GDPR

DPIA for AI: when it is required and a template-style checklist

A data protection impact assessment (DPIA) is required under GDPR Article 35 where processing is likely to result in a high risk to people. Many AI uses qualify: systematic profiling with significant effects, large-scale special-category data, or large-scale monitoring. The AI Act links to it: deployers of high-risk systems use the provider's Article 13 information for their DPIA. Use the checklist below, and copy it into your own record.

sources

Who this applies to

Controllers
The controller carries the DPIA duty, and should seek the advice of the data protection officer where one is designated.
Deployers of high-risk AI systems
Article 26(9) of the AI Act directs deployers to use the provider's Article 13 information to carry out their DPIA where applicable.
Providers and processors
Not the legal owner of the DPIA, but expected to supply facts: data flows, security measures, sub-processors.

When a DPIA is required

Under GDPR Article 35 a DPIA is required before processing that is likely to result in a high risk to the rights and freedoms of natural persons. The Regulation names three cases in particular.

  • Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based.
  • Large-scale processing of special categories of data.
  • Systematic monitoring of a publicly accessible area on a large scale.

Many AI deployments touch at least one: automated screening of applicants, scoring customers, monitoring employees, or an agent with broad access to personal data. Supervisory authorities also publish national lists of processing that needs a DPIA, so check your own. If you decide a DPIA is not required, write down why. Where a DPIA shows high residual risk you cannot mitigate, Article 36 requires prior consultation with the supervisory authority.

What Article 35(7) requires the DPIA to contain

  1. A systematic description of the processing operations and their purposes, including the legitimate interest where relied on.
  2. An assessment of the necessity and proportionality of the processing in relation to the purposes.
  3. An assessment of the risks to the rights and freedoms of data subjects.
  4. The measures envisaged to address the risks, including safeguards, security measures and mechanisms to demonstrate compliance with the Regulation.

How the DPIA fits with the AI Act

  • Article 26(9). Deployers of high-risk AI systems use the provider's Article 13 information (capabilities, limitations, accuracy, oversight) to carry out their DPIA.
  • Article 27 FRIA. Where a fundamental rights impact assessment is required, it complements the DPIA, and the deployer may cross-reference or include relevant DPIA parts. FRIA applies to public bodies, private entities providing public services, and deployers of Annex III points 5(b) and 5(c), before first use.
  • Dates. DPIA duties under GDPR already apply to any current AI use. The AI Act high-risk duties follow from 2 December 2027 for Annex III.

One DPIA can serve both purposes if it is written once, structured around the Article 35(7) elements, and has an AI-specific annex that covers the items below.

Template-style checklist

Copy this into your own document. It is a structure, not a finished assessment or legal advice.

DPIA checklist for an AI system

0 of 29 ticked

1. Description of the processing
2. Necessity and proportionality
3. Risks to people
4. Measures
5. Governance

Ticks stay in your browser and are not sent to Swfte. This is a structure to complete, not legal advice.

How the platform supports it

Each row maps a requirement to a platform control, the evidence artifact it produces, and the Trust & Governance Fabric facets involved. Swfte provides the controls and the evidence. You remain responsible for the decisions.

RequirementPlatform controlEvidence artifactFabric facets
Describe the processing and data flows (Art. 35(7)(a))Trust Profile: owner, approved models, data classification, data residency, permitted systems, allowed and restricted actions.Trust Profile export to attach to the DPIA.Identity, Data controls, Compliance
Show necessity and minimisation (Art. 35(7)(b))Data controls and masking on what an agent can read and write.Classification map and masking policy decisions.Data controls, Privacy, Policy
Show risk measures in operation (Art. 35(7)(d))Policy verbs Allow, Deny, Warn, Filter, Escalate and Require human approval, enforced at runtime.Decision log by policy.Policy, Human oversight, Security
Review the DPIA when something changesMonitoring of model, data-source and policy changes with a change history.Change history and monitoring records.Monitoring, Traceability, Evidence

Compliance-by-design. Swfte provides the technical controls, governance mechanisms and evidence to support deployment within applicable requirements. The exact posture depends on your use case, jurisdiction, deployment and configuration. This is not legal advice.

Hosting today: customer data is stored in AWS eu-west-1 (Ireland), as stated on the trust page. EU region, in-country, dedicated and on-prem options are the platform position: what it is designed to let you do, scoped with you through a dedicated deployment engagement, not self-serve.

What this does not cover

  • Swfte does not write or sign your DPIA. The controller is responsible for it, with its DPO.
  • The platform does not decide whether your processing is high risk or whether you must consult an authority.
  • The checklist is a structure for you to complete. It is not a legal template and does not replace advice from your DPO or counsel.
  • It does not cover non-GDPR impact assessments, such as the Article 27 FRIA, beyond cross-references.

Frequently asked questions

Do I need a DPIA for an AI chatbot?

Not always. A DPIA is required where processing is likely to result in a high risk. A chatbot that handles special-category data at scale, profiles people, or supports significant decisions often will need one. Record your reasoning either way.

What must an Article 35 DPIA contain?

A description of the processing and purposes, an assessment of necessity and proportionality, an assessment of risks to data subjects, and the measures to address those risks (Article 35(7)).

How does a DPIA relate to the AI Act?

Under Article 26(9), deployers of high-risk systems use the provider's Article 13 information for their DPIA. Under Article 27, a fundamental rights impact assessment complements the DPIA where it applies.

Can I download a template?

The checklist above is built into the page, and a copy button saves it as a text file. It is a structure to complete, not legal advice.

Who signs off the DPIA?

The controller. Seek the advice of your data protection officer, record residual risk, and consult the supervisory authority under Article 36 if high residual risk remains.

Sources

Last verified 2026-10-06. Primary sources are EUR-Lex and European Commission pages. Items marked as secondary are commentary or trackers; check the primary text before relying on them.

Across the platform

The controls on this page are part of the Trust & Governance Fabric that runs through every layer of the Sovereign Intelligence Platform.

Build EU-first AI with the evidence already running

Start with one entry point. Add governance, in-region options and evidence as your requirements grow.

Ready to build with Swfte?

One platform for the agents, models and workflows your team ships. Free to start, no card required.