A DPIA (Data Protection Impact Assessment) is a mandatory impact study required by Article 35 GDPR. It applies to any processing likely to result in a high risk to the rights and freedoms of natural persons, especially large-scale processing and processing involving AI.
Definition and legal basis
A DPIA is required by Article 35 GDPR. It is a prior analysis, to be carried out before implementing a processing operation, in order to identify and mitigate risks to data subjects.
When is it mandatory?
The CNIL publishes 9 criteria; meeting at least two triggers the DPIA obligation:
- Evaluation or scoring (profiling)
- Automated decision with legal or similarly significant effect
- Systematic monitoring
- Sensitive or highly personal data (health, opinions, biometrics)
- Large-scale processing
- Combining or matching datasets
- Vulnerable data subjects (minors, employees, patients)
- Innovative use or new technology (AI, IoT, blockchain)
- Exclusion from a right, service or contract
DPIA content
- Systematic description of the processing and purposes.
- Necessity and proportionality assessment.
- Assessment of risks to data subjects' rights and freedoms (privacy intrusion, discrimination, etc.).
- Measures to address the risks (technical, organisational, legal).
Consulting the DPO and, where relevant, the data subjects is a best practice expected by the CNIL.
Relevance for GEO/AEO tools
An AI visibility audit combines profiling (LLM categorisation of brands), large-scale processing (multi-model, multi-language, multi-market) and innovative technology. Three CNIL criteria are met: a DPIA is strongly recommended, and mandatory in some sectors.
GDPR DPIA vs. EU AI Act assessment
These are two distinct but complementary exercises:
- The GDPR DPIA covers risks to natural persons (privacy, personal data).
- The EU AI Act fundamental rights impact assessment (Article 27, FRIA) covers a broader scope: fundamental rights, safety, health, environment, democracy.
For a high-risk system processing personal data, both must be carried out in parallel.
AI Labs Audit DPIA template
AI Labs Audit provides clients on the Consultant plan and above with a pre-filled DPIA template for the "AI visibility audit" use case, including sub-processor mapping, typical risks and recommended corrective measures. See GDPR and AI compliance and EU AI Act.
Every question asked to ChatGPT without your name in the answer is a competitor recommended instead of you — measured across 6,820 real AI answers.