AI Supplement to a Data Protection Impact Assessment
In brief
The AI Supplement to a Data Protection Impact Assessment is a free DOCX and XLSX assessment for EU AI Act. Fifteen AI-specific questions to add to a DPIA (inferences, training on personal data, accuracy across groups, automated decisions, model attacks, suppliers), with the privacy and impact-assessment duties on record. It is licensed CC BY 4.0 and is not legal advice.
- Format
- DOCX and XLSX · Assessment
- Version
- v1, built 5 Oct 2026
- Duties cited
- 11 from 9 instruments
- Rows from the records
- 26
- Frameworks
- EU AI Act
- Written for
- Deployer / user organisation, Provider / developer, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Fifteen questions in nine areas, each with answer, risk rating and mitigation
- Document version with a section per area
- Privacy and impact-assessment duties sheet
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: AI questions
| Area | Question to add to the DPIA | Answer | Risk ▾ | Mitigation |
|---|---|---|---|---|
| Purpose and necessity | What decision or output does the AI system produce, and why is AI necessary for it? | |||
| Purpose and necessity | Could the same purpose be met with less personal data or without AI? | |||
| Data | Which personal data trains, tunes or grounds the model, and what is its lawful basis? | |||
| Data | Does the system infer new personal data (for example characteristics, preferences or risk scores)? | |||
| Data | Is special-category or children's data used or inferred? | |||
| Data | Can personal data be extracted from the model or its outputs? |
Questions specific to AI processing, to answer alongside the standard data protection impact assessment.
Sheet: Privacy and impact duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Carry out a fundamental rights impact assessment before deployment | Impact assessment | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 27 | 2027-12-02 | Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers | Fundamental rights impact assessment report | Clause 6.1.4 AI system impact assessment; Annex A control on impact assessment | MAP 5.1, MAP 5.2 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-fundamental-rights-impact-assessment |
| Deployers must use the provider's transparency information in their data protection impact assessment | Privacy and personal-data protection | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 26(9) | 2027-12-02 | Where a deployer of a high-risk AI system is required to carry out a data protection impact assessment under Article 35 of the GDPR or Article 27 of the Law Enf | Data protection impact assessment citing the provider's Article 13 information | Clause 6.1.4; Annex A.5.2 | MAP 3.1, MEASURE 2.10 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-26-9-dpia-using-provider-information |
| Process personal data only with valid consent or a legitimate use, after notice | Privacy and personal-data protection | India DPDP Act | India | Provider / developer, Deployer / user organisation | Legal requirement | Sections 4 to 7 | Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses | Consent records and notices | Annex A controls on data for AI systems | Source-linked | https://aipolicytracker.org/obligations/india-dpdp-consent-and-notice | ||
| Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits | Impact assessment | India DPDP Act | India | Provider / developer, Deployer / user organisation | Legal requirement | Section 10 | Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protecti | Data protection impact assessment | Clause 6.1.4 AI system impact assessment | Source-linked | https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties | ||
| Collect and use personal information only with consent and for the stated purpose | Privacy and personal-data protection | Nepal Privacy Act 2075 | Nepal | Provider / developer, Deployer / user organisation, Public authority / government body | Legal requirement | Chapter on collection and protection of personal information (reviewer to cite sections) | Personal information may be collected only by authorised persons for a lawful purpose with the individual's consent, and must not be used or disclosed for other | Consent and purpose records | Annex A controls on data for AI systems | Source-linked | https://aipolicytracker.org/obligations/nepal-privacy-act-consent-and-purpose | ||
| Employers and employment agencies must disclose the data collected and their retention policy for the tool | Privacy and personal-data protection | NYC Local Law 144 (automated employment decision tools) | New York (United States) | Deployer / user organisation | Legal requirement | NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303 | 2023-07-05 | Unless already disclosed on the website, an employer or employment agency must provide, within 30 days of a written request from a candidate or employee, inform | Data collection and retention notice for the tool; Request response log | Annex A.7.2, A.8.5 | MAP 2.2, MEASURE 2.10 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-data-policy-disclosure |
The recorded privacy and impact-assessment duties for AI systems.
Document outline (DOCX)
- AI supplement to a data protection impact assessment
- Purpose and necessity
- Data
- Accuracy and fairness
- Automated decisions
- Transparency
- Rights
- Security
- Suppliers
- Monitoring
- Duties on record
- Carry out a fundamental rights impact assessment before deployment
- Deployers must use the provider's transparency information in their data protection impact assessment
- Process personal data only with valid consent or a legitimate use, after notice
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
- Collect and use personal information only with consent and for the stated purpose
- Employers and employment agencies must disclose the data collected and their retention policy for the tool
- Identify consent or an applicable PDPA exception before using personal data in AI
- Operators of high-impact AI should assess its impact on fundamental rights before use
- Conduct a data protection impact assessment for high-risk processing using new technologies
- Carry out a data protection impact assessment for high-risk AI processing
- Map context, intended use and potential impacts (Map)
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The DOCX and XLSX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Check the duties against your situation. The "AI questions" and "Privacy and impact duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 4Complete the document. Work through the DOCX sections (AI supplement to a data protection impact assessment, Duties on record) and replace each placeholder with your organisation's answer.
- 5Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (11)
Each is cited in the file with its source reference and a link back to the record.
- Carry out a fundamental rights impact assessment before deployment
- Deployers must use the provider's transparency information in their data protection impact assessment
- Process personal data only with valid consent or a legitimate use, after notice
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits
- Collect and use personal information only with consent and for the stated purpose
- Employers and employment agencies must disclose the data collected and their retention policy for the tool
- Identify consent or an applicable PDPA exception before using personal data in AI
- Operators of high-impact AI should assess its impact on fundamental rights before use
- Conduct a data protection impact assessment for high-risk processing using new technologies
- Carry out a data protection impact assessment for high-risk AI processing
- Map context, intended use and potential impacts (Map)
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | c6967b988bb5 | First version, built from dataset c6967b988bb5. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Supplement to a Data Protection Impact Assessment?
Fifteen questions in nine areas, each with answer, risk rating and mitigation. Document version with a section per area. Privacy and impact-assessment duties sheet.
Which duties does it cite?
11 recorded duties from EU AI Act, India DPDP Act, Nepal Privacy Act 2075 and NYC Local Law 144 (automated employment decision tools), including Article 27, Article 26(9), Sections 4 to 7, Section 10, Chapter on collection and protection of personal information (reviewer to cite sections) and NYC Administrative Code Section 20-871(b)(3); 6 RCNY Section 5-303. Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on deployer / user organisation, provider / developer and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the DOCX and XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 5 October 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.