The legal position in four sentences
Art. 35 GDPR requires an impact assessment before processing that is likely to result in a high risk to the rights and freedoms of natural persons, with the advice of the data protection officer, where one has been designated. It describes the operations and purposes, assesses necessity and proportionality as well as the risks, and sets out the measures to address them (Art. 35(7)). If a high risk remains after that, the supervisory authority must be consulted beforehand under Art. 36. The processor assists under Art. 28(3)(f), but does not owe the assessment itself.
What the Datenschutzkonferenz's mandatory list says
The Datenschutzkonferenz, the joint body of the German data protection authorities, keeps an expressly non-exhaustive list of processing operations for which a DPIA must be carried out. Two entries directly concern AI tools in the office:
No. 11: “Use of artificial intelligence to process personal data in order to control interaction with data subjects or to evaluate personal aspects of the data subject”
No. 8 covers the extensive processing of data on employees' behaviour that can be used to evaluate their work in such a way that legal consequences arise or the data subjects are significantly affected; as examples, the list names data loss prevention systems that create systematic profiles and the central recording of workplace activities.
In addition, the Guidelines on Data Protection Impact Assessment (WP 248 rev. 01), adopted by the European Data Protection Board, apply. They name nine criteria: evaluation or scoring, automated decisions with significant effect, systematic monitoring, sensitive or highly personal data, scale, matching of datasets, vulnerable data subjects (expressly including employees), innovative technology, and obstacles to exercising a right or accessing a service. According to the guidelines, if two of them coincide, a DPIA is needed in most cases; sometimes one is enough.
When an AI tool tips the balance
- The tool records activity at user level: ID, time, operation, usage.
- Personal data runs through a model: personnel files, job applications, sick notes, customer data.
- Results evaluate people or control how they are dealt with; then no. 11 of the mandatory list is close.
- Analyses are visible to managers or can be traced back to individuals.
- Datasets are linked: project, user, quality, time.
- An agent can act across several systems; this points to the “innovative technology” criterion.
Operating without content logging and with only aggregated metrics lowers the risk considerably, but it does not make the written threshold assessment unnecessary. If a supervisory authority asks, it is the first document you can present, and it often fits on one page. According to the Datenschutzkonferenz's AI guidance, this preliminary assessment must be carried out before personal data is processed (para. 38).
What the provider must supply
- System description and data flows: what flows, where to, how often
- Model and route details per provider: region, retention, human review, training exclusion
- Technical and organisational measures, verifiable rather than a declaration of intent
- The system's limits and foreseeable misuse, the section providers would most like to leave out
- Residual risk from the provider's perspective, expressly marked as such
- Deletion routes including queues, caches and backups
At Biwak, you will find this information in three places today: the data path, recipients and the commitments on storage and training in sections 9 and 14 of the privacy policy; storage locations, checkpoint and network connections in the evidence; plus the usage data per account. You will find the DPA with measures and subprocessors at biwak.ai/avv; whatever it names as open belongs in your assessment. The risk assessment should also reflect that on Azure, the first route, Microsoft may store conspicuous requests for abuse detection and have them reviewed by humans.
A framework to get you started
- Name the operation
Not “AI roll-out”, but the specific operation, for example: “Summarising incoming customer letters with a language model at the provider”.
- Legal basis per data type
Not per tool: the data types differ, and a blanket justification stands out in any review.
- Necessity and proportionality
With the alternative you rejected. Without it, the section reads like a justification after the fact.
- Risks for the data subjects
Not for the company. This is the most common mistake in submitted assessments.
- Measures and residual risk
With a date and a responsible person.
- Review date
A change of model or a new sub-processor is a significant change and a reason to review the assessment.
A concise introduction to process and content is given in Short Paper No. 5 of the Datenschutzkonferenz.
Frequently asked questions
Is it enough if the provider supplies a DPIA?
No, it is owed by the controller, and that is you. A provider can supply input: system description, data flows, routes, retention, measures, limits and its residual risk. Anyone distributing a ready-made “DPIA” as a PDF is supplying a template; they cannot assess your use.
Do we need a DPIA for a pilot with five people?
The threshold assessment, yes. Whether a full DPIA becomes necessary depends on the content, not on headcount: if the AI evaluates people or controls how they are dealt with, or if employees' behavioural data is analysed extensively, one is likely even with five people. A small pilot is not an exemption.
What if we do not enter any personal data at all?
Then the threshold assessment is short, and the exclusion must be ensured, not merely intended: anyone who can open files will eventually open one with names in it. Record which data sets are excluded and how this is enforced; only then does the finding hold.
Does a locally run model make the assessment smaller?
Yes, because the transfer to a model provider, its sub-processors and the question of retention and human review there no longer apply; the Datenschutzkonferenz considers technically closed systems preferable. What remains is your own processing: access rights, logs, deletion. Biwak does not offer such operation; with Biwak, the model route belongs in the assessment: first Microsoft Azure in the EU Data Zone, alternatively PREM SA.
Do we also need a fundamental rights impact assessment under the EU AI Act?
Only in certain cases. From 2 December 2027, Art. 27 of the EU AI Act requires it from deployers of certain high-risk systems, such as public bodies and private providers of public services, and for creditworthiness assessments or life and health insurance. Where it is required, it has been allowed to refer to the relevant sections of the DPIA since 27 July 2026.
Sources
- Regulation (EU) 2016/679 (GDPR), Art. 35 and 36
- DSK: Mandatory list for data protection impact assessments, version 1.1 (PDF)
- Article 29 Working Party / EDPB: Guidelines on Data Protection Impact Assessment, WP 248 rev. 01
- DSK: Short Paper No. 5, Data protection impact assessment (PDF)
- DSK: Guidance on artificial intelligence and data protection, 6 May 2024 (PDF)
- Biwak: Privacy policy, sections 9 and 14
This text is not legal advice. It is the groundwork we had to do for ourselves, with the legal references, so that your lawyer does not have to start from scratch. Where a question depends on your circumstances, the text says so.
