Obligation guides

Do I need a DPIA?

A DPIA is indicated when processing is likely to result in a high risk to individuals — especially large-scale special-category data, systematic monitoring, or automated decisions with legal or similarly significant effects.

01

When a DPIA is commonly indicated for AI

Automated decisions that accept, reject, score, or rank people in consequential ways.

Special-category or biometric data at meaningful scale.

Vulnerable people — patients, children, and similar groups — in the processing population.

EU/EEA or UK people in the footprint. Headquarters elsewhere does not remove the duty when those people are in scope.

02

Two halves of the assessment

Every mandated assessment has two halves. The regulatory half is knowing the law: which statutes apply, which obligations they trigger, what structure the instrument requires, and what the vendor’s published practices are. The organisational half is your controls, processes, risk decisions, and sufficiency judgment.

LegisGate automatically fills the regulatory half from the obligation record. Your privacy and legal team completes the organisational half and determines sufficiency.

← Obligation Atlas · Start the free check

Talk to usWe're here to help
Do I Need a DPIA for My AI Tool | LegisGate