Does an AI system require a data protection impact assessment?
The duty follows from Art. 35 GDPR and depends on the risk of the processing, not on whether artificial intelligence is involved. The data protection check guides you through 94 questions in ten sections and ends with a pre-check on whether an impact assessment is required. It runs as a single file in the browser, without any sign-up.
Does classification under the EU AI Act replace the data protection impact assessment?
No. The two assessments remain separate and rest on different legal bases. However, Art. 26(9) of the EU AI Act explicitly requires deployers to use the provider information on performance limits and types of error in that assessment. This is why both start from the same system context here.
- Evidence
- Impact assessment referencing the provider information
What role does my organisation have under the EU AI Act?
The Act knows seven roles: provider, deployer, importer, distributor, authorised representative, product manufacturer and provider of a general-purpose AI model. Anyone using a bought-in system in their own organisation is normally a deployer. For deployers the obligations compass lists 24 of the 62 obligations.
When does a deployer become a provider?
Under Art. 25(1) a deployer moves into the provider role when it puts the system on the market under its own name, substantially modifies it or changes its intended purpose. With that change the full set of provider obligations applies. This is the most frequently overlooked role change, because nobody in the organisation reports it.
- Evidence
- Note per modification with type of change, assessment and result
Which AI threats directly affect personal data?
The catalogue holds 52 threats, four of them in the privacy group: privacy attacks, disclosure of sensitive information, exfiltration from the machine learning application, and cross-tenant leakage in shared vector databases. Four further threats carry a mapping to the GDPR, eight in total. Each names its mitigations and its verified references.
What information must I require from the provider?
The instructions for use under Art. 13, the information on performance limits and types of error for the impact assessment, access to the logs, and the assurances on data processing. If any of these is missing, the impact assessment cannot be completed: record the gap and request the information from the provider.
Who must I inform about the use, and where?
Affected persons under Art. 26(11) and, for systems at the workplace, the workers and their representatives in advance under Art. 26(7). The information belongs where the decision is made, for example in the application process or the credit decision. A note in the general privacy policy usually does not reach the person concerned.
- Evidence
- Wording and placement of the notice per process
How long must the logs of a high-risk system be kept?
At least six months under Art. 26(6), unless Union or national law requires a longer period. For cloud services, access to those logs is a contractual matter, not a configuration matter: whoever has not agreed it does not have it when it is needed.
- Evidence
- Contractual assurance of log access
Must I carry out a fundamental rights impact assessment under Art. 27?
The duty does not apply to every deployer of a high-risk system, but to the group named in Art. 27. So check first whether you are covered. If your organisation is, the assessment must be carried out and notified to the market surveillance authority.
- Evidence
- Completed assessment and notification to the authority
From when do the obligations for high-risk systems apply?
Since Regulation (EU) 2026/1744, in force since 27 July 2026, the requirements for systems under Annex III apply from 2 December 2027 and for Annex I from 2 August 2028. Two new prohibitions already take effect on 2 December 2026. Many overviews still in circulation quote the earlier dates.
Do the assessment data leave my computer?
No. The application runs in the user’s browser. The working state is saved to a file and read back in; there is no transfer to any service run by the provider. This holds for the free edition, for the single modules and for the offline edition. What that means for your own professional or contractual obligations is for you to assess.
What does the application explicitly not do?
It replaces neither an assessment of the individual case nor legal advice. It keeps no record of processing activities, it notifies nothing to supervisory authorities, and it does not assess data processing agreements. The obligations compass classifies; it does not decide.