Your team has found an AI tool that will save hours — an AI assistant that reads applications, a chatbot that answers service users, a system that flags cases for follow-up. Before you switch it on, there's a question worth asking: does introducing it trigger a Data Protection Impact Assessment? For a lot of charities, the honest answer is yes — and doing the assessment first is far cheaper than discovering it was needed later.
This is a plain-English guide to GDPR Article 35 for people who run organisations, not for lawyers. It explains when a DPIA is required, what has to be in one, how the new AI Act layer sits on top, and gives you a short screening checklist you can run in ten minutes.
This article is general information, not legal advice. It does not constitute legal advice, and Vedomia does not provide legal services. For legal questions about your specific situation, speak to a qualified solicitor or your Data Protection Officer.
What a DPIA actually is
A Data Protection Impact Assessment is a structured think-before-you-act. Under Article 35 of the GDPR, when a type of processing is likely to result in a high risk to the rights and freedoms of individuals, you have to assess that risk before you start — early enough that the findings can still change the design. It is not a form you file with a regulator. It is your own written record that you looked at the risk to people and did something about it.
The reason it matters for AI is simple: the Irish Data Protection Commission and the European Data Protection Board both treat the use of new or innovative technology as one of the signals that pushes processing into "high-risk" territory. AI, in most charities, is exactly that.
The three cases where a DPIA is always required
Article 35(3) names three situations where a DPIA is mandatory regardless of anything else:
- Systematic and extensive profiling with significant effects — evaluating people based on automated processing, then making decisions that affect them.
- Large-scale processing of special-category data — health, ethnicity, religion, sexual orientation, or data about criminal convictions. Many charities hold exactly this kind of data about the people they serve.
- Systematic monitoring of a publicly accessible area on a large scale.
If an AI tool you're adopting sits inside any of these, a DPIA is not optional.
The Irish "always do a DPIA" list
Beyond the GDPR's three cases, the Irish Data Protection Commission has published its own list, under Article 35(4), of processing operations that always require a DPIA in Ireland. It includes operations such as large-scale profiling, processing special-category or highly personal data to evaluate people, systematic monitoring, and combining or matching datasets from different sources. AI-assisted decisions about vulnerable individuals — which is a lot of what charities do — tend to land on this list quickly.
The practical takeaway: you don't get to decide on gut feeling that your AI tool is "low risk". If it resembles anything on the mandatory list, the assessment is required, and the assessment is where you find out how risky it really is.
The point of a DPIA isn't to prove the risk is zero. It's to show you saw the risk clearly and chose your safeguards on purpose.
When AI specifically tips you into DPIA territory
You don't need a legal background to spot the common triggers. Ask whether the AI tool does any of the following with real people's data:
- Helps decide who gets something — screening applicants, ranking or scoring people for a service, grant, place or role.
- Evaluates or predicts — flagging "risk", predicting need, assessing performance or behaviour.
- Processes sensitive data at scale — health, disability, immigration status, financial hardship, safeguarding notes.
- Monitors people — content moderation, communications, or activity, systematically.
- Combines data from separate systems to build a fuller picture of someone.
A "yes" to any of these, involving personal data, is a strong signal that a DPIA is expected — and that it should be done before the tool goes live.
What a DPIA has to contain
Article 35(7) sets the minimum. A DPIA must include, in writing:
- A systematic description of the processing and its purposes — what the AI tool does, with whose data, why, and on what lawful basis.
- An assessment of necessity and proportionality — do you actually need to process this data this way to achieve the purpose, or is there a lighter-touch option?
- An assessment of the risks to the rights and freedoms of the people whose data is involved — how likely, how serious, and who is affected.
- The measures to address those risks — safeguards, security measures, human review, limits on what the tool can do, and how you'll monitor it.
Your Data Protection Officer (if you have one) must be consulted, and their advice recorded. If, after your safeguards, a high risk still remains and you can't reduce it, GDPR requires you to consult the Data Protection Commission before going ahead.
A six-step way to run one
You don't need a consultant to start. A workable DPIA follows a simple arc:
1. Screen
Decide whether a DPIA is needed at all, using the triggers above. Write down the answer either way — "we checked, and here's why it does / doesn't apply" is itself useful evidence.
2. Describe
Map the data flow: what personal data goes into the AI tool, where it comes from, where it goes, who the vendor is, and whether data leaves the EU.
3. Test necessity
Ask whether you genuinely need the AI, and this much data, for the purpose. Proportionality is often where a DPIA earns its keep — it's where you decide not to feed the tool something it doesn't need.
4. Assess the risks
For each risk to people — wrong decisions, exposure of sensitive data, loss of human review — rate how likely and how severe it is, and who bears it.
5. Choose measures
Decide the safeguards: a human reviews every consequential output, sensitive data is kept out, access is limited, the vendor's terms are checked. Note the residual risk that remains after them.
6. Sign off and revisit
Someone accountable signs it, with a date. Review it when the tool, the data, or the purpose changes. A DPIA is a living record, not a one-off.
The one-line test: if the Data Protection Commission asked tomorrow, "before you switched this AI tool on, how did you assess the risk to the people whose data it uses?" — could you hand them a dated document? If not, that document is your next task.
The new layer: DPIA and the AI Act's FRIA
From 2 August 2026, the EU AI Act adds a second kind of assessment for some organisations: a Fundamental Rights Impact Assessment (FRIA) under Article 27. It is narrower than a DPIA. A FRIA is required from deployers of certain high-risk AI systems who are public bodies or private organisations providing public services — a description that can reach charities delivering publicly funded or public-facing services.
The two assessments overlap heavily. Where both apply, the sensible approach — and the one regulators are signalling — is to build on your DPIA rather than duplicate it: the DPIA supplies most of the personal-data analysis, and the FRIA adds the wider look at effects on people's fundamental rights. One joined-up assessment, not two disconnected ones.
AI Tool — DPIA Screening Checklist
Run this before adopting any AI tool that touches personal data. Any "Yes" means a full DPIA is very likely required.
| Screening question | Yes / No |
|---|---|
| Does the tool use personal data of service users, applicants, staff or volunteers? | [ ] |
| Does it help make or shape decisions about people (screening, scoring, ranking, flagging)? | [ ] |
| Does it process special-category or highly sensitive data (health, disability, safeguarding, financial hardship)? | [ ] |
| Does it evaluate or predict something about individuals? | [ ] |
| Does it combine data from different systems, or monitor people systematically? | [ ] |
| Is this new technology for your organisation? | [ ] |
| Are the people involved potentially vulnerable? | [ ] |
| Might your organisation count as a public-service provider (relevant for a FRIA from Aug 2026)? | [ ] |
Keep the completed checklist — even a "no DPIA needed" result is worth recording, with your reasons and the date.
How Vedomia can help
Vedomia is an Irish company focused on one thing: helping organisations make their processes and their use of AI visible, explainable and auditable. We work mainly with charities, nonprofits and publicly funded organisations.
A DPIA rests on a foundation you need anyway: knowing exactly where AI lives in your organisation, what data it touches, and who reviews its output. That inventory is where we start.
- Transparency Self-Audit (free). Around 20 questions across four pillars — Visibility, Sequence, Justification, Auditability. It surfaces where AI is used, what it decides, and where your evidence and human-review are thin — the same ground a DPIA has to cover.
- Mapped with you (€1,450, one-off). A single 90-minute session: you describe how one key process really runs, Sandra maps it live, and you leave with a finished, official document — the process end to end, where AI enters it, the evidence to keep and a prioritised 30–90 day plan. No homework, and it begins with a free Clarity Call.
To be clear about what we do and don't do: Vedomia supports readiness, helps you document your AI use, and identifies transparency gaps. We do not certify compliance, we do not provide legal advice, and nothing we provide guarantees legal conformity. A DPIA is a legal obligation — its content and sign-off rest with your organisation and, where relevant, your Data Protection Officer and solicitor.
The tool that saves your team hours is worth adopting. Spending one of those hours, up front, on a DPIA is how you make sure it doesn't cost you the trust of the people whose data you hold.
This article is general information about GDPR Article 35 and the EU AI Act, and does not constitute legal advice.
Prepared with the help of an AI assistant, reviewed by Sandra Fedakova.
Want to see where AI touches personal data across your organisation — and where the gaps are?
Take the Free Transparency Self-Audit