Do I need a DPIA before using an AI tool?
For most AI deployments touching personal data the honest answer is yes — and a short one is far better than none.
Andy Wake, Founder and Managing Director6 min read
A Data Protection Impact Assessment is a structured way of asking: what could this do to a person, and what are we doing about it? Under UK GDPR it is mandatory where processing is likely to result in a high risk to individuals.
When it is required
The ICO treats several triggers as indicating high risk, and AI deployments frequently hit more than one at a time.
- Use of innovative technology — which covers most AI deployments by default.
- Large-scale profiling, or any automated decision-making with significant effects.
- Processing children's data or data about vulnerable people.
- Special-category data such as health, or criminal-offence data.
- Systematic monitoring, including workplace monitoring.
What a proportionate DPIA contains
- The processing: what the tool does, whose data, what categories, and why.
- Necessity and proportionality: why this, rather than something less intrusive.
- Risks to people: not risks to the organisation — harm, unfairness, distress, exclusion, loss of control.
- Mitigations: what reduces each risk, and the residual level afterwards.
- Oversight: who reviews outputs, who can override, and how someone challenges an outcome.
- Sign-off: a named person, a date, and a review interval.
The gaps we see most
- Risks written from the organisation's perspective rather than the person's.
- No stated retention period for prompts, outputs or logs.
- No answer to 'what happens when the model is wrong about a specific individual?'
- No review date, so the assessment describes a system that has since changed.
A DPIA is a living document. If the tool, the data or the purpose changes materially, the assessment is out of date — and an out-of-date DPIA is treated much like no DPIA at all.
Frequently asked questions
- Is a DPIA legally required for AI in the UK?
- It is required under UK GDPR wherever processing is likely to result in high risk to individuals. Because the ICO treats innovative technology, large-scale profiling, automated decisions with significant effects and children's data as high-risk indicators, most AI deployments involving personal data will require one.
- Who should sign off a DPIA?
- A named individual with authority to accept the residual risk — typically the data controller's accountable owner for the service, taking advice from a data protection officer or adviser where one exists. Sign-off without a named person is the most common weakness we see.
- How long should a DPIA be?
- As long as the risk justifies. For a small organisation using an approved tool for a bounded purpose, two to four pages that genuinely address harm to people is better than a twenty-page template completed mechanically.
Sources and further reading
- When do we need to do a DPIA?
Information Commissioner's Office
Where to go next
- Free governance templates
- AI compliance for individuals and small charities
- Responsible AI hub
- AI governance glossary
More articles on the insights index.