Initial screening questions
- Does the processing evaluate, score or profile participants?
- Could it produce legal or similarly significant effects?
- Does it involve systematic monitoring?
- Are sensitive or highly personal data likely to appear?
- Is processing large scale or does it combine multiple datasets?
- Are vulnerable people involved?
- Does the use rely on a materially new technology or prevent access to a right or service?
How to respond
The CNIL explains that a DPIA is required where processing is likely to result in a high risk. Meeting AI is not automatically high risk merely because it uses AI, but the content, scale, monitoring purpose and consequences can change the assessment. Two relevant EDPB criteria generally create a presumption that a DPIA is needed, subject to documented analysis.
Minimum DPIA structure
- Describe processing operations and purposes.
- Assess necessity and proportionality.
- Identify risks to people's rights and freedoms.
- Document safeguards, security measures and residual risk.
- Review the assessment when the use or technology changes.
This checklist is a screening aid, not a completed DPIA or legal determination.
Official sources
Use the authoritative texts below when making legal or compliance decisions.
This resource provides general product and operational information. It is not legal advice. Your organization remains responsible for assessing its specific use, lawful basis and obligations.