Do You Need a DPIA Before Using AI Tools?

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Do You Need a DPIA Before Using AI Tools?
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Do You Need a DPIA Before Using AI Tools?

Sometimes. Under the GDPR you need a DPIA before processing that's likely to result in high risk to people, and AI counts as the kind of new technology that makes that likelier. Drafting marketing copy in a business AI account rarely needs one; a chatbot handling health questions, AI-assisted decisions about people, or large-scale sensitive data usually does.

A DPIA (data protection impact assessment) isn't a legal opinion or a thick report. For a small business it's a few structured pages: what you're doing and why, whether it's necessary and proportionate, what could go wrong for the people whose data is involved, and what you'll do about it. Most small-business AI uses need only a short, recorded screening check, and a smaller number need the full assessment. This tutorial is general information rather than legal advice, and it flags where an adviser should be involved.

Follow me on Instagram@sagnikteaches

What the GDPR actually requires

Article 35 is the source. Its first paragraph says that where processing, "in particular using new technologies", is likely to result in a high risk to people's rights and freedoms, the controller must assess its impact before starting. It then names three cases where a DPIA is always required:

Connect on LinkedInSagnik Bhattacharya
  1. a systematic and extensive evaluation of people based on automated processing, including profiling, that leads to decisions with legal or similarly significant effects on them;
  2. processing special categories of data, such as health data, or criminal-offence data, on a large scale;
  3. systematic monitoring of a publicly accessible area on a large scale.

The same article sets out what a DPIA must contain: a description of the processing and its purposes, an assessment of necessity and proportionality, an assessment of the risks to the people concerned, and the measures to address them. You must seek your data protection officer's advice if you have one, seek the views of the people affected where appropriate, and review the assessment when the risk changes. Data-protection authorities also publish their own lists of processing that always needs a DPIA, so check the list that applies where you operate. If an assessment shows a high risk you can't reduce, Article 36 requires you to consult your authority before going ahead.

Subscribe on YouTube@codingliquids

The nine warning signs, and the two-sign rule of thumb

The DPIA guidelines endorsed at EU level (known as WP248) turn "likely to result in high risk" into nine criteria. They say that in most cases processing meeting two criteria needs a DPIA, and that sometimes one is enough. Here's each criterion with an AI example from a small business:

CriterionWhat it could look like with AI
Evaluation or scoringAI ranking customers by likelihood to buy, or scoring job applicants
Automated decisions with legal or similar effectAI deciding who gets a refund, an appointment slot or a job interview
Systematic monitoringAI analysing staff emails or call recordings for performance
Sensitive or highly personal dataHealth details in clinical notes, audiology results, prescriptions
Large-scale processingRunning a whole customer database through an AI tool
Matching or combining datasetsJoining booking history with website behaviour to target offers
Vulnerable peoplePatients, children, or employees who can't easily object
Innovative use of new technologyMost generative AI uses, especially new ones
Processing that blocks a right or serviceAI deciding someone can't book or can't receive a service

Notice that "innovative technology" will be ticked for almost any generative AI use. That makes the second tick the one that matters: health data, vulnerable people, scoring, monitoring or scale alongside a new AI tool is the classic DPIA combination. If you decide a use meeting two criteria doesn't need a DPIA, the guidelines expect you to write down why.

Screening six AI uses in ten minutes each

Screening means asking the questions above and recording the answer, whichever way it falls. Here's how six uses at the kinds of business this series follows would screen (illustrative):

UseCriteria metOutcome
Electrician drafting quotes in ChatGPT Business, customer names onlyNew technologyNo DPIA; screening note filed
Plumbing firm summarising recorded customer calls with AINew technology, systematic monitoring of callsShort DPIA; tell callers about recording and AI
Pharmacy WhatsApp bot for opening hours and stock questionsNew technology; customers may volunteer health detailsMini DPIA, with a strict never-answer list
Osteopathy clinic using an AI note-taker in treatment sessionsNew technology, health data, vulnerable peopleFull DPIA; adviser review
Hearing-aid shop using AI to pick customers for upgrade offersScoring, health data, combining datasets, new technologyFull DPIA; rethink using audiology data for marketing at all
Podiatry clinic using AI to shortlist job applicantsScoring, possible automated decisions, new technologyFull DPIA, adviser input, and Article 22 safeguards

The last row carries extra weight. The EU AI Act lists AI used in recruitment as high-risk in Annex III; most obligations for those stand-alone systems are deferred to 2 December 2027, but the GDPR duties apply now. The osteopathy row shows why tool choice belongs inside the DPIA: note-takers differ a great deal. Heidi says it doesn't keep audio; Nabla discards audio and keeps transcripts for 14 days by default; and SimplePractice's Note Taker has, since 16 June 2026, opted new users in by default to keeping de-identified transcripts. For a closer look at these tools, see whether AI meeting note-takers are safe for client calls.

A screening note for the first row, where no DPIA is needed, can be four lines long. The electrician's reads:

Use: drafting quotes and follow-up emails in ChatGPT Business. Personal data: customer names and job addresses only; no health, financial or ID data. Criteria met: new technology only. Decision: no DPIA, because the risk to customers is low; covered by the vendor DPA, training off by default. Review if we start pasting in anything beyond names and addresses. Signed and dated by the owner.

That note is worth having. If anyone ever asks how you assessed the use, "we screened it, here's the record" is a far better answer than "we didn't think about it".

A mini DPIA, filled in for a podiatry clinic's website chatbot

Here's a complete small-business DPIA for a common AI use. The clinic is illustrative; the structure follows what Article 35 requires. It runs to about two pages when printed.

1. Description of the processing

Purpose: answer common questions on the clinic's website (prices, opening hours, what to bring, how to book) outside reception hours, and collect callback requests. Tool: a no-code chatbot builder on a paid plan, trained only on the clinic's FAQ, price list and booking page. Data: anything visitors type, plus the name and phone number of those who ask for a callback. Volume: about 150 conversations a month. People affected: prospective and existing patients, some of them elderly or in pain. Retention: transcripts auto-deleted after 90 days; callback details moved into the patient system and deleted from the chatbot within 7 days.

2. Necessity and proportionality

The bot replaces an out-of-hours voicemail that many callers didn't use. It needs no personal data to answer FAQs; the only personal data it asks for is a name and phone number, and only when the visitor wants a callback. Lawful basis: legitimate interests for answering enquiries, with a documented balancing test, and steps to deter health information, which the bot doesn't need. Visitors are told at the start that they're chatting with an automated assistant, as Article 50 of the EU AI Act requires for customers in the EU.

3. Risks to the people involved

RiskLikelihoodSeverityBefore measures
R1. Visitors type health details, which the vendor then holdsLikelyModerateMedium
R2. The bot gives something that reads as clinical advicePossibleSignificantMedium
R3. Wrong prices or booking informationPossibleMinorLow
R4. A breach at the chatbot vendorRemoteModerateLow
R5. Visitors don't realise they're talking to AIPossibleMinorLow
R6. Data processed outside the EU without safeguardsPossibleModerateMedium

4. Measures and residual risk

RiskMeasuresResidual
R1Opening message asks visitors not to share medical details; the bot never asks about symptoms; 90-day transcript deletion; vendor DPA signed; transcript access limited to the practice managerLow
R2Never-answer list for symptoms, treatment and medicines; fixed handover wording; 30-question test before launch; weekly transcript review for the first two monthsLow
R3Bot trained only on the current price list; monthly source check; prices restated as "from" with a booking linkLow
R4Vendor's security documentation reviewed; multi-factor sign-in on the admin account; minimal data collectedLow
R5Disclosure in the first message; "type PERSON" always offeredLow
R6Vendor DPA includes standard contractual clauses; privacy notice updatedLow

5. Outcome and sign-off

Residual risk is low across the board, so there's no need to consult the data-protection authority. Approved by the clinic owner; reviewed by the clinic's data-protection adviser because health data may be volunteered. Review: in six months, or sooner if the vendor changes its terms or model, the bot is connected to the booking system, or an incident occurs.

That last line is what keeps a DPIA honest. If the clinic later lets the bot see real appointment slots, the processing has changed and the assessment needs revisiting. Before launch, the testing in measure R2 follows the routine in how to test a customer chatbot before it goes live.

How to write one in about two hours

  1. Describe it in plain words (20 minutes). What the tool does, what data goes in, who's affected, how long it's kept. If you can't describe the data flow, you're not ready to assess it.
  2. Read the vendor's terms (30 minutes). DPA, training default, retention, sub-processors, where data is processed. The GDPR steps for AI tools lists what to look for.
  3. List what could go wrong for the people involved (20 minutes). Think about them, not your business: exposure of sensitive details, wrong information, loss of control, unfair decisions.
  4. Match a measure to every risk (30 minutes). Prefer measures that remove data or add a human check over ones that rely on people remembering a rule.
  5. Decide and sign (10 minutes). Residual risk, sign-off, review date.
  6. Ask for views where appropriate (10 minutes to arrange). A couple of patients or staff reading the plain description often spot something you haven't.

Keep it with your other records, and add each AI use to your wider AI risk register so the review dates don't get lost.

Three ways small-business DPIAs miss the point

  • Assessing the tool instead of the use. A DPIA titled "ChatGPT" that concludes "approved" invites someone to use it for patient letters six months later. Assess each use: "drafting booking replies" and "summarising clinical notes" are different processing with different risks, even in the same tool.
  • Copying generic risks. A downloaded template full of "cyber attack" and "system outage" misses what actually matters to the people involved: a patient's symptoms sitting in a vendor's logs, or a wrong answer they act on. Write the risks from the patient's or customer's point of view.
  • Ignoring the version staff really use. A careful DPIA of the business plan is undermined if a receptionist uses a personal free account on busy days. Check what people actually use before you assess, and include a measure that closes the gap, such as company accounts and a clear rule.

When a DPIA goes stale

A DPIA describes a use at a point in time, and AI tools change underneath you. The SimplePractice example above is a real one: a vendor changed a privacy default for new users in June 2026. A clinic whose DPIA assumed "transcripts are not retained" would have been relying on an assessment that no longer matched the tool for anyone who signed up after that date.

Build four review triggers into every AI DPIA: the vendor changes its terms, defaults or underlying model; you connect the tool to a new system or data source; you start using it for a new purpose; or something goes wrong. Article 35 requires a review at least when the risk changes, and a calendar reminder every six months catches the changes nobody announced.

Where the EU AI Act fits alongside a DPIA

The EU AI Act doesn't replace the GDPR's DPIA; it sits alongside it. For a small business deploying everyday AI tools, three parts matter now: the transparency duties in Article 50, which have applied since 2 August 2026 and cover telling people they're dealing with a chatbot; the ban since 2 February 2025 on AI that infers employees' emotions at work, including in recruitment; and the list of high-risk uses in Annex III, such as recruitment and creditworthiness, whose main obligations for stand-alone systems are deferred to 2 December 2027. If a use appears on that high-risk list, treat the DPIA as mandatory in practice and involve an adviser early.

When to hand it to an adviser

You can screen uses and write a mini DPIA like the one above yourself. Bring in a data-protection adviser when the use involves health or other special-category data beyond incidental mentions, as with clinical note-takers; children's data; monitoring of staff or the public; decisions about people that are made wholly by AI with significant effects, which Article 22 restricts; any use on the EU AI Act's high-risk list; or a residual risk you can't get down to low. For patient-facing businesses in particular, the patient data and AI confidentiality checklist covers the professional duties that sit alongside data protection.

The underlying habit is simple: before a new AI use goes live, spend ten minutes asking whether it could hurt the people whose data it touches, write the answer down, and do the full assessment when the answer isn't a clear no.

DPIAs for AI: follow-up questions

Can I use a vendor's own risk assessment instead of writing a DPIA?

Use it as input, not a replacement. Some vendors publish material to help, such as Microsoft's risk assessment quickstart for Copilot and Copilot Chat, and their DPAs and security documents answer the supplier questions in your assessment. None of that can judge your particular use: whose data, for what purpose, with what safeguards. That part of the DPIA has to come from you.

Who should sign off a DPIA in a small business?

The controller, which in practice means the owner or a director, because the GDPR puts the duty on the business. If you've appointed a data protection officer, the law requires you to seek their advice while doing the assessment. For uses involving health data or other high-risk processing, having a data-protection adviser review the finished DPIA is sensible.

Do I have to publish my DPIA?

No. Publishing a DPIA isn't a legal requirement of the GDPR; it's at the controller's discretion. Some businesses publish a short summary to build trust with customers. You should keep the full version on file, review it when things change, and be able to produce it if your data-protection authority asks how you assessed the risk.

What if the DPIA shows a high risk I can't reduce?

Then you shouldn't simply go ahead. Under Article 36 of the GDPR, if an assessment shows high risk that your measures can't bring down, you must consult your data-protection authority before starting the processing. In practice most small businesses redesign the use instead: less data, a different tool, human review, or dropping the riskiest part.

Further reads

Sources: the GDPR (Articles 9, 22, 35 and 36); the DPIA guidelines endorsed at EU level (WP248 rev.01); the EU AI Act (Article 50 and the deferral of high-risk obligations); vendor pages on note-taker data handling (checked September 2026). General information, not legal advice.

Want a second pair of eyes on an AI use before launch?

On a 1:1 call we'll screen your planned AI uses, decide which need a full DPIA, and design the safeguards, so the assessment you write reflects what the tool will really do.

Book a 1:1 call with me