← Back to blog

Who Should Write the DPIA When a Supplier Builds Your AI System?

Your firm owns the data protection impact assessment and signs it. But most of the facts in it come from the companies that build or supply the system: where the data goes, how long it's kept, who can see it. Getting it right means collecting those facts from each company, checking them, and keeping them current as the project moves. A supplier that does that work in your format leaves your team to review and sign.

What is a DPIA, and do we need one?

A data protection impact assessment, or DPIA, is a written check done before a new system goes live. It sets out what personal data the system uses, what could go wrong for the people concerned, and what you're doing about it.

GDPR requires one where the processing is likely to be high risk, and it names new technology as a reason to look closely (Article 35(1)). It's always required for some uses, including automated decisions with significant effects on people, and large-scale use of sensitive data such as health information (Article 35(3)). An AI system that handles client files, meeting recordings or health details will often need one. The Data Protection Commission's guidance is to do it as early as you can, while the design can still change.

Why does it need to be right?

Because it's your firm's record. GDPR calls your firm the controller, and the Data Protection Commission's guidance says the controller stays accountable for the DPIA even when someone else drafts it. If the Commission asks to see it, your firm answers for it.

Because it's only useful if it describes the system you actually run. Picture a DPIA that says meeting recordings are deleted after 30 days, when the tool keeps them until someone deletes them by hand. That's worse than no assessment: it shows you thought about the risk and got the answer wrong.

And because it's the cheapest place to find a problem. If the DPIA shows a tool sends data outside the EU, that's a settings change or a contract question before launch. Found after launch, the same thing can mean a difficult conversation with clients.

Why is it harder when several companies are involved?

Most AI projects in a small firm involve more than one company. There's the AI vendor whose tool you're adopting. There may be a company that hosts or connects it to your systems, a specialist like us building the parts around it, and your own data protection adviser. Each knows part of the picture.

The facts the DPIA needs are spread across contracts, technical documents, settings screens and people's memories. And they change during the project. Halfway through, a vendor adds a subcontractor for transcription, or moves its hosting to a new region. If nobody carries that through, the DPIA describes a system that no longer exists.

How do we make sure the right information reaches it?

When we support an implementation, including one where the AI comes from another company, we keep one record of the facts and make the DPIA draw from it.

  1. Map the system. We set out every step client data takes: what goes in, which company or tool handles it, where it's stored, for how long, and who can reach it.
  2. Get each fact from its source. We put the same written questions to every vendor and keep their answers with their contracts and terms. Where a vendor's answer and its contract disagree, we raise it before it reaches the DPIA.
  3. Check the live system. Settings, storage locations and retention are checked in the system itself, as well as in the documents.
  4. Write it in your format. If your firm or your data protection adviser has a template, we use it and keep its questions word for word, so your reviewer can work through it in their own order. Each new version is built from the copy you last sent back, so your edits stay in.
  5. Account for every question. Every question in your template gets an answer. Anything still open is listed with an owner and a date.
  6. Name the evidence. Each piece of supporting evidence is named, with who provides it: we hand it over, you already hold it, or you need to get it.
  7. Keep it current. When something changes, such as a new vendor feature, a new data source or a new storage region, we update the record and the DPIA follows. GDPR expects a review when the risk changes (Article 35(11)).

What should a supplier provide, and what stays out?

A supplier should provide the facts only it holds: how data flows through its part of the system, where it's hosted, how long it's kept, which subcontractors it uses, and the results of any security testing. Where a supplier processes personal data for you, GDPR requires your contract with it to oblige it to help with the DPIA (Article 28(3)(f)). If a supplier builds a system and hands it over without processing any data, write that duty into the build contract anyway.

Some things stay out: hours, costs and day rates. They belong in the supplier's own records. The actions in your DPIA should say what has to happen, who owns it and what evidence will show it's done.

Who signs it?

Your firm. If you have a data protection officer, GDPR requires you to get their advice when carrying out the assessment (Article 35(2)), and the Data Protection Commission's guidance says to record that advice. If a high risk remains after everything you've put in place, you have to consult the Commission before the system goes live (Article 36(1)).

How does this save time?

Done this way, your team answers a handful of questions and reviews a document that's already accurate. Your adviser reviews it in their own format. And the next AI project starts from a record that already exists.

We covered the wider question of AI and data protection in Can a Regulated Firm Use AI Without Breaching GDPR?, and one common case in Can You Keep Client Documents and Meeting Notes Together in an AI Tool?. The rest of our method is on our how we build page.

If you want an honest picture of where your firm stands first, our free AI Readiness Self-Assessment takes ten minutes. A dploy.ai AI Operations Assessment covers this ground properly and maps where AI pays back for your business, for a fixed fee agreed before we start. Or book a short call and talk it through first.

This is practical guidance and not legal advice. A firm facing a high-risk assessment, or a question about consulting the Data Protection Commission, should take its own.

Want to know where AI fits in your business?

We run a structured assessment that identifies your highest-value AI opportunities. Fixed price, agreed before we start, delivered within ten working days.

Book a free 15-minute call