EU
Data Protection Impact Assessment
The short answer. A DPIA is required before processing that is likely to result in a high risk to the rights and freedoms of natural persons, under GDPR Article 35(1). Article 35(3) lists the processing that always requires one, and the item that catches voice data at scale is large-scale processing of the special categories in Article 9(1). The assessment has to contain the four elements in Article 35(7). If the residual risk stays high after mitigation, Article 36 requires consultation with the supervisory authority before processing begins.
The law
GDPR Article 35(1)
Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data.
Two things in that sentence matter commercially. It is the controller who carries it out, and it happens before the processing, not after. Training a speech model on a corpus of real speakers is the kind of processing the provision was written for: new technology, at scale, with consequences that are hard to reverse.
GDPR Article 35(3)(b)
processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10.
This is the mandatory trigger to test first, and it has two parts. The data has to be special category, which for voice depends on the purpose rather than the file. And the processing has to be large scale, which the regulation does not define by a number; supervisory authorities look at the number of people, the volume and variety of data, the duration, and the geographic extent. A corpus of tens of thousands of hours from speakers across several countries is not a borderline case on any of those measures.
GDPR Article 35(7)
The assessment shall contain at least: a systematic description of the envisaged processing operations and the purposes of the processing, including, where applicable, the legitimate interest pursued by the controller; an assessment of the necessity and proportionality of the processing operations in relation to the purposes; an assessment of the risks to the rights and freedoms of data subjects referred to in paragraph 1; and the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure the protection of personal data.
The second element is the one that does real work in a data purchase: why this volume, why the raw audio rather than derived features, why this retention period. A DPIA that describes the processing without arguing necessity and proportionality does not satisfy Article 35(7)(b), and it is the most common gap we see in assessments written for dataset projects.
GDPR Article 36(1)
The controller shall consult the supervisory authority prior to processing where a data protection impact assessment under Article 35 indicates that the processing would result in a high risk in the absence of measures taken by the controller to mitigate the risk.
The DPIA is not only a document to file. If the residual risk stays high after the mitigations, the next step is the supervisory authority and the processing waits for the outcome. That is a schedule risk as much as a legal one, and it belongs in the project plan before the recording budget is committed.
Who it applies to
The duty sits on the controller. If you buy a corpus and decide what it is used for, you are the controller for that processing, and you cannot delegate the assessment to the vendor. GDPR Article 28(3)(f) requires a processor to assist the controller with obligations including Articles 32 to 36, which means the vendor supplies facts; it does not mean the vendor writes the assessment.
Two consequences follow for procurement. The vendor's answers are inputs, so the contract has to require them rather than leave them to goodwill. And a DPIA the vendor wrote for its own collection does not cover your training run, because your purpose is different from the purpose it assessed. Copying it across is a common shortcut that leaves the buyer's actual processing unassessed.
Supervisory authorities publish lists of processing types that require a DPIA under Article 35(4). Some national lists name biometric processing and AI training explicitly, and checking the list for the authority you are answerable to is a ten-minute task that occasionally changes the whole plan. Even where the processing is not on a list, Article 35(1) can still require an assessment on the facts.
What it costs to get wrong
Failing to carry out a DPIA infringes Article 35, which falls in the Articles 25 to 39 group under GDPR Article 83(4): administrative fines up to 10 million euros, or in the case of an undertaking, up to 2% of the total worldwide annual turnover of the preceding financial year, whichever is higher. That is the lower of the two tiers, and it is the least of the consequences.
The DPIA is the first document a supervisory authority asks for, and its absence means there is no record that the necessity and proportionality questions were asked at all. Where the processing should have gone to prior consultation under Article 36 and did not, the authority can order the processing stopped, which for a training run strands both the data spend and the compute.
There is a commercial consequence that arrives faster than any regulator. Enterprise customers ask for the DPIA during diligence, and a data vendor selling into regulated sectors is asked for it before the purchase order rather than after. A buyer who cannot produce one usually loses the deal before the legal question is ever tested.
How to comply when you are buying data
A DPIA for a dataset purchase is short if the inputs are available and impossible if they are not. The procurement work is to make the inputs contractual.
- Decide who writes it. If you choose the purpose, that is you. Article 28(3)(f) is the clause that obliges the vendor to give you what you need to write it.
- Get from the vendor: the categories of data subjects and an approximate count, the countries where recording took place, the volume in hours and the distinct speaker count, whether speaker identity labels or embeddings are included, and the retention the vendor applies to its own copies.
- Test the Article 35(3) triggers one by one and record the answer for each, including the ones you conclude do not apply. A recorded negative is what makes the assessment defensible later.
- Write the necessity and proportionality section in your own words about your own purpose. This is the section that cannot be copied from the vendor, and it is the section that gets read.
- Check your supervisory authority's Article 35(4) list for biometric processing and AI training before assuming the general test is the only gate.
- If the residual risk stays high after mitigation, start the Article 36 consultation before the training run. Consultation after the fact is not consultation.
Related compliance topics
-
Data Processing Agreement
data processing agreement
-
Vendor Due Diligence Checklist
vendor due diligence checklist
-
Voice Anonymization
voice anonymization
-
Anonymisation vs Pseudonymisation
anonymisation vs pseudonymisation
-
Ethical Data Collection
ethical data collection
-
Consent for AI Training
ai training consent
Not legal advice
We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.
Sourcing data under Data Protection Impact Assessment?
Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.
- Pilot batch before the full run, so problems surface early.
- Consent documentation delivered with the data.
- No medical or clinical data. No recorded telephone calls.