Hael
Book a meeting
GDPR for AI · DPIA

GDPR for AI - DPIA Consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • A DPIA is legally required before processing likely to result in high risk begins. Most AI affecting individuals meets that threshold.
  • It must be done before processing starts, not afterwards, and revisited when processing changes materially.
  • Where residual high risk remains after mitigation, you must consult your supervisory authority before proceeding.
  • Most AI DPIAs fail on the same point: they describe processing generically and never engage with the model itself.
  • Outsourced AI DPIAs typically cost £4,000 to £15,000 per system and take two to four weeks.

When it is required

A data protection impact assessment is the one document in this area that is legally mandatory rather than good practice. Article 35 requires one where processing is likely to result in a high risk to people's rights and freedoms, and specifically names systematic and extensive automated evaluation, including profiling, on which decisions with legal or similarly significant effects are based.

For AI that makes or supports decisions about individuals, the answer is almost always that one is required. Where you conclude otherwise, record the reasoning, because the absence of a DPIA is itself something a supervisory authority examines.

Supervisory authorities publish lists of processing requiring a DPIA. Across them, the triggers most relevant to AI are consistent.

Systematic and extensive evaluation of personal aspects, including profiling, with significant effects. Large-scale processing of special category data. Systematic monitoring of publicly accessible areas. Innovative use of new technology. Processing that prevents people from exercising a right or accessing a service. Data concerning vulnerable people, including employees and children.

Most production AI touching individuals hits at least two.

The timing rule

The DPIA has to be carried out before processing begins.

This is the requirement most often missed, and it is not a formality. The purpose is to identify risk while the design can still change. A DPIA written after deployment can only document what already happened, and it is visibly retrospective to anyone reading it.

It must also be revisited when the processing changes materially. For AI that means retraining on new data, changing purpose, expanding to new populations, or altering the human review arrangement.

What an AI DPIA must contain

ElementWhat it means for an AI system
Systematic descriptionWhat the system does, what data it uses, where that data came from, who is affected, and how the output is used
Purpose and lawful basisThe purposes separated, with the basis for each and the legitimate interests assessment where relevant
Necessity and proportionalityWhether the AI is necessary for the purpose, and whether a less intrusive approach would achieve it
Risks to individualsConcrete risks: wrong decisions, discriminatory outcomes, loss of control over data, inability to contest, re-identification
MeasuresSafeguards that address each risk, with a judgement on residual risk
ConsultationViews of affected people or their representatives where appropriate, and of your DPO

Why most AI DPIAs are inadequate

The failure is consistent. The document describes the processing in general terms, lists risks from a standard library, proposes standard measures, and never engages with the model.

A DPIA that would survive scrutiny answers questions like these. Where did the training data come from and what did the people concerned expect. What is the error rate and how does it differ across groups. What happens to a person when the system is wrong, and how do they find out. Who reviews the output, how much time do they have, and can they overrule it without permission. What does the de-identification actually achieve against re-identification. If someone objects, what happens in the pipeline.

Those questions require someone who understands both the law and the system. A DPIA written by a privacy specialist with no technical input, or by an engineer with no legal framing, tends to fail on one side or the other.

The consultation obligation

Where the DPIA identifies a high residual risk that you cannot mitigate, Article 36 requires you to consult your supervisory authority before proceeding.

Organisations avoid this by concluding that residual risk is acceptable. Sometimes that conclusion is correct. Where it is not, the failure to consult compounds the original problem, because it is straightforward for an authority to demonstrate after the fact.

An honest DPIA sometimes produces an uncomfortable answer. That is what it is for.

Who can write it

There is no restriction. A DPIA can be written internally, by your DPO, or by an external firm.

The controller remains responsible for it whoever writes it, and the DPO must be consulted where one is appointed. The DPO's advice, and any decision to depart from it, should be recorded.

In practice organisations outsource AI DPIAs for two reasons: the combination of legal and technical understanding is scarce internally, and an external assessment is harder to quietly soften when the answer is inconvenient.

Cost and timing

ItemTypical range
AI DPIA, per system£4,000 to £15,000
Duration2 to 4 weeks per system
Review when processing changes materially£1,500 to £5,000
Combined with an EU AI Act fundamental rights impact assessmentUsually cheaper than doing both separately

That last point matters. Where a system is high risk under the EU AI Act and a deployer must complete a fundamental rights impact assessment, it shares substantial content with the DPIA. Doing them together is materially cheaper than sequentially. See our EU AI Act service page.

Our approach

We write AI DPIAs that engage with the system rather than describing it generically, and we bring technical input rather than assessing the model from the outside. Where the honest conclusion is that residual risk is high, we say so and set out the consultation position rather than adjusting the language.

That is part of our readiness and gap assessment and implementation services.

What to do next

List your AI systems and mark which ones make or support decisions about people. Those need a DPIA, and if processing has already started, they need one now rather than later.

Our free AI impact assessment gives an immediate first view, and the GDPR for AI service page sets out how we run the work.

References

FAQ

Is a DPIA mandatory for AI?

Where processing is likely to result in high risk, yes, and most AI making or supporting decisions about people meets that threshold.

When must it be done?

Before processing begins, and revisited when processing changes materially.

Who can write a DPIA?

Anyone. The controller remains responsible, and the DPO must be consulted where one is appointed.

What if residual risk is still high?

Article 36 requires you to consult your supervisory authority before proceeding.

What does an AI DPIA cost?

Typically £4,000 to £15,000 per system, taking two to four weeks, and cheaper when combined with an EU AI Act fundamental rights impact assessment.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. We write AI data protection impact assessments that engage with the system rather than describing it generically, and we state uncomfortable conclusions where the assessment produces them. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on GDPR for AI, free.

Answer a short set of questions and see what GDPR for AI expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether GDPR for AI applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to GDPR for AI.

Or speak to us about your deadline. Book a meeting.