Gains:
- Evaluating whether an AI use requires DPIA
- Applying the seven-step DPIA process to an AI project
- Prioritize risks with a probability-impact matrix and design mitigating measures
Some uses of AI pose serious risks to individuals: large-scale monitoring, sensitive data processing, automated decisions. In such projects, both the KVKK/GDPR and the EU AI Law expect a structured risk assessment before work begins. The name of this assessment is Data Protection Impact Assessment (DPIA). In this unit we will learn how to tell if a use requires DPIA, how to apply the seven-step DPIA process to an AI project, and how to prioritize risks with a probability-impact matrix.
What is DPIA and when is it needed?
Data Protection Impact Assessment (DPIA) is a structured analysis that evaluates in advance the risks of a processing activity on the rights and freedoms of individuals and determines mitigating measures. The critical point: DPIA is done at the design stage, before processing begins — not after the problem occurs.
DPIA is usually required when:
- Use of new technology (AI is often included).
- Large-scale processing of personal data.
- Systematic monitoring or profiling.
- Special data processing.
- Automated decisions that significantly impact people.
Tip: If you're not sure, do a "screening": if two or more of the five above are present, default to doing DPIA. The cost of doing DPIA is low; The cost of not doing so is very high in one violation.
Seven-step DPIA process
You apply DPIA to an AI project in these seven steps:
step
What do you do?
1. Description
Describe the processing: what data, purpose, scope, flow
2. Necessity and proportionality
Is AI really necessary? Is there a less intrusive way?
3. Stakeholder opinion
Obtain the opinion of relevant persons/representatives
4. Risk identification
List possible harms to individuals
5. Risk assessment
Score each risk by probability and impact
6. Mitigation measures
Design precautions for each risk, identify residual risk
7. Approval and review
Document the result, submit it for approval, update it periodically
Prioritizing risk: probability-impact matrix
You evaluate each risk in two dimensions: the likelihood of it happening and the impact if it does happen. The combination of the two gives priority.
<w:tcPr><w:tcW w:type="dxa" w:w="2160"/></w:tcPr><w:p><w:r><w:rPr><w:b/></w:rPr><w:t>Low impact
medium effect
high impact
high probability
medium
high
critical
medium probability
low
medium
high
low probability
low
low
medium
Critical and high risks are risks for which the project should not be continued without taking precautions. The aim is not to eliminate every risk; is to reduce each risk to an acceptable level and consciously accept the remaining (residual) risk.
three mini cases
Case 1 — Omitted DPIA. A retail chain implements a system that tracks customer behavior in-store with AI, without DPIA. Months later, a complaint reveals that the system made specific inferences (health, pregnancy prediction). There is no answer to the question "why didn't you do DPIA" in the audit. A DPIA from the beginning would have caught this risk at the design stage and made the project safe.
Case 2 — Project rescued by DPIA. DPIA is done for recruitment support AI in a bank. During the risk identification phase, the risk of gender bias due to historical data turns out to be "high". As a mitigation, the team removes gender information from the model, attributes the output to regular bias testing, and requires human validation. Now the risk drops to "moderate" and the project becomes acceptable. DPIA makes the project safe instead of killing it.
Case 3 — Proportionality test. A company wants to scan employee emails for “loyalty analysis” with AI. In the necessity/proportionality step of the DPIA this is found to be overly intrusive relative to the purpose; There are less intrusive alternatives. The project is not approved in its current form. The proportionality test distinguishes between “we can” and “we must.”
Attention: DPIA is not a form that is filled out once and put aside. When processing changes (new data, new purpose, new tool) the DPIA must be updated. A dead DPIA is more misleading than no DPIA at all because it gives false confidence.
Who does the DPIA and risk register relationship with DPIA
A single person cannot fill out the DPIA at their desk; Correct DPIA is a team effort. Typically, the data protection officer carries out the process (Doer), the compliance manager is ultimately responsible (Accountable), the relevant business unit describes the processing, evaluates IT/security technical measures and confirms the legal basis. Obtaining the opinions of relevant people (third step) should not be neglected; However, this is the step most skipped in practice.
The output of DPIA does not sit in a vacuum: identified risks are recorded in the organisation's risk register. The risk register is a live chart that captures all open risks, their priorities, mitigations, culprits and last review dates. This way, the risks of an AI project speak the same language as the organization's overall risk management and are monitored regularly.
Risk register area
example
Risk definition
Gender bias in recruitment AI
priority
high
Mitigation measure
Surrogate variable extraction + bias testing
Responsible
Data protection officer
review
every 3 months
Tip: Treat DPIA with a “risk log and track” mentality, not a “done and forget” approach. Has a risk mitigation been implemented, is the residual risk at an acceptable level — without a record keeping track of these, the DPIA becomes a window document.
Copiable templates
TEMPLATE 1 — DPIA pre-screening: "Is DPIA required for this AI use? [describe the use]. Evaluate against five triggers: new technology, large-scale processing, systematic monitoring, sensitive data, significant automated decision-making. How many triggers are there, do you recommend DPIA, with justification."
TEMPLATE 2 — Risk identification brainstorming: "List the possible harms to people in this AI project [describe the project]: data leak, discrimination, misjudgment, invasion of privacy, lack of transparency, purpose drift. Write a one-sentence scenario for each harm. Just detect, yet do not counteract."
TEMPLATE 3 — Likelihood-impact scoring: "Score the following risks [list risks] as probability (low/medium/high) and impact (low/medium/high); priority (low/medium/high/critical) appears on each row. List critical and high at the top. Present in table format."
TEMPLATE 4 — Mitigation design: "For the following risk [write the risk], propose at least 3 mitigation measures (technical, process, organizational). Estimate the 'residual risk' level after each measure. If the risk is still high after the measure, indicate that the project should be redesigned."
Weak prompt / Strong prompt
WEAK: “Is this AI project risky?”-> The model gives a vague ‘maybe’ answer; does not classify risks, does not prioritize risks, does not produce measures.STRONG: "Conduct a mini DPIA for the following AI project: (1) describe the processing,(2) evaluate the need for DPIA with 5 triggers, (3) list6 possible harms to persons, (4) score each by probability-impact,(5) recommend mitigation for critical/high risks. Make definitive legal decision-making; produce a draft that will go to legal approval."-> The model produces a draft of a structured, actionable DPIA.
Common mistakes
- Doing the DPIA after the transaction has started (or even after the problem has occurred).
- Skipping high-risk processing requiring DPIA as “no big deal.”
- Not listing risks and prioritizing them by probability and impact.
- Considering DPIA "complete" without producing measures for every risk.
- Skipping the necessity/proportionality step and saying "we can do it, so let's do it".
- Filling out the DPIA once and not updating it when the process changes.
- Approving the project without clearly documenting the residual (remaining) risk.
In summary
- DPIA is a structured analysis that evaluates the impact of a high-risk processing on individuals before it is initiated.
- DPIA is required if there is new technology, large-scale processing, systematic monitoring, sensitive data or significant automated decision-making.
- The process consists of seven steps: identification, necessity/proportionality, stakeholder opinion, risk identification, assessment, action, approval/review.
- Risks are prioritized with a probability-impact matrix; Critical/high risks are not accepted without precautions.
- DPIA does not kill the project, it makes it safe; It is a living document that must be updated as processing changes.
Application task
Choose a use of AI your organization might use that may be high-risk (for example, recruiting support, behavioral tracking, or credit scoring). First consider whether DPIA is necessary with five triggers. Then conduct a mini DPIA for this use: describe the processing, list at least six possible harms to individuals, score each on the likelihood-impact matrix, and assign priority. Design three mitigation measures for two critical and high risks and estimate the residual risk level after the measure. Finally, note when this DPIA will need to be updated.
checklist
- [ ] I evaluated the DPIA requirement with five triggers.
- [ ] I defined the processing (data, purpose, scope, flow).
- [ ] I questioned necessity and proportionality.
- [ ] I have listed the possible harms to individuals.
- [ ] I prioritized the risks in the probability-impact matrix.
- [ ] I designed mitigation measures for critical/high risks.
- [ ] I have now documented the risk and set the review conditions.