Vai al contenuto

DPIA for artificial intelligence systems

Not needed for every tool with AI inside. Needed when the processing may present a high risk, and in three recurring cases it does.

In breve

An impact assessment is not required for every tool containing artificial intelligence: it is required where the processing may present a high risk to individuals' rights. In a company the recurring cases are three — recruitment, monitoring of workers, and automated decisions affecting individuals. Where doubt remains, carrying one out in short form costs little.

Not for every tool with AI in it

A spelling checker does not require an impact assessment. A system that filters CVs does.

Three recurring business cases

Recruitment, monitoring of workers, automated decisions about people.

In doubt, do a short one

It costs a few hours and still delivers the main benefit: having written down which risks were considered.

It is not AI that triggers it: it is the processing

This is the most widespread misunderstanding since artificial intelligence entered the conversation, and it leads to two opposite mistakes — those who do one for every tool and those who never do one at all.

An impact assessment is required by the GDPR where the processing may present a high risk to individuals’ rights and freedoms. The fact that artificial intelligence is involved is not in itself the condition: an advanced spelling checker requires nothing, while a system that ranks CVs does.

What makes the difference is the combination of two elements: systematic evaluation of people and concrete consequences for them.

The three cases we find in companies

Recruitment. It is the most frequent case and the most underestimated. A tool that filters, ranks or scores CVs evaluates people systematically and produces a very concrete effect: who gets through and who does not. It deserves attention even when the filtering is presented as a simple organisational aid.

Monitoring of worker activity. This often does not arrive as a conscious decision: it arrives as a secondary feature of software bought for something else — productivity, security, ticket management. The fact that nobody explicitly chose it does not make it any less significant.

Automated decisions with effects on people. Assigning terms, granting access to a service, assessing reliability. Here, alongside the impact assessment, the individual’s right not to be subject to a decision based solely on automated processing comes into play.

What changes compared with a traditional DPIA

The structure stays the same: description of the processing, necessity and proportionality, risks, measures. With artificial intelligence systems two elements are added which in practice are the hardest to complete honestly.

Explainability. You have to be able to say on what basis the system arrives at a result. With some tools that is possible only approximately, and that approximation has to be written down rather than hidden.

Effective human oversight. The delicate part is the word effective. A person who formally approves a list already ranked by the system, without the time or the information to question it, is not oversight: it is a tick. How that person can genuinely intervene has to be designed.

The vendor’s documentation is not enough

A serious vendor supplies documentation about their system, and that documentation is useful material.

But the assessment concerns the processing that you carry out: in your context, with your data, for your purposes, on your people. The same tool used by two different companies can produce very different risks. That is why a downloaded and adapted assessment does not survive scrutiny.

In doubt, do a short one

Where it is unclear whether a case requires a formal assessment, the position we recommend is to carry one out in short form: a few pages describing the processing, listing the risks considered and stating which measures were adopted.

It costs a few hours and still delivers the main benefit, which is not the compliance box but having in writing that the risks were assessed. That is exactly what accountability requires, and what distinguishes a company that looked from one that never asked the question.

The rest

See also AI Act, GDPR and AI governance for the overall picture, the company AI policy and GDPR consulting for the obligations upstream. When the obligations become numerous, GAPOFF holds them as tasks with an owner and a deadline rather than as documents in a folder.

The first step

We look at which tools are in use and tell you for which an assessment is genuinely needed and for which it is not. Free and without obligation.

Frequently asked questions

When is a DPIA needed for an artificial intelligence system?

When the processing may present a high risk to individuals' rights and freedoms. It is not the use of AI in itself that triggers it: it is the type of processing. A spelling checker does not require one; a system that assesses candidates, monitors workers or takes automated decisions with effects on people does, because it combines systematic evaluation with concrete consequences.

Which cases do you find most often in companies?

Three. Recruitment, where a tool filters or ranks CVs. Monitoring of worker activity, even when it arrives as a secondary feature of business software. And automated decisions producing effects on a person, such as assigning terms or granting access to a service. All three involve the systematic evaluation of individuals.

Is the DPIA supplied by the software vendor enough?

No, and the confusion is understandable. The vendor can supply documentation about their system, but the impact assessment concerns the processing that you carry out with that system, in your context, with your data and for your purposes. The vendor's documentation is useful material for completing it, not a substitute.

What does it have to contain?

A description of the processing and its purposes, an assessment of necessity and proportionality against that purpose, an analysis of the risks to the people involved, and the measures planned to reduce them. With AI, two specific elements are added - the explainability of the decision and effective human oversight, which has to be real rather than a formal tick.

How long does it take?

A short assessment on a contained case can be closed in a few days. A complete one on a system affecting many people takes longer, particularly in the gathering stage - genuinely understanding how the tool decides, what the vendor declares and which data it uses. The writing is the quickest part.

Are the tools you already use compliant?

The AI Act and the GDPR apply to what entered the company without anyone deciding it, too. Let us establish which obligations genuinely affect you.