Free template · Word · English and Dutch
AI procurement checklist template for public bodies (EU AI Act and GDPR)
An AI procurement checklist for public bodies is a working document that takes a municipality, ministry or agency through one AI purchase, from need to deployment. For each phase you record your organisation's role under the EU AI Act and the GDPR, the resulting duties, and what you ask of the supplier and put in the contract.
- Last checked against the law
- Editor
- Zahed Ashkara, jurist, privacy and AI
- Version and template ID
- 2.0 ·
praxikon:template:ai-inkoop-checklist-overheid - Legal basis
- Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Regulation (EU) 2016/679 (GDPR)
Who is this template for?
- Procurement officers and contract managers in municipalities, regions, ministries and agenciesTender and contract: information from the provider (Article 13) and the deployer's duties (Article 26)
- Legal advisers and privacy officersDetermining whether you are the provider or the deployer (Article 3, points 3 and 4, Article 25) and the data processing agreement (Article 28 GDPR)
- Data protection officer (DPO)Advice on the DPIA (Article 35(2) GDPR) and prior consultation of the data protection authority (Article 36 GDPR)
- Process owners for benefits, care and support services and other public servicesHigh-risk under Annex III, point 5(a); FRIA for bodies governed by public law from 2 December 2027 (Article 27)
- CIO and information securityLogs (Article 12 and Article 26(6)) and security (Article 15(5), Article 32 GDPR)
What is inside
- Overview of the seven phases and a timeline of what applies when, with the role that carries each duty (introduction)
- Assessment of alternatives and how to handle AI that arrives through an update (phase 1)
- Decision box: provider or deployer, plus the roles under the GDPR (phase 2)
- Prohibited practices, the Annex III points that matter for public bodies and Article 50, with fictional public-sector examples (phase 3)
- FRIA, DPIA, registration in the EU database and national instruments such as the Dutch IAMA and algorithm register, per procurement phase (phase 4)
- 19 supplier questions with columns for type, answer and assessment (phase 5)
- 16 contract clauses to use alongside the EU model contractual clauses (MCC-AI) or national model terms (phase 6)
- Acceptance tests T1 to T10 and the conditions for the decision to deploy (phase 7)
- Fictional worked example: an AI module for a social assistance benefit (Annex A)
How to use the template
- Use one checklist per procurement procedure, also when AI arrives through an update of software you already use.
- Go through phases 1 to 3 before the market consultation: need, role and classification determine what you ask the market.
- Plan the FRIA, the DPIA and the registrations in phase 4, and involve the DPO and information security from the start.
- Put the supplier questions and the contract clauses in the tender, so bidders know in advance what they are signing up to.
- Test in phase 7 with your own case files, processes and staff, and only then take the decision to deploy.
Common mistakes
- Assuming a public body is always the deployer. If you have a chatbot or model built and put it into service under your own name, you are the provider (Article 3, point 3); if you use a general-purpose system for an Annex III purpose, you may become one (Article 25(1)(c)).
- Waiting until 2 December 2027. A public contract of four years or more runs beyond that date; what you do not agree now is hard to enforce later.
- Mixing up policy and law. National instruments such as the Dutch IAMA or a public algorithm register are not duties under the AI Act, and they do not replace the FRIA in Article 27.
- Not excluding training on your data. If the supplier uses case files for its own purposes, it is a controller for that part (Article 28(10) GDPR).
- Adopting the EU model contractual clauses (MCC-AI) unchanged. They follow the June 2024 text; the high-risk dates postponed by Regulation (EU) 2026/1744 are not reflected.
When do you need legal advice?
- You are having something built or adapted. If you have a chatbot or model built that you put into service under your own name, or you use a general-purpose AI system for an Annex III purpose, your organisation may become the provider (Article 3, point 3, and Article 25(1)).
- The system helps decide about residents. For benefits or services it quickly becomes high-risk (Annex III, point 5(a)): from 2 December 2027 the deployer carries out a FRIA, and the controller assesses Article 22 GDPR.
- The supplier wants your data or withholds information. It wants to use case files for training (for that part it is then a controller, Article 28(10) GDPR), or it refuses the information required by Article 13, access to logs or an audit right.
Frequently asked questions
Is a public body that buys AI the provider or the deployer?
Usually the deployer (Article 3, point 4). A public body becomes the provider if it has a system built and puts it into service under its own name (Article 3, point 3), or if it uses a system for an Annex III purpose the supplier did not intend (Article 25(1)(c)); the provider obligations apply from 2 December 2027 for Annex III.
When must a public body carry out a fundamental rights impact assessment (FRIA)?
From 2 December 2027, before first use of an Annex III high-risk system (except point 2). The duty rests on deployers that are bodies governed by public law (Article 27). Systems in use before that date are covered only after a significant change in their design; systems intended for use by public authorities must comply by 2 August 2030 (Article 111(2)).
Does a public body have to register its AI system?
From 2 December 2027, a deployer that is a public authority registers its use of an Annex III high-risk system (except point 2) in the EU database (Article 26(8) and Article 49(3)). If the system itself is not registered, it may not be used. National algorithm registers are a separate matter: in the Netherlands, publication in the Algoritmeregister is policy, not a legal duty (as of 6 October 2026).
Does Article 50 already apply to a chatbot on a municipal website?
Yes, since 2 August 2026. The provider ensures that people know they are interacting with AI, unless that is obvious to a reasonably well-informed person (Article 50(1)). If the municipality has the chatbot built and puts it into service under its own name, it is the provider itself.
Are the EU model contractual clauses (MCC-AI) still up to date?
The updated version was published on 5 March 2025 and follows the text of the AI Act as adopted in June 2024. The postponement of the high-risk dates by Regulation (EU) 2026/1744 is not reflected, so check dates and references. The contract clauses in this checklist use the current dates.
What fines apply to public bodies?
The AI Act sets maximum fines that Member States must lay down in their own rules, and each Member State decides to what extent fines can be imposed on public authorities (Article 99(8)). Check your own Member State: in the Netherlands, as of 6 October 2026, no market surveillance authority for the AI Act has been designated and there is no implementing act yet. The duties themselves do apply.
Use and credit
You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.
How to cite this template: Source: Praxikon, AI procurement checklist template for public bodies (EU AI Act and GDPR), version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/ai-inkoop-checklist-overheid
This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.
Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597