DPIAs and international transfers

Lesson 5 of 6 in Privacy and Data Protection Law for AI: GDPR from Scratch.

Two more GDPR machines complete your toolkit, and both run constantly in AI programs.

The DPIA. Article 35 requires a data protection impact assessment before any processing "likely to result in a high risk" to people’s rights and freedoms — and Article 35(3)(a) names the AI case explicitly: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions with legal or similarly significant effects are based. The Article 29 Working Party’s guidance (WP248) adds nine risk criteria — evaluation or scoring, automated decisions with significant effect, systematic monitoring, sensitive data, large scale, matching datasets, vulnerable subjects, innovative technology, and blocking rights or services. Rule of thumb: two or more criteria → do a DPIA. Almost every consequential AI deployment trips at least two ("innovative technology" plus nearly anything else).

A DPIA is not paperwork theatre: describe the processing, assess necessity and proportionality, identify risks to individuals, and specify mitigations. If high residual risk remains, Article 36 forces prior consultation with the supervisory authority before you launch. If this sounds like the AI Act’s FRIA, the resemblance is deliberate — the AI Act says deployers may fold the FRIA into an existing DPIA process, which is why privacy teams often own AI impact assessment operationally.

Transfers. Chapter V forbids moving personal data outside the EEA unless protection travels with it. Three routes: an adequacy decision (the Commission certifies a country’s law as essentially equivalent — the UK, Japan, and the EU–US Data Privacy Framework for certified US companies), appropriate safeguards (chiefly standard contractual clauses plus, since Schrems II, a documented transfer impact assessment of the destination country’s surveillance law), or narrow derogations.

Why this is an AI topic: training pipelines are global. Data scraped or collected in Europe, preprocessed by contractors elsewhere, trained on US or Asian GPU clusters, served worldwide — every hop is a transfer. In Schrems II (C-311/18, 2020) the CJEU annulled the Privacy Shield because US surveillance law defeated the promised protection, stranding thousands of companies mid-transfer overnight. Its successor, the Data Privacy Framework, took effect in 2023 and survived its first General Court challenge in 2025 — but it rests on US executive commitments that can change, so mature programs keep SCC fallbacks ready.

Is a DPIA required for your AI system?

  1. New AI processing of personal data
  2. Art 35(3) listed case? Systematic evaluation with significant effects, large-scale special categories, or public monitoring
  3. Two or more WP248 criteria? (scoring, monitoring, sensitive data, large scale, vulnerable subjects, innovative tech…)
  4. DPIA required before processing

    Describe processing → assess necessity and proportionality → identify risks to individuals → mitigate. Combine with FRIA where the EU AI Act applies.

  5. High residual risk after mitigation?
  6. Art 36: consult the supervisory authority before launch
  7. Document the DPIA and proceed; revisit on substantial change
  8. No DPIA strictly required — record the screening decision anyway

Privacy law milestones that shaped AI governance

  • 1973-07-01US HEW report births Fair Information Practices:

    The principles governing automated personal-data systems — notice, access, correction, security — become the DNA of every privacy law that follows.

  • 1980-09-23OECD Privacy Guidelines:

    The first international data-protection framework — the template for cross-border governance of information technology, four decades before the same body wrote AI principles.

  • 1995-10-24EU Data Protection Directive 95/46/EC:

    Article 15 already grants a right not to be subject to purely automated decisions — the direct ancestor of GDPR Art 22 and, eventually, the AI Act’s Art 86.

  • 2016-04-14GDPR adopted:

    Automated decision-making rules (Art 22), DPIAs, and extraterritorial reach — the regulatory architecture the AI Act would later borrow wholesale.

  • 2018-05-25GDPR becomes applicable:

    Art 22 automated-decision rights go live across the EU — the first binding, enforceable constraints most AI systems ever met.

  • 2023-03-31Italy temporarily bans ChatGPT:

    The Garante suspends the service over GDPR concerns — first proof that existing privacy law already reaches generative AI, no new statute required.

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.