Sometimes. Under the GDPR you need a DPIA before processing that's likely to result in high risk to people, and AI counts as the kind of new technology that makes that likelier. Drafting marketing copy in a business AI account rarely needs one; a chatbot handling health questions, AI-assisted decisions about people, or large-scale sensitive data usually does.
A DPIA (data protection impact assessment) isn't a legal opinion or a thick report. For a small business it's a few structured pages: what you're doing and why, whether it's necessary and proportionate, what could go wrong for the people whose data is involved, and what you'll do about it. Most small-business AI uses need only a short, recorded screening check, and a smaller number need the full assessment. This tutorial is general information rather than legal advice, and it flags where an adviser should be involved.
What the GDPR actually requires
Article 35 is the source. Its first paragraph says that where processing, "in particular using new technologies", is likely to result in a high risk to people's rights and freedoms, the controller must assess its impact before starting. It then names three cases where a DPIA is always required:
- a systematic and extensive evaluation of people based on automated processing, including profiling, that leads to decisions with legal or similarly significant effects on them;
- processing special categories of data, such as health data, or criminal-offence data, on a large scale;
- systematic monitoring of a publicly accessible area on a large scale.
The same article sets out what a DPIA must contain: a description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to the people concerned, and the measures to address them. You must seek your data protection officer's advice if you have one, seek the views of the people affected where appropriate, and review the assessment when the risk changes. Data-protection authorities also publish their own lists of processing that always needs a DPIA, so check the list that applies where you operate. If an assessment shows a high risk you can't reduce, Article 36 requires you to consult your authority before going ahead.
The nine warning signs, and the two-sign rule of thumb
The DPIA guidelines endorsed at EU level (known as WP248) turn "likely to result in high risk" into nine criteria. They say that in most cases processing meeting two criteria needs a DPIA, and that sometimes one is enough. Here's each criterion with an AI example from a small business:
| Criterion | What it could look like with AI |
|---|---|
| Evaluation or scoring | AI ranking customers by likelihood to buy, or scoring job applicants |
| Automated decisions with legal or similar effect | AI deciding who gets a refund, an appointment slot or a job interview |
| Systematic monitoring | AI analysing staff emails or call recordings for performance |
| Sensitive or highly personal data | Health details in clinical notes, audiology results, prescriptions |
| Large-scale processing | Running a whole customer database through an AI tool |
| Matching or combining datasets | Joining booking history with website behaviour to target offers |
| Vulnerable people | Patients, children, or employees who can't easily object |
| Innovative use of new technology | Most generative AI uses, especially new ones |
| Processing that blocks a right or service | AI deciding someone can't book or can't receive a service |
Notice that "innovative technology" will be ticked for almost any generative AI use. That makes the second tick the one that matters: health data, vulnerable people, scoring, monitoring or scale alongside a new AI tool is the classic DPIA combination. If you decide a use meeting two criteria doesn't need a DPIA, the guidelines expect you to write down why.
Screening six AI uses in ten minutes each
Screening means asking the questions above and recording the answer, whichever way it falls. Here's how six uses at the kinds of business this series follows would screen (illustrative):
| Use | Criteria met | Outcome |
|---|---|---|
| Electrician drafting quotes in ChatGPT Business, customer names only | New technology | No DPIA; screening note filed |
| Plumbing firm summarising recorded customer calls with AI | New technology, systematic monitoring of calls | Short DPIA; tell callers about recording and AI |
| Pharmacy WhatsApp bot for opening hours and stock questions | New technology; customers may volunteer health details | Mini DPIA, with a strict never-answer list |
| Osteopathy clinic using an AI note-taker in treatment sessions | New technology, health data, vulnerable people | Full DPIA; adviser review |
| Hearing-aid shop using AI to pick customers for upgrade offers | Scoring, health data, combining datasets, new technology | Full DPIA; rethink using audiology data for marketing at all |
| Podiatry clinic using AI to shortlist job applicants | Scoring, possible automated decisions, new technology | Full DPIA, adviser input, and Article 22 safeguards |
The last row carries extra weight. The EU AI Act lists AI used in recruitment as high-risk in Annex III; most obligations for those stand-alone systems are deferred to 2 December 2027, but the GDPR duties apply now. The osteopathy row shows why tool choice belongs inside the DPIA: note-takers differ a great deal. Heidi says it doesn't keep audio; Nabla discards audio and keeps transcripts for 14 days by default; and SimplePractice's Note Taker has, since 16 June 2026, opted new users in by default to keeping de-identified transcripts. For a closer look at these tools, see whether AI meeting note-takers are safe for client calls.
A screening note for the first row, where no DPIA is needed, can be four lines long. The electrician's reads:
Use: drafting quotes and follow-up emails in ChatGPT Business. Personal data: customer names and job addresses only; no health, financial or ID data. Criteria met: new technology only. Decision: no DPIA, because the risk to customers is low; covered by the vendor DPA, training off by default. Review if we start pasting in anything beyond names and addresses. Signed and dated by the owner.
That note is worth having. If anyone ever asks how you assessed the use, "we screened it, here's the record" is a far better answer than "we didn't think about it".
A mini DPIA, filled in for a podiatry clinic's website chatbot
Here's a complete small-business DPIA for a common AI use. The clinic is illustrative; the structure follows what Article 35 requires. It runs to about two pages when printed.
1. Description of the processing
Purpose: answer common questions on the clinic's website (prices, opening hours, what to bring, how to book) outside reception hours, and collect callback requests. Tool: a no-code chatbot builder on a paid plan, trained only on the clinic's FAQ, price list and booking page. Data: anything visitors type, plus the name and phone number of those who ask for a callback. Volume: about 150 conversations a month. People affected: prospective and existing patients, some of them elderly or in pain. Retention: transcripts auto-deleted after 90 days; callback details moved into the patient system and deleted from the chatbot within 7 days.
2. Necessity and proportionality
The bot replaces an out-of-hours voicemail that many callers didn't use. It needs no personal data to answer FAQs; the only personal data it asks for is a name and phone number, and only when the visitor wants a callback. Lawful basis: legitimate interests for answering enquiries, with a documented balancing test, and steps to deter health information, which the bot doesn't need. Visitors are told at the start that they're chatting with an automated assistant, as Article 50 of the EU AI Act requires for customers in the EU.
3. Risks to the people involved
| Risk | Likelihood | Severity | Before measures |
|---|---|---|---|
| R1. Visitors type health details, which the vendor then holds | Likely | Moderate | Medium |
| R2. The bot gives something that reads as clinical advice | Possible | Significant | Medium |
| R3. Wrong prices or booking information | Possible | Minor | Low |
| R4. A breach at the chatbot vendor | Remote | Moderate | Low |
| R5. Visitors don't realise they're talking to AI | Possible | Minor | Low |
| R6. Data processed outside the EU without safeguards | Possible | Moderate | Medium |
4. Measures and residual risk
| Risk | Measures | Residual |
|---|---|---|
| R1 | Opening message asks visitors not to share medical details; the bot never asks about symptoms; 90-day transcript deletion; vendor DPA signed; transcript access limited to the practice manager | Low |
| R2 | Never-answer list for symptoms, treatment and medicines; fixed handover wording; 30-question test before launch; weekly transcript review for the first two months | Low |
| R3 | Bot trained only on the current price list; monthly source check; prices restated as "from" with a booking link | Low |
| R4 | Vendor's security documentation reviewed; multi-factor sign-in on the admin account; minimal data collected | Low |
| R5 | Disclosure in the first message; "type PERSON" always offered | Low |
| R6 | Vendor DPA includes standard contractual clauses; privacy notice updated | Low |
5. Outcome and sign-off
Residual risk is low across the board, so there's no need to consult the data-protection authority. Approved by the clinic owner; reviewed by the clinic's data-protection adviser because health data may be volunteered. Review: in six months, or sooner if the vendor changes its terms or model, the bot is connected to the booking system, or an incident occurs.
That last line is what keeps a DPIA honest. If the clinic later lets the bot see real appointment slots, the processing has changed and the assessment needs revisiting. Before launch, the testing in measure R2 follows the routine in how to test a customer chatbot before it goes live.
How to write one in about two hours
- Describe it in plain words (20 minutes). What the tool does, what data goes in, who's affected, how long it's kept. If you can't describe the data flow, you're not ready to assess it.
- Read the vendor's terms (30 minutes). DPA, training default, retention, sub-processors, where data is processed. The GDPR steps for AI tools lists what to look for.
- List what could go wrong for the people involved (20 minutes). Think about them, not your business: exposure of sensitive details, wrong information, loss of control, unfair decisions.
- Match a measure to every risk (30 minutes). Prefer measures that remove data or add a human check over ones that rely on people remembering a rule.
- Decide and sign (10 minutes). Residual risk, sign-off, review date.
- Ask for views where appropriate (10 minutes to arrange). A couple of patients or staff reading the plain description often spot something you haven't.
Keep it with your other records, and add each AI use to your wider AI risk register so the review dates don't get lost.
Three ways small-business DPIAs miss the point
- Assessing the tool instead of the use. A DPIA titled "ChatGPT" that concludes "approved" invites someone to use it for patient letters six months later. Assess each use: "drafting booking replies" and "summarising clinical notes" are different processing with different risks, even in the same tool.
- Copying generic risks. A downloaded template full of "cyber attack" and "system outage" misses what actually matters to the people involved: a patient's symptoms sitting in a vendor's logs, or a wrong answer they act on. Write the risks from the patient's or customer's point of view.
- Ignoring the version staff really use. A careful DPIA of the business plan is undermined if a receptionist uses a personal free account on busy days. Check what people actually use before you assess, and include a measure that closes the gap, such as company accounts and a clear rule.
When a DPIA goes stale
A DPIA describes a use at a point in time, and AI tools change underneath you. The SimplePractice example above is a real one: a vendor changed a privacy default for new users in June 2026. A clinic whose DPIA assumed "transcripts are not retained" would have been relying on an assessment that no longer matched the tool for anyone who signed up after that date.
Build four review triggers into every AI DPIA: the vendor changes its terms, defaults or underlying model; you connect the tool to a new system or data source; you start using it for a new purpose; or something goes wrong. Article 35 requires a review at least when the risk changes, and a calendar reminder every six months catches the changes nobody announced.
Where the EU AI Act fits alongside a DPIA
The EU AI Act doesn't replace the GDPR's DPIA; it sits alongside it. For a small business deploying everyday AI tools, three parts matter now: the transparency duties in Article 50, which have applied since 2 August 2026 and cover telling people they're dealing with a chatbot; the ban since 2 February 2025 on AI that infers employees' emotions at work, including in recruitment; and the list of high-risk uses in Annex III, such as recruitment and creditworthiness, whose main obligations for stand-alone systems are deferred to 2 December 2027. If a use appears on that high-risk list, treat the DPIA as mandatory in practice and involve an adviser early.
When to hand it to an adviser
You can screen uses and write a mini DPIA like the one above yourself. Bring in a data-protection adviser when the use involves health or other special-category data beyond incidental mentions, as with clinical note-takers; children's data; monitoring of staff or the public; decisions about people that are made wholly by AI with significant effects, which Article 22 restricts; any use on the EU AI Act's high-risk list; or a residual risk you can't get down to low. For patient-facing businesses in particular, the patient data and AI confidentiality checklist covers the professional duties that sit alongside data protection.
The underlying habit is simple: before a new AI use goes live, spend ten minutes asking whether it could hurt the people whose data it touches, write the answer down, and do the full assessment when the answer isn't a clear no.
DPIAs for AI: follow-up questions
Can I use a vendor's own risk assessment instead of writing a DPIA?
Use it as input, not a replacement. Some vendors publish material to help, such as Microsoft's risk assessment quickstart for Copilot and Copilot Chat, and their DPAs and security documents answer the supplier questions in your assessment. None of that can judge your particular use: whose data, for what purpose, with what safeguards. That part of the DPIA has to come from you.
Who should sign off a DPIA in a small business?
The controller, which in practice means the owner or a director, because the GDPR puts the duty on the business. If you've appointed a data protection officer, the law requires you to seek their advice while doing the assessment. For uses involving health data or other high-risk processing, having a data-protection adviser review the finished DPIA is sensible.
Do I have to publish my DPIA?
No. Publishing a DPIA isn't a legal requirement of the GDPR; it's at the controller's discretion. Some businesses publish a short summary to build trust with customers. You should keep the full version on file, review it when things change, and be able to produce it if your data-protection authority asks how you assessed the risk.
What if the DPIA shows a high risk I can't reduce?
Then you shouldn't simply go ahead. Under Article 36 of the GDPR, if an assessment shows high risk that your measures can't bring down, you must consult your data-protection authority before starting the processing. In practice most small businesses redesign the use instead: less data, a different tool, human review, or dropping the riskiest part.
Further reads
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — What the big four AI vendors offer on DPAs, training and residency.
- What to Check in an AI Tool's Privacy Policy and Terms — Reading a vendor's terms to fill in the supplier section of a DPIA.
- AI Literacy Requirements: What Your Staff Need to Know — The staff training that many DPIA measures depend on.
- How to Anonymise Client Data Before You Paste It Into AI — Reducing risk by taking identifying details out before AI sees them.
- Can You Build an AI Chatbot for Your Business Without Coding? — Building the kind of chatbot the example DPIA assesses.
- Is It Safe to Let AI Reply to Customers on WhatsApp? — The same risks when the chatbot works on WhatsApp.
- How to Classify Business Data Before Using AI Tools — A four-tier scheme a small team can apply in an afternoon, with the AI rule for each tier and a fitness studio classified line by line.
- What to Ask Before Buying Any AI Tool for a Medical Practice — A grouped checklist of questions for any AI vendor selling to a medical practice, what a good answer looks like, a scored example and the red-flag answers.
- A Worked AI Implementation Plan for a Small Medical Practice — One small medical practice's 12-week AI plan, from time audit to scribe rollout and phone overflow, with the costs, the numbers at day 90 and the lessons.
- Telling Patients You Use AI Note-Taking: Consent Wording That Works — Ready-to-adapt wording for telling patients about AI note-taking, from the booking text to the in-room question and the information page.
- Dental Practice AI Mistakes: Consent, Data, and Over-Automation — Ten AI mistakes dental practices make with consent, patient data and over-automation, with examples of how each shows up and the fix.
- Is It Safe to Use AI With Children's Data in a Nursery? — When a nursery can safely use AI with children's information, what must never go in, and the checks, parent wording and risk review to do first.
- Where Is Your Data Stored When You Use AI Tools? — Chats, files and safety logs live in the vendor's cloud. How storage and processing regions work plan by plan, and how to check your own account.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: the GDPR (Articles 9, 22, 35 and 36); the DPIA guidelines endorsed at EU level (WP248 rev.01); the EU AI Act (Article 50 and the deferral of high-risk obligations); vendor pages on note-taker data handling (checked September 2026). General information, not legal advice.