- Tools
- Data protection (GDPR)
DPIA for an AI tool
The screening (art. 35 GDPR, the APD list, the WP248 criteria), its result and reasons, then a DPIA pre-filled for the use chosen, to review and sign.
What the rule says
Rules verified on 07/10/2026
A DPIA is required before a processing likely to result in a high risk (art. 35 GDPR). For a law firm it is not automatically mandatory: an individual lawyer's client data are not large scale (recital 91) and generative AI is not on the APD list.
The APD's guidance considers that two criteria of the WP248 list call for a DPIA in most cases, and generative AI counts as an innovative use. Before the first use of an AI tool with client data, a short DPIA is therefore recommended; if the firm does without, it records why.
- Regulation (EU) 2016/679 (GDPR)
- Belgian DPA (APD/GBA), General Secretariat decision 01/2019 (list of processing that requires a DPIA)
- Belgian DPA (APD/GBA), guidance on the data protection impact assessment (v4.0, 21 April 2021)
- CNIL, privacy impact assessment methodology (PIA, February 2018)
- CNIL, AI factsheet on carrying out an impact assessment (8 April 2024)
- La Tribune (AVOCATS.BE) no. 280, article on generative AI and the GDPR (2025)
- OVB and AVOCATS.BE, Guidelines for lawyers on the use of artificial intelligence (January 2025)
- EDPB, Opinion 28/2024 on certain data protection aspects related to AI models (17 December 2024)
Your DPIA appears here
Answer the screening on the left: the result appears with its reasons, then the DPIA fills in as you go.
A generative AI tool used to summarise client documents.
How it works
How the tool works
- The screening. The mandatory cases of art. 35(3) GDPR, the eight types of the APD list, then the nine criteria of the WP248 list that the APD applies. Generative AI counts as an innovative use: that criterion is ticked by default, to untick for a conventional tool.
- The result. A mandatory case: DPIA mandatory. Two criteria or more: DPIA required. One criterion: DPIA recommended. No criterion but client data: a short DPIA recommended before first use. Otherwise, a DPIA is not required. Where the firm may do without, the tool asks it to record its reasons.
- The context. The tool, the provider, the use (drafting, summaries, translation, transcription, research, the firm's own documents), the data, the persons concerned, the data flow, hosting, retention and training. With the vault open, this information can be taken from the AI tools register.
- The principles. Necessity and proportionality, legal basis, minimisation and pseudonymisation, accuracy, retention, information, rights of the persons concerned, processor, transfers.
- The risks. Ten pre-filled risks (breach of professional secrecy, reuse by the provider, access by foreign authorities or the provider's staff, leakage between matters, security incident, inaccurate output, bias, loss of control, unlawful model), with their measures and a severity and likelihood on the CNIL's four-level scales, to adjust.
- The validation. The residual risk, the advice of the data protection officer if there is one, prior consultation of the APD if a risk stays high (art. 36), the decision, the action plan and the signature.
The DPIA exports to PDF and Word, in the language chosen. With a verified address, it carries your firm's letterhead, and the firm's name is used as the controller.
What the texts say
- GDPR, art. 35: a DPIA is required before a processing likely to result in a high risk, "in particular using new technologies". Recital 91 says that the client data of an individual lawyer are not processed on a large scale.
- APD decision 01/2019: the Belgian list of processing that requires a DPIA. Generative AI is not on it, which does not rule out a DPIA under art. 35.
- APD guidance: in most cases, two criteria of the WP248 list call for a DPIA.
- CNIL AI factsheet: generative AI is an innovative use. CNIL PIA methodology: context, fundamental principles, risks, validation.
- La Tribune of AVOCATS.BE (no. 280) considers a DPIA unavoidable in practice before the first use of a generative AI tool.
Points to watch
- A DPIA is not automatically mandatory for a law firm: the tool recommends one by default before first use with client data, and lets the firm document a reasoned decision not to carry one out.
- One DPIA may cover several similar processing operations and may be reused from a similar processing.
- The severity and likelihood levels offered are a starting point, to review for your case.
What the tool does not do
- It does not consult the APD for you and does not check the provider's statements.
- It sends nothing: your answers stay in this tab's memory.
Verification
The sources were verified on 7 October 2026. The tool assists the lawyer, who remains responsible for the assessment and the decision.
Updated on 7 October 2026
Frequently asked questions
Is a DPIA mandatory before using AI at the firm?
Not automatically. The GDPR requires one where the processing is likely to result in a high risk. For an individual lawyer, client data are not processed on a large scale (recital 91), and generative AI is not on the APD list. But the APD's guidance considers that two criteria call for a DPIA in most cases, and generative AI used on files holding sensitive data often meets two.
What are the criteria?
The nine criteria of the WP248 list, applied by the APD: evaluation or scoring, automated decision, systematic monitoring, sensitive or highly personal data, large scale, matching datasets, vulnerable persons, innovative use, processing that prevents people from exercising a right. For a firm, the most frequent are the sensitive data in files and the innovative use of generative AI.
What if no DPIA is required?
Record the reasons. The APD's guidance asks the controller to explain why a processing that meets some criteria is not considered high-risk. The tool has a field for these reasons, which the document includes.
When must the APD be consulted?
When a risk stays high after the planned measures (art. 36 GDPR). The tool says so as soon as a risk keeps a significant or maximum severity and likelihood.
Can one DPIA cover several tools?
Yes, one assessment can cover similar processing with similar risks, and an existing DPIA can be reused and adapted. The tool notes it if you say so.
In which language is the DPIA written?
In French, Dutch, English or German, as you choose, independently of the site's language. It exports to PDF and Word.