Systematic review identifies DPIA challenges in AI contexts, developing a PDCA-based governance framework.
AI-driven digitalisation transforms how organisations process personal data and introduces risks that traditional Data Protection Impact Assessment (DPIA) frameworks cannot adequately address. Automated decision-making and large-scale processing in AI, IoT, big data analytics, and blockchain environments create privacy concerns beyond the scope of existing DPIA methodologies. The EU AI Act extends this scope through the Fundamental Rights Impact Assessment (FRIA) under Article 27, which links data protection obligations to broader fundamental rights governance. This study addresses these gaps through a two-phase research design. Phase 1 conducts a systematic literature review of 25 studies and applies framework analysis to identify DPIA implementation challenges across four categories: legal and regulatory, risk assessment, scope, and complexity. AI-specific challenges appear across all four categories. Phase 2 develops a governance framework built on the Plan-Do-Check-Act (PDCA) cycle and organised through a four-level hierarchy of Lifecycle Phase, Risk Management Domain, Control Objective, and Operational Activity. The framework translates the requirements of ISO 31000:2018, ISO/IEC 27701:2025, and ISO/IEC 29134:2023 into traceable activities and encompasses algorithmic fairness and socio-ethical impacts. The actionable DPIA framework supports compliance with the GDPR, the EU AI Act and the three ISO standards and will be of interest to company practitioners and other researchers investigating the theoretical and practice-based aspects of digitalisation and data privacy.
No takes yet. Share an insight, caveat, or question.
Metin et al. (2026) studied this question.
Synapse has enriched 4 closely related papers on similar clinical questions. Consider them for comparative context: