Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

AI impact assessment vs DPIA: ISO 42005 impacts on people and society compared with the GDPR Article 35 DPIA

AI Impact Assessment vs DPIA: The Essential 2026 Guide to Running Both

AI impact assessment vs DPIA comes up whenever an AI system uses personal data, which is most of the time. A data protection impact assessment (DPIA) is a legal duty under Article 35 of the GDPR for processing likely to be high risk. An AI system impact assessment, as ISO/IEC 42005 describes it, looks at everything an AI system could do to people and society, whether or not personal data is involved. They overlap heavily, but neither replaces the other. This guide sets out the differences, where they meet and how to run them together.

AI impact assessment vs DPIA: ISO 42005 impacts on people and society compared with the GDPR Article 35 DPIA

AI Impact Assessment vs DPIA: The Short Answer

A DPIA asks whether processing personal data is likely to result in a high risk to people’s rights and freedoms, and what measures bring that risk down. It is mandatory when the test is met, and if high risk remains, the supervisory authority must be consulted before processing starts. An AI system impact assessment asks what an AI system’s reasonably foreseeable impacts are on individuals, groups and society, benefits as well as harms, across the whole lifecycle. It is guidance under ISO/IEC 42005 and a requirement for organizations certified to ISO/IEC 42001 (clause 6.1.4).

AI Impact Assessment vs DPIA: Side-by-Side

DPIAAI system impact assessment
SourceGDPR and UK GDPR Article 35ISO/IEC 42005; required by ISO/IEC 42001 clause 6.1.4
Mandatory?Yes, where processing is likely to be high riskFor ISO/IEC 42001; otherwise good practice
TriggerProcessing of personal data likely to be high riskAn AI system in scope, before deployment and on significant change
Scope of harmRights and freedoms of the people whose data it isIndividuals, groups and society, including people whose data is not used
Core contentDescription, necessity and proportionality, risks, measures (Article 35(7))System, uses and misuse, data, model, environment, people affected, impacts, measures
BenefitsWeighed in necessity and proportionalityRecorded and weighed explicitly
Who advisesThe DPO, where one is designated (Article 35(2))An AI governance function, as the organization decides
RegulatorPrior consultation if high risk remains (Article 36)None under the standard

Why Most AI Systems Need a DPIA

The UK Information Commissioner’s Office is direct about it: its guidance on AI and data protection says that in the vast majority of cases, using AI will involve processing likely to result in a high risk, and so will trigger the legal requirement for a DPIA. Several of the nine criteria regulators use to screen for a DPIA, such as evaluation or scoring, automated decisions, innovative technology and large scale, describe typical AI uses. Our guide to when a DPIA is required covers the screening.

What an AI Impact Assessment Adds

A DPIA is anchored to personal data and to data protection law. An AI impact assessment reaches further:

  • People outside the dataset. A model trained on one group’s data can affect another group entirely, such as applicants ranked by patterns learned from past hires.
  • Harms beyond data protection. Physical safety, misinformation, effects on jobs and working conditions, the environment, and trust in public services.
  • AI-specific causes. Automation bias, model drift, third-party model changes, generated content and foreseeable misuse.
  • The whole lifecycle. Design, development, deployment, use and retirement, with a review at each significant change.

Where the AI Impact Assessment vs DPIA Overlap Is Useful

Much of the description is the same: what the system does, the data, the people affected, the recipients and the safeguards. Fairness, transparency, human review and contestability appear in both. Rather than two teams describing one system twice, run them together:

  1. Screen for both at the same time: the DPIA criteria and the AI impact thresholds.
  2. Describe the system once, covering what each needs: purposes and lawful basis for the DPIA; uses, misuse, model and deployment for the impact assessment.
  3. Rate privacy risks in the DPIA and the wider impacts in the impact assessment, cross-referencing where they are the same harm.
  4. Choose measures once, and record them in both.
  5. Get the DPO’s advice on the DPIA and the AI governance review on the impact assessment, then take one decision on the system.

Our AI impact assessment example shows a recruitment tool where Brightwell did exactly this, and the DPIA example shows the data protection half for a different system.

The EU AI Act Adds a Third

Certain deployers of high-risk AI systems, including public bodies, private entities providing public services, and deployers of credit scoring or life and health insurance pricing, also owe a fundamental rights impact assessment under Article 27 of the EU AI Act. The Act itself says that where a DPIA already covers some of the obligations, the fundamental rights assessment complements it. After the Digital Omnibus, the duties for Annex III high-risk systems apply from December 2027. See our guide to the fundamental rights impact assessment.

What to Record in Each

When the two run together, keep each record complete on its own terms, so either can be shown to the person who asks for it:

RecordDPIAAI impact assessment
ScreeningArticle 35(3) cases, the authority’s list, the nine criteriaProhibited and sensitive uses, context factors
DescriptionPurposes, lawful basis, data, recipients, retention, transfersSystem, uses and misuse, data quality, model, deployment, people affected, benefits
AnalysisNecessity and proportionality; risks to rights and freedomsSafeguards per dimension of impact; impacts on individuals, groups and society
MeasuresData protection measures, referenced to GDPR articlesMeasures referenced to ISO/IEC 42001 Annex A controls
Sign-offDPO advice, views of the people concerned, outcome, Article 36 checkGovernance review, views of the people affected, decision, next review

Cross-reference the two by risk, so a reviewer can see that a privacy harm in the DPIA and the same harm in the impact assessment carry the same rating and the same measures. That single step removes most of the AI impact assessment vs DPIA confusion an auditor or regulator would otherwise find.

Common Mistakes

  • Assuming the DPIA covers AI. It covers the personal data. The harms to people outside the data, and the AI-specific causes, need the impact assessment.
  • Assuming the impact assessment satisfies Article 35. It can, if it includes everything Article 35(7) requires and the DPO’s advice, but it has to be checked against the law, not assumed.
  • Different conclusions on the same harm. Two teams rating the same risk differently is the first thing a regulator will notice.
  • No review after model updates. A provider’s model update can change both assessments.

Frequently Asked Questions

AI impact assessment vs DPIA: can one document serve as both?

Yes, if it contains everything Article 35(7) requires, records the DPO’s advice, covers the ISO/IEC 42005 elements, and makes one decision on the system. Many organizations prefer two linked records, because the DPIA has legal consequences the impact assessment does not.

What if the AI system uses no personal data?

Then no DPIA is needed, but an impact assessment still is: an AI system can affect people without processing their data.

In the AI impact assessment vs DPIA sequence, which comes first?

Screen for both at once. If a DPIA is required, its timing is fixed: before the processing starts.

Who owns each one?

In the AI impact assessment vs DPIA split, the DPIA belongs to the controller, advised by the DPO. The impact assessment belongs to whoever owns the AI system, with the AI governance function reviewing it.

Run the impact assessment with our free AI impact assessment template and the DPIA with the free DPIA template; both rate harms for the people affected, not for the organization. For the documents around them, see the ISO 42001 Toolkit and the GDPR Toolkit, and for how the impact assessment relates to AI risk, our comparison of AI impact assessment vs risk assessment.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.