Compliance / EU

DPIA (Data Protection Impact Assessment)

A DPIA (Data Protection Impact Assessment) is a mandatory impact study required by Article 35 GDPR. It applies to any processing likely to result in a high risk to the rights and freedoms of natural persons, especially large-scale processing and processing involving AI.

Definition and legal basis

A DPIA is required by Article 35 GDPR. It is a prior analysis, to be carried out before implementing a processing operation, in order to identify and mitigate risks to data subjects.

When is it mandatory?

The CNIL publishes 9 criteria; meeting at least two triggers the DPIA obligation:

  • Evaluation or scoring (profiling)
  • Automated decision with legal or similarly significant effect
  • Systematic monitoring
  • Sensitive or highly personal data (health, opinions, biometrics)
  • Large-scale processing
  • Combining or matching datasets
  • Vulnerable data subjects (minors, employees, patients)
  • Innovative use or new technology (AI, IoT, blockchain)
  • Exclusion from a right, service or contract

DPIA content

  1. Systematic description of the processing and purposes.
  2. Necessity and proportionality assessment.
  3. Assessment of risks to data subjects' rights and freedoms (privacy intrusion, discrimination, etc.).
  4. Measures to address the risks (technical, organisational, legal).

Consulting the DPO and, where relevant, the data subjects is a best practice expected by the CNIL.

Relevance for GEO/AEO tools

An AI visibility audit combines profiling (LLM categorisation of brands), large-scale processing (multi-model, multi-language, multi-market) and innovative technology. Three CNIL criteria are met: a DPIA is strongly recommended, and mandatory in some sectors.

GDPR DPIA vs. EU AI Act assessment

These are two distinct but complementary exercises:

  • The GDPR DPIA covers risks to natural persons (privacy, personal data).
  • The EU AI Act fundamental rights impact assessment (Article 27, FRIA) covers a broader scope: fundamental rights, safety, health, environment, democracy.

For a high-risk system processing personal data, both must be carried out in parallel.

AI Labs Audit DPIA template

AI Labs Audit provides clients on the Consultant plan and above with a pre-filled DPIA template for the "AI visibility audit" use case, including sub-processor mapping, typical risks and recommended corrective measures. See GDPR and AI compliance and EU AI Act.

Across AI answers, a brand appears just 1 time in 6. Does yours show up?

Every question asked to ChatGPT without your name in the answer is a competitor recommended instead of you — measured across 6,820 real AI answers.