A DPIA is not required when the processing misses the high-risk markers: none of the three Article 35(3) triggers, fewer than two of the nine criteria, and no place on your supervisory authority's list of processing that requires one. Article 35(5) lets each supervisory authority publish a list of processing operations exempt from the requirement, and GDPR Recital 91 carves out processing of patient or client data by an individual physician, health care professional, or lawyer, which falls outside "large scale." When the screen is close, run the assessment anyway.
Does GDPR Article 35 Apply to Companies Outside the EU?
Yes, when GDPR itself applies. Article 3(2) extends GDPR to companies outside the EU that offer goods or services to people in the EU or monitor their behavior there, and the Article 35 DPIA duty travels with the regulation. A US company running large-scale profiling of EU users owes the same assessment as a controller based in Paris.
What Happens if You Fail to Carry Out a Required DPIA?
Failing to carry out a required DPIA is an independent GDPR infringement, fineable up to 10 million euros or 2% of total worldwide annual turnover under Article 83(4), whichever is higher. Sweden's first GDPR fine, SEK 200,000 against a school board's three-week facial recognition pilot, cited an inadequate impact assessment under Article 35 and a missing Article 36 prior consultation.
What Is the Difference Between a DPIA and a DPA?
A DPIA is the risk assessment a controller runs under GDPR Article 35 before high-risk processing begins. A DPA, or data processing agreement, is the contract Article 28 requires between a controller and a processor. On a vendor deal the two travel together. The assessment sizes the risk, and the agreement locks in the safeguards it calls for.
Can AI Help Me Complete a Data Protection Impact Assessment Faster?
Yes, a legal AI platform built for in-house work can speed up the mechanical parts of a DPIA while the lawyer keeps the judgment. GC AI can run the nine-criteria screen as a saved checklist, analyze a vendor's data processing agreement against your standards, and surface the current regulatory position with citations to primary sources. The controller and the signing lawyer still own the assessment and its conclusions; the platform handles the gathering and drafting.







