Back to docs
Research Operations

DPIA for User Research: When You Need One and How to Write It (2026)

A practical guide to Data Protection Impact Assessments for customer and user research: the Article 35 triggers, the WP29 nine criteria, what belongs in each section, and a worked example for AI-moderated interviews.

The short answer

Most one-off user research does not require a DPIA. Research programs that record people, run at scale, use AI to moderate or analyse, or touch sensitive topics usually do. A Data Protection Impact Assessment (DPIA) is the GDPR's structured way of asking "could this processing hurt the people in it, and what have we done about that?" Article 35 makes it mandatory whenever processing is "likely to result in a high risk to the rights and freedoms of natural persons."

The practical test used across the EU comes from the Article 29 Working Party (now the EDPB): score your study against nine risk criteria. Hit two or more, and you should assume a DPIA is required. A recorded, AI-moderated interview study with EU participants routinely hits three or four — which is why research teams that adopted AI interviewing in 2025 and 2026 are being asked for DPIAs they have never written before.

This guide gives you the triggers, the required contents, a seven-step process, and a worked example you can adapt.

What a DPIA actually is

A DPIA is a documented risk assessment carried out before processing begins. It is not a legal opinion, a security review, or a privacy policy. It is a written record showing that you identified the risks to participants, weighed them against your purpose, and reduced them.

Three things follow from that definition, and teams get all three wrong:

  • It is prospective. Article 35 and the data-protection-by-design principle both require the assessment in advance. A DPIA written after launch is remediation, not compliance.
  • It is about the participant, not the company. The risk you assess is risk to the person being interviewed — re-identification, exposure of a sensitive disclosure, loss of control over their words. Not your brand risk.
  • It is a living document. If you change methodology, add voice recording, or start using a new analysis vendor, you revisit it.

When a DPIA is required

Article 35(3) names three situations where a DPIA is always required:

  1. Systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where decisions produce legal or similarly significant effects.
  2. Large-scale processing of special category data (Article 9) — health, race, religion, political opinion, sex life, biometrics — or criminal conviction data.
  3. Systematic monitoring of a publicly accessible area on a large scale.

Beyond those, the WP29 guidelines give nine criteria that indicate high risk:

#CriterionCommon research trigger
1Evaluation or scoringScoring or ranking participants, quality-rating responses
2Automated decision-making with legal or significant effectAuto-screening applicants or customers out
3Systematic monitoringAlways-on feedback capture, session monitoring
4Sensitive data or data of a highly personal natureHealth, finances, workplace grievances, trauma
5Data processed on a large scaleHundreds or thousands of participants
6Matching or combining datasetsJoining interview data to CRM or product analytics
7Data concerning vulnerable subjectsChildren, patients, employees, asylum seekers
8Innovative use or new technological solutionsAI-moderated interviews, voice analysis, LLM synthesis
9Processing that prevents subjects exercising a rightBarriers to withdrawing consent or requesting deletion

The rule of thumb regulators apply: two or more criteria means do the DPIA. Where you are genuinely unsure, do it anyway — it is cheaper than defending the decision not to.

Four research scenarios that almost always trigger one

  • AI-moderated interviews at scale with EU participants. Criteria 5 and 8 at minimum; add 4 if the topic is personal. This is the single most common trigger in 2026.
  • Employee research. Employees are vulnerable subjects (criterion 7) because consent is rarely freely given in an employment relationship. Add sensitive topics and you are at three.
  • Health, financial, or minor-facing research. Special category data or children — often mandatory under 35(3) alone.
  • Research joined to behavioural data. Matching interview transcripts to product analytics or CRM records is criterion 6.

Conversely: a five-person moderated usability test on a checkout flow, unrecorded, notes anonymised immediately, is not high risk. Do not burn a DPIA on it. Document the screening decision instead.

What goes in a DPIA

Article 35(7) sets four mandatory elements. Everything else is your own structure.

  1. A systematic description of the processing — purposes, categories of data, categories of participants, recipients, retention periods, international transfers, and your legal basis.
  2. An assessment of necessity and proportionality — why you need this data to answer this question, and why a less intrusive method would not do.
  3. An assessment of the risks to participants' rights and freedoms.
  4. The measures envisaged to address those risks, including safeguards and security measures.

A workable research DPIA runs 4-8 pages. Longer usually means you have pasted in vendor marketing.

The necessity-and-proportionality section is where DPIAs fail

This is the section auditors actually read, and the one teams skip. It has to answer: could you have learned this without collecting this data? Concretely — do you need full-name identifiers, or would a pseudonymous participant ID do? Do you need video, or is audio enough? Do you need audio retained, or just the transcript? Every "no, we do not need that" you write here removes risk from every later section.

The seven-step process

  1. Screen. Score against the nine criteria. Record the score and the decision even when the answer is "no DPIA needed" — the screening record is itself evidence of accountability.
  2. Describe the processing. Data flow from recruitment through to deletion. Name every system that touches participant data, including transcription and analysis.
  3. Consult. Article 35(9) says seek the views of data subjects "where appropriate." For research, a short question in your pilot round covers this cheaply. Involve your DPO if you have one — that consultation is mandatory under 35(2).
  4. Assess necessity and proportionality. Justify each field you collect against the research question.
  5. Identify and score risks. Likelihood x severity, from the participant's point of view.
  6. Identify mitigations and record the residual risk after each.
  7. Sign off and review. Named owner, date, and a review trigger tied to methodology changes.

Risk and mitigation table you can reuse

Risk to participantLikelihoodSeverityMitigationResidual
Re-identification from quoted transcriptMediumHighPseudonymous IDs; strip names, employers, rare job titles before sharing; review quotes before they enter reportsLow
Voice recording reused beyond stated purposeLowHighPurpose limitation in consent; audio deleted at 30-90 days; transcripts retained insteadLow
Sensitive disclosure captured incidentallyMediumHighTopic guardrails in the interview script; participants told they may skip any question; redaction pass before analysisLow
Participant cannot withdrawLowMediumWithdrawal contact in the consent screen; documented deletion path with SLALow
Cross-border transfer without safeguardsMediumMediumDocumented transfer mechanism and processing locationsLow

Where AI-moderated research changes the analysis

Criterion 8 — "innovative use of new technological solutions" — is not a formality. When an AI moderates the conversation, two things genuinely change:

The interview is adaptive, not fixed. A human-written script is auditable in advance; an AI that generates follow-up questions is not. Your DPIA should describe the guardrails rather than the exact questions: the topic scope the AI is instructed to stay within, whether it is permitted to probe on sensitive areas, and what it does when a participant volunteers something out of scope.

Analysis is automated. If a model summarises, themes, or scores responses, say so, and say whether any of that produces a decision about the individual. In most product research it does not — the output is aggregate insight, not a decision about the participant — and stating that plainly is often what closes the review.

This is also where the EU AI Act now interacts with your DPIA. Article 26 obligations for deployers of certain AI systems and the transparency duty to tell people they are interacting with an AI sit alongside, not instead of, your GDPR work. The clean pattern is one paragraph in the DPIA cross-referencing your AI Act position — see the EU AI Act and user research for the classification detail.

How Koji makes this section easy to write

Most of a research DPIA is a description of what the tool does with participant data. That is far easier to write when the platform is built for research rather than adapted from a meeting tool.

With Koji, the description section writes itself along these lines: participants join a link-based AI-moderated interview by text or voice; the AI asks a defined set of questions and probes within a scoped topic; responses are transcribed and analysed automatically into an aggregate report; no human moderator is present, which removes an entire category of incidental disclosure to staff.

Two design choices in particular reduce risk before you mitigate anything:

  • Structured questions constrain what gets collected. Koji supports six question types — open_ended, scale, single_choice, multiple_choice, ranking, and yes_no. Every question you convert from open-ended to scale, single_choice, or yes_no collects a bounded value instead of free text that might contain anything. That is data minimisation implemented in the study design, not promised in a policy. See the structured questions guide.
  • No moderator means no incidental audience. In a traditional study, a moderator, a notetaker, and often observers hear every word. Koji's AI runs the session and produces aggregate analysis, so fewer humans see raw disclosures.

Because studies run asynchronously and analysis is automatic, teams also stop the worst privacy habit in research: keeping recordings "just in case" because nobody has had time to analyse them. When reports generate automatically, short retention becomes realistic — and short retention is the mitigation that does the most work in any DPIA.

Prior consultation: the step nobody plans for

If, after mitigation, residual risk is still high, Article 36 requires you to consult your supervisory authority before processing. Expect that to add weeks. In practice, research studies almost never reach this point — but the way to guarantee you avoid it is to mitigate down to acceptable residual risk in step 6, not to quietly downgrade your own risk scores.

Five common mistakes

  1. Treating the DPIA as a vendor questionnaire. Your vendor's SOC 2 report is evidence, not an assessment. The DPIA is about your study.
  2. Writing it after fieldwork starts. It must be prospective.
  3. Assessing company risk instead of participant risk. "Reputational damage to us" is not an Article 35 risk.
  4. Skipping the screening record for low-risk studies. The record of deciding you did not need one is itself accountability evidence.
  5. Never reviewing it. Adding voice to a text-only study, or a new analysis vendor, changes the assessment.

Related Resources

Related Articles

Anonymizing Customer Interview Data: A Practical Guide for Privacy-Safe Research

Five operational techniques for handling PII in AI customer interviews — from intake-time anonymization to stakeholder-safe quote sharing — without sacrificing research signal.

Enterprise Security for AI Customer Research Platforms: SOC 2, SSO, and Vendor Review

A procurement-ready guide to evaluating the security of an AI customer research platform — SOC 2, encryption, SSO/SAML, data residency, sub-processors, and the questions your security team should ask.

The EU AI Act and User Research: What AI-Moderated Interviews Actually Require (2026)

AI-moderated customer interviews sit in the EU AI Act's limited-risk transparency tier, not the high-risk tier. Here is exactly what Article 50 requires from 2 August 2026, the two things that escalate a study to high-risk, and a compliance checklist you can run this week.

GDPR-Compliant AI User Research: A Practical Guide

How to run AI-moderated customer interviews under GDPR. Lawful basis, consent flows, data minimization, retention, sub-processors, and how Koji handles each requirement.

Do You Need IRB Approval for User Research? A 2026 Decision Guide

Most commercial UX and product research does not require IRB approval - but four specific situations flip the answer to yes. Here is the actual regulatory test, the exempt categories, and how to prepare a submission that clears review fast.

Research Consent Form Templates: GDPR-Compliant Forms for Every Study

Ready-to-use consent form templates for user research, UX studies, and AI interviews. Covers GDPR compliance, informed consent best practices, and how to collect consent automatically with Koji.

Research Data Retention and Deletion: How Long Should You Keep Interview Data?

There is no universal legal number - which is exactly why having no retention schedule is itself the compliance failure. A tiered, per-artifact schedule for recordings, transcripts, quotes, and reports, plus how to handle deletion requests without losing your insights.

Structured Questions in AI Interviews

Mix quantitative data collection — scales, ratings, multiple choice, ranking — with AI-powered conversational follow-up in a single interview.