Skip to main content
Skip to main content
Responsible AI

Do I need a DPIA before using an AI tool?

For most AI deployments touching personal data the honest answer is yes — and a short one is far better than none.

Andy Wake, Founder and Managing Director6 min read

A Data Protection Impact Assessment is a structured way of asking: what could this do to a person, and what are we doing about it? Under UK GDPR it is mandatory where processing is likely to result in a high risk to individuals.

When it is required

The ICO treats several triggers as indicating high risk, and AI deployments frequently hit more than one at a time.

  • Use of innovative technology — which covers most AI deployments by default.
  • Large-scale profiling, or any automated decision-making with significant effects.
  • Processing children's data or data about vulnerable people.
  • Special-category data such as health, or criminal-offence data.
  • Systematic monitoring, including workplace monitoring.

What a proportionate DPIA contains

  1. The processing: what the tool does, whose data, what categories, and why.
  2. Necessity and proportionality: why this, rather than something less intrusive.
  3. Risks to people: not risks to the organisation — harm, unfairness, distress, exclusion, loss of control.
  4. Mitigations: what reduces each risk, and the residual level afterwards.
  5. Oversight: who reviews outputs, who can override, and how someone challenges an outcome.
  6. Sign-off: a named person, a date, and a review interval.

The gaps we see most

  • Risks written from the organisation's perspective rather than the person's.
  • No stated retention period for prompts, outputs or logs.
  • No answer to 'what happens when the model is wrong about a specific individual?'
  • No review date, so the assessment describes a system that has since changed.

A DPIA is a living document. If the tool, the data or the purpose changes materially, the assessment is out of date — and an out-of-date DPIA is treated much like no DPIA at all.

Frequently asked questions

Is a DPIA legally required for AI in the UK?
It is required under UK GDPR wherever processing is likely to result in high risk to individuals. Because the ICO treats innovative technology, large-scale profiling, automated decisions with significant effects and children's data as high-risk indicators, most AI deployments involving personal data will require one.
Who should sign off a DPIA?
A named individual with authority to accept the residual risk — typically the data controller's accountable owner for the service, taking advice from a data protection officer or adviser where one exists. Sign-off without a named person is the most common weakness we see.
How long should a DPIA be?
As long as the risk justifies. For a small organisation using an approved tool for a bounded purpose, two to four pages that genuinely address harm to people is better than a twenty-page template completed mechanically.

Sources and further reading

Where to go next

More articles on the insights index.

Try the demo