legal247

DPIA for AI tools: when is it required, and what must it contain?

In brief

A DPIA for AI tools is required when their use is likely to result in a high risk to data subjects, under GDPR Art. 35. AI tools with access to email, documents, customer data or employee data often meet the threshold. If two or more of the nine criteria in the Article 29 Working Party guidelines are met, you should assume that a DPIA is required.

Many businesses are adopting AI tools faster than they can assess the data protection implications. That is risky, because the GDPR requires the assessment to be made before the processing starts, not afterwards. For AI tools that are given access to email, documents, customer data or employee data, a DPIA will often be required.

What is a DPIA for AI tools?

A DPIA, or data protection impact assessment, is a written analysis of the risk a processing operation poses to data subjects and of the measures that will reduce it. The obligation follows from GDPR Art. 35(1) in the GDPR, which applies as Norwegian law through Personal Data Act § 1 in the Personal Data Act (personopplysningsloven).

The assessment must be carried out before the processing starts. The provision expressly highlights the use of new technologies as a factor that may result in a high risk, and most generative AI tools fall within that. Unlike the AI Act, the DPIA obligation applies in full in Norway today.

When is a DPIA required for AI tools?

A DPIA is required when the processing is likely to result in a high risk to the rights and freedoms of natural persons. There are three routes in.

The first is the cases expressly listed in GDPR Art. 35(3). These include a systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are based that produce legal effects or similarly significant effects. They also include processing of special categories of personal data on a large scale, and systematic monitoring of publicly accessible areas on a large scale.

The second is the list published by the Norwegian Data Protection Authority (Datatilsynet) of processing operations that always require a DPIA, adopted under GDPR Art. 35(4). Several items on the list are particularly relevant to AI. They include processing using innovative technology combined with at least one other criterion, systematic monitoring of employees, the use of special categories or highly personal data on a large scale for training algorithms, and services that predict matters such as job performance, finances, health, behaviour or reliability.

The third is the nine criteria in the guidelines of the Article 29 Working Party (WP 248 rev.01), which the European Data Protection Board (EDPB) endorsed when it was established in May 2018. The criteria thus originate from the Article 29 Working Party, not from the EDPB itself. If two or more are met, the processing will in most cases require a DPIA.

Criterion in WP 248 Typical AI example
Evaluation or scoring Tools that rank job applicants or assess customers’ creditworthiness
Automated decision-making with legal or similarly significant effect Automatic rejection of an application or complaint
Systematic monitoring Analysis of employees’ email, chat or meeting recordings
Sensitive or highly personal data Health data in minutes or case documents
Large-scale processing An assistant with access to the entire document archive of the business
Matching or combining datasets AI that links CRM, email and case management systems
Vulnerable data subjects Employees, patients, children or pupils
Innovative use of technology Generative language models and agents
Processing that prevents the exercise of rights or access to services AI that decides whether a customer is offered a deal or a contract

The question is rarely whether the AI tool processes personal data. It is how much, about whom and with what consequences.

Which AI tools typically trigger a DPIA?

An AI assistant connected to email, calendar and document storage will often meet at least two criteria, namely innovative technology and large-scale processing. Matching of datasets and vulnerable data subjects often come on top, because employees are regarded as vulnerable in relation to their employer. A DPIA should then be assumed.

The same applies to AI in recruitment, tools that transcribe and summarise meetings, chatbots that handle customer enquiries, and analytics tools that assess employee productivity. The last of these appears directly on Datatilsynet’s list as systematic monitoring of employees.

A translation tool used only on text without personal data does not normally require a DPIA. The boundary must nevertheless be assessed case by case, and the conclusion should be documented even when the answer is that no DPIA is required.

What must a DPIA for AI tools contain?

The minimum content is set out in GDPR Art. 35(7). The assessment must contain at least four elements.

  1. A systematic description of the processing and its purposes.
  2. An assessment of whether the processing is necessary and proportionate.
  3. An assessment of the risks to the rights and freedoms of data subjects.
  4. The measures envisaged to address the risks and demonstrate compliance with the GDPR.

The data protection officer must give advice on the work where the business has one, under GDPR Art. 35(2). Where appropriate, data subjects or their representatives must be given the opportunity to express their views, under GDPR Art. 35(9). For AI tools used by employees, it is natural to involve employee representatives. The assessment must be updated when the risk changes, under GDPR Art. 35(11), for example when the supplier launches new features or a new model.

For AI tools, the assessment should in particular cover whether the supplier uses data for training, where data is stored and processed, which sub-processors are used, how errors in the output are detected and how data subjects can exercise their rights. This is closely linked to the data processing agreement with the SaaS supplier. If data is processed in the US, the assessment must also cover the transfer mechanism, see the article on the EU-US Data Privacy Framework.

When must Datatilsynet be consulted?

If the assessment shows that the processing would result in a high risk in the absence of measures taken by the business, Datatilsynet must be consulted before the processing starts, under GDPR Art. 36(1). In practice, this applies where the business is unable to reduce the risk to an acceptable level.

If Datatilsynet considers that the intended processing would infringe the GDPR, it must provide written advice within eight weeks. That period may be extended by six weeks in complex cases, under GDPR Art. 36(2). This means that an AI project with a high residual risk must be planned with a margin of several months.

Failure to carry out a DPIA or prior consultation can lead to an administrative fine of up to EUR 10 million or 2 per cent of total global annual turnover, under GDPR Art. 83(4). The largest cost, however, is often something else. If a tool has to be stopped after it has been rolled out, the investment and the working hours are lost.

How does the DPIA relate to the AI Act?

The AI Act builds on the DPIA obligation, but does not yet apply in Norway. Under AI Act Art. 26(9), deployers of high-risk systems must use the information provided by the provider under Article 13 when they carry out a DPIA under the GDPR.

AI Act Art. 27 additionally requires a fundamental rights impact assessment from public bodies, private entities providing public services, and deployers using high-risk systems for credit scoring or for risk assessment and pricing in life and health insurance. Where some of the requirements are already met through the DPIA, the assessment under Article 27 must complement it, under AI Act Art. 27(4).

Following amending Regulation (EU) 2026/1744, the obligations for high-risk systems in Annex III apply in the EU from 2 December 2027. In Norway, the regulation must first be incorporated into the EEA Agreement and implemented in Norwegian law, and the government aims to present a bill to the Norwegian Parliament in spring 2027. A good DPIA today will in any event provide a basis that can be reused. Read also about the AI literacy requirement under the AI Act and the data protection topic page.

What should the business do?

  1. Map the AI tools. Draw up an overview of the tools that process personal data, including those employees have started using on their own.
  2. Carry out a threshold assessment. Assess each tool against GDPR Art. 35(3), Datatilsynet’s list and the nine criteria, and document the conclusion.
  3. Carry out the DPIA before procurement. Ask the questions about training, storage, sub-processors and transfers before the agreement is signed.
  4. Involve the data protection officer and employees. Use employee representatives when the tool affects employees.
  5. Link the assessment to the rules. Let the findings shape the AI policy for employees, for example what must not be entered into the tool.
  6. Update when things change. Review the assessment when the supplier changes the model, features or terms.
  7. Consult Datatilsynet where the residual risk is high. Plan for a processing time of up to 14 weeks.

Questions and answers

Must we always carry out a DPIA before introducing an AI assistant?

No, but the threshold is often met. If the tool processes personal data on a large scale, monitors employees, or has access to email, documents and customer data, you should assume that a DPIA is required. If you conclude that it is not required, the reasoning should be documented.

Can we use the supplier's DPIA?

No, not as a substitute for your own assessment. The obligation lies with the controller, and the risk depends on how you use the tool. The supplier's documentation is nevertheless a useful basis, and the processor must assist under GDPR Art. 28(3)(f).

What happens if we do not carry out a DPIA when one is required?

The Norwegian Data Protection Authority can impose an administrative fine of up to EUR 10 million or 2 per cent of global annual turnover under GDPR Art. 83(4). It can also order you to stop the processing until the assessment has been carried out.

Next legal review: 15 January 2027