Skip to content
GDPRDPIAArticle 35Article 36WP248AI systems

DPIA Screening Criteria for AI Systems

The nine WP248 criteria for a GDPR Art. 35 DPIA, how they behave when an AI system is involved, and when Art. 36 prior consultation is possible.

Landfall ยท Published 5 September 2026

Whether a data protection impact assessment is required is a question the GDPR answers with a standard, not a list: Art. 35(1) requires one where processing is likely to result in a high risk to the rights and freedoms of natural persons. To make that workable, the Article 29 Working Party published nine screening criteria in its guidelines WP248 rev.01, which the European Data Protection Board has endorsed. This article sets out the nine, explains how they behave once an AI system is in the picture, and describes the narrow case where prior consultation with the supervisory authority under Art. 36 comes into play.

The nine criteria

WP248 rev.01 lists nine indicators of high risk:

  1. Evaluation or scoring, including profiling and predicting, especially of aspects such as performance at work, economic situation, health, interests or behaviour.
  2. Automated decision-making with legal or similarly significant effect.
  3. Systematic monitoring of people, including in publicly accessible areas.
  4. Sensitive data or data of a highly personal nature, including the Art. 9 special categories and data such as location or financial records.
  5. Data processed on a large scale.
  6. Matching or combining datasets from different processing operations, in a way the data subject would not reasonably expect.
  7. Data concerning vulnerable data subjects, such as children, employees, patients, asylum seekers or people in a position of imbalance with the controller.
  8. Innovative use or application of new technological or organisational solutions.
  9. Processing that prevents data subjects from exercising a right or using a service or contract.

The guidelines say that in most cases a controller can consider that processing meeting two criteria requires a DPIA, and that in some cases one criterion suffices. The criteria do not replace Art. 35(3), which names three cases where a DPIA is always required: systematic and extensive evaluation based on automated processing including profiling with legal or similarly significant effects; large-scale processing of special categories or criminal data; and large-scale systematic monitoring of a publicly accessible area.

The Dutch list

Art. 35(4) lets each supervisory authority publish its own list of processing operations that always require a DPIA. The Autoriteit Persoonsgegevens has done so. The list includes categories such as profiling, fraud prevention, creditworthiness assessment, covert investigation, monitoring of employees, camera surveillance and large-scale processing of biometric or health data. A processing operation on that list requires a DPIA whatever the WP248 count says. Treat the AP list as a separate check, and check the current version; it is the authority's list, not the guidelines'.

How AI changes the screening

An AI system moves the count in three ways.

First, criterion 8 is almost always met. An AI system is, for the purposes of the screening, an innovative use of a new technology, and the guidelines say so explicitly. That means an AI system starts at one criterion before anyone looks at what it does.

Second, criterion 1 is met whenever the system evaluates or scores people. Most operational AI in a public body does exactly that: it ranks, flags, predicts or prioritises. The combination of criteria 1 and 8 is two criteria, which is the guidelines' threshold.

Third, criterion 2 depends on whether a person meaningfully reviews the output. GDPR Art. 22 restricts decisions based solely on automated processing with legal or similarly significant effects. A caseworker who only counter-signs is not meaningful human involvement. If the system decides, criterion 2 is met and a DPIA is due regardless of the count.

The practical consequence for screening: an AI system that processes personal data should never be screened out by a questionnaire alone. The honest outcome for a system with no other criterion is "review", not "no DPIA".

What the AI Act adds

The AI Act does not create a second DPIA. It connects to the existing one at two points. Art. 26(9) requires deployers of high-risk systems to use the information the provider supplies under Art. 13 when carrying out the GDPR DPIA. Art. 27(4) says that where the DPIA already covers part of the fundamental rights impact assessment, the FRIA complements it. In practice one assessment record can carry both, with a section map showing which element each section satisfies.

When prior consultation is possible

Art. 36(1) requires the controller to consult the supervisory authority before processing where the DPIA indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk. The authority responds within eight weeks, extendable by six for complex cases, and can use any of its Art. 58 powers. Art. 36(5) also lets Member State law require consultation for processing carried out in the public interest.

The trigger is residual risk after mitigation. That is something only a completed DPIA can show. No questionnaire answer can establish it, so a screening tool can only ever say "possible" or "not indicated", never "required". A report that told a municipality to consult the AP before any DPIA had been run would be sending it to the regulator with nothing to say.

A worked example

The fictional municipality of Veenhorst wants a model that predicts which residents are at risk of falling behind on municipal taxes, so that a debt counsellor can reach out early. The DPO runs the screening.

Criterion 1: yes, it scores residents. Criterion 4: financial data, yes. Criterion 6: it combines tax records with social-support records, which residents would not expect. Criterion 7: residents in financial difficulty are in a position of imbalance with the municipality. Criterion 8: a new model. Five criteria; a DPIA is clearly required. Criterion 2: no, a counsellor decides whether to make contact, and the contact carries no legal effect. The AP list: profiling is on it, so the DPIA was required on that ground alone.

The DPIA finds that the risk of stigmatising households can be reduced by removing the ethnicity-correlated postcode feature, by contacting people only with an offer of help, and by deleting scores after ninety days. The residual risk is judged acceptable, so no Art. 36 consultation is needed. Had the municipality wanted to use the score to withhold a payment arrangement, the residual risk would have looked different, and consultation would be on the table.

How Landfall helps

Landfall asks the nine WP248 criteria by name so that the screening is auditable against the guideline, and asks separately whether decisions are taken by automated means alone. Two criteria, or a solely automated decision with legal effect, produce a "DPIA required" row with its basis printed. One criterion, an unsure answer, or an AI system with nothing else selected produce "requires review", because an AI system never screens out on answers alone. The Art. 36 row is never "yes" from screening; it is "no" when no DPIA is indicated and "review" otherwise, since only the completed DPIA can establish residual risk. Landfall does not model the AP's national list, and says so.

Explore the underlying obligations

This article is grounded in the obligations Landfall maps from source legal text. Browse them yourself:

Questions this article answers

How many WP248 criteria trigger a DPIA?
The guidelines say that in most cases processing meeting two criteria will require a DPIA. One criterion can be enough where the risk is clearly high. The criteria are a screening aid; Art. 35(1) itself asks whether the processing is likely to result in a high risk.
Does using AI automatically require a DPIA?
Not automatically, but nearly. Innovative use of a new technology is itself criterion 8, and AI systems usually also evaluate or score people (criterion 1). Two criteria met normally means a DPIA. An AI system should not be screened out on a questionnaire alone.
What is prior consultation under Art. 36?
Where the DPIA shows the processing would still result in a high risk after the planned measures, the controller consults the supervisory authority before processing. The authority has eight weeks to respond, extendable by six. It cannot be decided from screening; only the completed DPIA can show residual risk.
Does the Autoriteit Persoonsgegevens have its own list?
Yes. Under Art. 35(4) the AP publishes a list of processing operations for which a DPIA is always required in the Netherlands. It includes categories such as profiling, fraud prevention, monitoring of employees and processing of biometric data. Check the current list; it applies independently of the WP248 screening.

Sources

For informational purposes only. This guide is summary-level, informational writing โ€” not legal advice, not a risk score, and not regulatory approval. It does not create an attorney-client relationship. Always consult qualified legal counsel for compliance decisions about your specific product.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations