GDPR AI DPIA: When Article 35 Requires a Data Protection Impact Assessment for an AI System
GDPR Article 35 requires a Data Protection Impact Assessment when processing is likely to result in a high risk to the rights and freedoms of natural persons. Deploying an LLM against personal data almost always triggers the Article 35 threshold under the criteria the Article 29 Working Party and the European Data Protection Board have published. This piece walks through the Article 35 mandatory triggers, the EDPB Guidelines 3/2019 signals that apply to AI systems, the DPIA process steps under Article 35(7), the coordination with the EU AI Act Article 27 Fundamental Rights Impact Assessment, and the inspection-layer records that the DPIA references for the ongoing monitoring under Article 35(11).
Read post →