Skip to main content
Praxikon

Free template · Word · English and Dutch

DPIA template for AI systems, with a bridge to the FRIA

A DPIA for AI is the data protection impact assessment that Article 35 GDPR requires when an AI application is likely to result in a high risk to people's rights. The controller describes the processing, assesses the legal basis, necessity and automated decisions, weighs risks and measures, and completes it before real personal data enter the system.

Last checked against the law
Editor
, jurist, privacy and AI
Version and template ID
2.0 · praxikon:template:dpia-ai
Legal basis
Regulation (EU) 2016/679 (GDPR); Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744

Who is this template for?

  • Privacy officer or drafter of the DPIA, on behalf of the controllerContent of the DPIA (Article 35(7) GDPR) and screening against your supervisory authority's DPIA list (Article 35(4) GDPR)
  • Data protection officer (DPO)Advice on the DPIA (Article 35(2) GDPR) and the decision on prior consultation of the supervisory authority (Article 36 GDPR)
  • Business process owner deploying the AI systemBusiness process and human oversight; as deployer of a high-risk system also Article 26(2) and (9) AI Act (for Annex III from 2 December 2027)
  • Procurement and legalTerms with the AI vendor as processor (Article 28 GDPR) and the instructions for use from the provider (Article 13 AI Act)
  • Public bodies and organisations providing public servicesFundamental rights impact assessment as deployer (Article 27 AI Act, from 2 December 2027) and national instruments such as the Dutch IAMA
  • Works council or other employee representativesConsultation or consent under national law when the AI monitors or assesses staff (in the Netherlands Article 27(1)(k) and (l) of the Works Councils Act)

What is inside

  • Decision box: is a DPIA required for this AI application, with the EDPB criteria and a supervisory authority's DPIA list (Dutch example) (chapter 1)
  • What Article 26(9) of the AI Act does and does not say about the DPIA (chapter 1)
  • System, roles under the GDPR and the AI Act, business process and data flows from training to feedback (chapter 2)
  • Legal basis per processing operation, balancing test under EDPB Opinion 28/2024 and questions on the lawful development of the model (chapter 3)
  • Necessity, retention periods, transparency and rights, including Articles 50 and 86 of the AI Act (chapter 4)
  • Decision box for Article 22 GDPR after the SCHUFA judgment, with safeguards and human oversight (chapter 5)
  • AI vendors: roles, transfers and ten contract terms (chapter 6)
  • Risk matrix and ten common AI risks, each with a measure, owner and deadline (chapters 7 and 8)
  • DPO advice, views of data subjects, employee representatives, prior consultation and decision (chapters 9 and 10)
  • Bridge to the FRIA (Article 27 AI Act) and to national instruments such as the Dutch IAMA, plus a worked fictional example of a municipality (chapters 11 and 12)

How to use the template

  1. Start with the screening in chapter 1. If a DPIA is not required, record why and repeat the screening after every change.
  2. Ask the provider for the instructions for use and documentation, and complete chapter 2 together with the owner of the business process.
  3. Work through chapters 3 to 6: legal basis, necessity, automated decisions and the vendor.
  4. Identify the risks and give every measure an owner and a deadline (chapters 7 and 8).
  5. Ask the DPO for advice, involve employee representatives where needed and have the controller decide before processing starts (chapters 9 and 10).
  6. If you also need a FRIA or a national instrument such as the IAMA, copy the references from chapter 11 instead of the text.

Common mistakes

  • Assuming the AI Act requires the DPIA. The duty comes from Article 35 GDPR; Article 26(9) of the AI Act only says that the deployer of a high-risk system uses the provider's information for it.
  • Doing the DPIA at go-live. A pilot with real personal data is already processing; the DPIA is finished before it starts.
  • Assuming Article 22 GDPR does not apply because a human is involved. If that human draws strongly on the score, the score itself can be the decision (CJEU 7 December 2023, C-634/21, SCHUFA).
  • Looking only at what you put in. What the model infers can also be special category data (CJEU 1 August 2022, C-184/20), and logs and feedback held by the vendor belong in the assessment.
  • Treating the vendor as a processor in every case. If it trains its model on your data for its own purposes, it is a controller for that use and you need a legal basis of your own to disclose the data.

When do you need legal advice?

  • The residual risk stays high. A high risk remains even after measures. The controller must then consult the supervisory authority before processing starts (Article 36 GDPR); in the Netherlands that is the Autoriteit Persoonsgegevens.
  • The AI output effectively decides. A score or recommendation plays a determining role in a decision about a person. After the SCHUFA judgment (C-634/21) that can fall under Article 22 GDPR; the controller then needs an exception and safeguards.
  • The vendor uses your data for itself. It trains its model on your input. For that use it is a controller in its own right (Article 4(7) GDPR; outside your instructions, Article 28(10)). If it cannot explain how the model was lawfully developed, that affects your own use (EDPB Opinion 28/2024). In both cases the controller reassesses the legal basis and the contract.

Frequently asked questions

Does the EU AI Act require a DPIA?

No. The duty to carry out a DPIA comes from Article 35 GDPR and rests on the controller. Article 26(9) of the AI Act only says that the deployer of a high-risk system uses the information the provider supplies under Article 13 to carry out that DPIA.

When is a DPIA required for an AI application?

When the processing is likely to result in a high risk to the rights and freedoms of natural persons (Article 35(1) GDPR). That is always the case for the situations in Article 35(3) and for processing on your supervisory authority's DPIA list. If the processing meets two or more EDPB criteria, a DPIA is as a rule required.

Does a DPIA replace the fundamental rights impact assessment under Article 27?

No, but the deployer may refer to the DPIA in the FRIA or include parts of it (Article 27(4)). The FRIA looks at all fundamental rights and at everyone affected, not only at data protection. The template shows for each FRIA element what the DPIA already covers.

From when does the FRIA duty apply?

From 2 December 2027, before first use of an Annex III high-risk system (except point 2, critical infrastructure). The duty rests on deployers that are bodies governed by public law or private entities providing public services, and on deployers of systems for credit scoring or for risk assessment and pricing in life and health insurance. For systems already in use before then, Article 111(2) governs the transition.

What is the IAMA, and do I need it?

The Fundamental Rights and Algorithms Impact Assessment (IAMA) is an instrument from the Dutch central government's Algorithm Framework, used mainly by Dutch public bodies. It is not a legal duty under the AI Act, but it covers much of the FRIA. Chapter 11 maps it to the DPIA and the FRIA; use the same table for a comparable instrument in your own country.

May I adapt the template and share it within my organisation?

Yes. You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.

Use and credit

You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.

How to cite this template: Source: Praxikon, DPIA template for AI systems, with a bridge to the FRIA, version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/dpia-ai-systems

This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.

Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597