Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework

Metin, Bilgin, Yey, Nazli Elif and Wynn, Martin G ORCID logoORCID: https://orcid.org/0000-0001-7619-6079 (2026) Addressing Data Protection Impact Assessment (DPIA) Implementation Challenges in AI-Driven Digitalisation: A Systematic Review and PDCA-Based Governance Framework. Information, 17 (7). doi:10.3390/info17070679

[thumbnail of 16432 Metin et al (2026) Addressing Data Protection Impact Assessment (DPIA).pdf]
Preview
Text
16432 Metin et al (2026) Addressing Data Protection Impact Assessment (DPIA).pdf - Published Version
Available under License Creative Commons Attribution 4.0.

Download (4MB) | Preview

Abstract

AI-driven digitalisation transforms how organisations process personal data and introduces risks that traditional Data Protection Impact Assessment (DPIA) frameworks cannot adequately address. Automated decision-making and large-scale processing in AI, IoT, big data analytics, and blockchain environments create privacy concerns beyond the scope of existing DPIA methodologies. The EU AI Act extends this scope through the Fundamental Rights Impact Assessment (FRIA) under Article 27, which links data protection obligations to broader fundamental rights governance. This study addresses these gaps through a two-phase research design. Phase 1 conducts a systematic literature review of 25 studies and applies framework analysis to identify DPIA implementation challenges across four categories: legal and regulatory, risk assessment, scope, and complexity. AI-specific challenges appear across all four categories. Phase 2 develops a governance framework built on the Plan-Do-Check-Act (PDCA) cycle and organised through a four-level hierarchy of Lifecycle Phase, Risk Management Domain, Control Objective, and Operational Activity. The framework translates relevant requirements of ISO 31000:2018, ISO/IEC 27701:2025, and ISO/IEC 29134:2023 into traceable activities and encompasses algorithmic fairness and socio-ethical impacts. The actionable DPIA framework supports compliance with the GDPR, the EU AI Act and the three ISO standards and will be of interest to company practitioners and other researchers investigating the theoretical and practice-based aspects of digitalisation and data privacy.

Item Type: Article
Article Type: Article
Additional Information: This article belongs to the Special Issue New Information Communication Technologies in the Digital Era, 2nd Edition
Uncontrolled Keywords: General data protection regulation; GDPR; Data protection impact assessment; DPIA; Privacy impact assessment; PIA; Data protection; Technological advancements; Personal data processing; AI; Artificial intelligence; AI-driven digitalisation
Subjects: Q Science > Q Science (General) > Q336 Artificial intelligence
Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Q Science > QA Mathematics > QA76 Computer software > QA76.9 Other topics > QA76.9.B45 Big data
Divisions: Schools and Research Institutes > School of Business, Computing and Social Sciences
Depositing User: Martin Wynn
Date Deposited: 20 Jul 2026 11:34
Last Modified: 21 Jul 2026 09:30
URI: https://eprints.glos.ac.uk/id/eprint/16432

University Staff: Request a correction | Repository Editors: Update this record

University Of Gloucestershire

Bookmark and Share

Find Us On Social Media:

Social Media Icons Facebook Twitter YouTube Pinterest Linkedin

Other University Web Sites

University of Gloucestershire, The Park, Cheltenham, Gloucestershire, GL50 2RH. Telephone +44 (0)844 8010001.