It is not AI that triggers it: it is the processing
This is the most widespread misunderstanding since artificial intelligence entered the conversation, and it leads to two opposite mistakes — those who do one for every tool and those who never do one at all.
An impact assessment is required by the GDPR where the processing may present a high risk to individuals’ rights and freedoms. The fact that artificial intelligence is involved is not in itself the condition: an advanced spelling checker requires nothing, while a system that ranks CVs does.
What makes the difference is the combination of two elements: systematic evaluation of people and concrete consequences for them.
The three cases we find in companies
Recruitment. It is the most frequent case and the most underestimated. A tool that filters, ranks or scores CVs evaluates people systematically and produces a very concrete effect: who gets through and who does not. It deserves attention even when the filtering is presented as a simple organisational aid.
Monitoring of worker activity. This often does not arrive as a conscious decision: it arrives as a secondary feature of software bought for something else — productivity, security, ticket management. The fact that nobody explicitly chose it does not make it any less significant.
Automated decisions with effects on people. Assigning terms, granting access to a service, assessing reliability. Here, alongside the impact assessment, the individual’s right not to be subject to a decision based solely on automated processing comes into play.
What changes compared with a traditional DPIA
The structure stays the same: description of the processing, necessity and proportionality, risks, measures. With artificial intelligence systems two elements are added which in practice are the hardest to complete honestly.
Explainability. You have to be able to say on what basis the system arrives at a result. With some tools that is possible only approximately, and that approximation has to be written down rather than hidden.
Effective human oversight. The delicate part is the word effective. A person who formally approves a list already ranked by the system, without the time or the information to question it, is not oversight: it is a tick. How that person can genuinely intervene has to be designed.
The vendor’s documentation is not enough
A serious vendor supplies documentation about their system, and that documentation is useful material.
But the assessment concerns the processing that you carry out: in your context, with your data, for your purposes, on your people. The same tool used by two different companies can produce very different risks. That is why a downloaded and adapted assessment does not survive scrutiny.
In doubt, do a short one
Where it is unclear whether a case requires a formal assessment, the position we recommend is to carry one out in short form: a few pages describing the processing, listing the risks considered and stating which measures were adopted.
It costs a few hours and still delivers the main benefit, which is not the compliance box but having in writing that the risks were assessed. That is exactly what accountability requires, and what distinguishes a company that looked from one that never asked the question.
The rest
See also AI Act, GDPR and AI governance for the overall picture, the company AI policy and GDPR consulting for the obligations upstream. When the obligations become numerous, GAPOFF holds them as tasks with an owner and a deadline rather than as documents in a folder.
The first step
We look at which tools are in use and tell you for which an assessment is genuinely needed and for which it is not. Free and without obligation.