AIPolicyTracker
AssessmentFree · sent to your work emailEU AI Act

AI Supplement to a Data Protection Impact Assessment

Formats: DOCX and XLSX · Version v1 · Built from dataset c6967b988bb5 · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Supplement to a Data Protection Impact Assessment is a free DOCX and XLSX assessment for EU AI Act. Fifteen AI-specific questions to add to a DPIA (inferences, training on personal data, accuracy across groups, automated decisions, model attacks, suppliers), with the privacy and impact-assessment duties on record. It is licensed CC BY 4.0 and is not legal advice.

Format
DOCX and XLSX · Assessment
Version
v1, built 5 Oct 2026
Duties cited
11 from 9 instruments
Rows from the records
26
Frameworks
EU AI Act
Written for
Deployer / user organisation, Provider / developer, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Fifteen questions in nine areas, each with answer, risk rating and mitigation
  • Document version with a section per area
  • Privacy and impact-assessment duties sheet

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: AI questions · 5 columns · 15 rows from the records
First rows of the AI questions sheet
AreaQuestion to add to the DPIAAnswerRisk ▾Mitigation
Purpose and necessityWhat decision or output does the AI system produce, and why is AI necessary for it?
Purpose and necessityCould the same purpose be met with less personal data or without AI?
DataWhich personal data trains, tunes or grounds the model, and what is its lawful basis?
DataDoes the system infer new personal data (for example characteristics, preferences or risk scores)?
DataIs special-category or children's data used or inferred?
DataCan personal data be extracted from the model or its outputs?

Questions specific to AI processing, to answer alongside the standard data protection impact assessment.

Sheet: Privacy and impact duties · 14 columns · 11 rows from the records
First rows of the Privacy and impact duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Carry out a fundamental rights impact assessment before deploymentImpact assessmentEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 272027-12-02Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployersFundamental rights impact assessment reportClause 6.1.4 AI system impact assessment; Annex A control on impact assessmentMAP 5.1, MAP 5.2Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment
Deployers must use the provider's transparency information in their data protection impact assessmentPrivacy and personal-data protectionEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 26(9)2027-12-02Where a deployer of a high-risk AI system is required to carry out a data protection impact assessment under Article 35 of the GDPR or Article 27 of the Law EnfData protection impact assessment citing the provider's Article 13 informationClause 6.1.4; Annex A.5.2MAP 3.1, MEASURE 2.10Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information
Process personal data only with valid consent or a legitimate use, after noticePrivacy and personal-data protectionIndia DPDP ActIndiaProvider / developer, Deployer / user organisationLegal requirementSections 4 to 7Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses Consent records and noticesAnnex A controls on data for AI systemsSource-linkedhttps://aipolicytracker.org/obligations/india-dpdp-consent-and-notice
Significant Data Fiduciaries must appoint a DPO and run impact assessments and auditsImpact assessmentIndia DPDP ActIndiaProvider / developer, Deployer / user organisationLegal requirementSection 10Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data ProtectiData protection impact assessmentClause 6.1.4 AI system impact assessmentSource-linkedhttps://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties
Collect and use personal information only with consent and for the stated purposePrivacy and personal-data protectionNepal Privacy Act 2075NepalProvider / developer, Deployer / user organisation, Public authority / government bodyLegal requirementChapter on collection and protection of personal information (reviewer to cite sections)Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for otherConsent and purpose recordsAnnex A controls on data for AI systemsSource-linkedhttps://aipolicytracker.org/obligations/nepal-privacy-act-consent-and-purpose
Employers and employment agencies must disclose the data collected and their retention policy for the toolPrivacy and personal-data protectionNYC Local Law 144 (automated employment decision tools)New York (United States)Deployer / user organisationLegal requirementNYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-3032023-07-05Unless already disclosed on the website, an employer or employment agency must provide, within 30 days of a written request from a candidate or employee, informData collection and retention notice for the tool; Request response logAnnex A.7.2, A.8.5MAP 2.2, MEASURE 2.10Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-data-policy-disclosure

The recorded privacy and impact-assessment duties for AI systems.

Document outline (DOCX)

  1. AI supplement to a data protection impact assessment
  2. Purpose and necessity
  3. Data
  4. Accuracy and fairness
  5. Automated decisions
  6. Transparency
  7. Rights
  8. Security
  9. Suppliers
  10. Monitoring
  11. Duties on record
  12. Carry out a fundamental rights impact assessment before deployment
  13. Deployers must use the provider's transparency information in their data protection impact assessment
  14. Process personal data only with valid consent or a legitimate use, after notice
  15. Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
  16. Collect and use personal information only with consent and for the stated purpose
  17. Employers and employment agencies must disclose the data collected and their retention policy for the tool
  18. Identify consent or an applicable PDPA exception before using personal data in AI
  19. Operators of high-impact AI should assess its impact on fundamental rights before use
  20. Conduct a data protection impact assessment for high-risk processing using new technologies
  21. Carry out a data protection impact assessment for high-risk AI processing
  22. Map context, intended use and potential impacts (Map)

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The DOCX and XLSX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Check the duties against your situation. The "AI questions" and "Privacy and impact duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  4. 4Complete the document. Work through the DOCX sections (AI supplement to a data protection impact assessment, Duties on record) and replace each placeholder with your organisation's answer.
  5. 5Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (11)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

Version history

Versions of AI Supplement to a Data Protection Impact Assessment
VersionBuiltDatasetWhat changed
v1c6967b988bb5First version, built from dataset c6967b988bb5.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Supplement to a Data Protection Impact Assessment?

Fifteen questions in nine areas, each with answer, risk rating and mitigation. Document version with a section per area. Privacy and impact-assessment duties sheet.

Which duties does it cite?

11 recorded duties from EU AI Act, India DPDP Act, Nepal Privacy Act 2075 and NYC Local Law 144 (automated employment decision tools), including Article 27, Article 26(9), Sections 4 to 7, Section 10, Chapter on collection and protection of personal information (reviewer to cite sections) and NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303. Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on deployer / user organisation, provider / developer and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the DOCX and XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.