Skip to main content

DPIA for AI tools: when a UK firm needs one

By Syed Husnain Khalid · Published 8 October 2026 · Last checked 8 October 2026 · 9 min read

Drafted with AI. Each claim was checked against the primary sources listed below by AI on 8 October 2026; a person has not reviewed it yet.

Short answer

A UK firm needs a data protection impact assessment (DPIA) for an AI tool whenever the processing is likely to result in a high riskto people. The regulator’s AI guidance says that covers the vast majority of AI uses. UK GDPR Article 35 requires the assessment before processing starts, and a decision not to do one must be documented.

This guide is for the person in a UK accounting, advice or immigration firm who signs off a new AI tool. The duty sits with the firm, not the vendor. The timing matters because the Information Commission replaced the Information Commissioner’s Office (ICO) on 30 September 2026, and its DPIA and AI guidance is marked as under review after the Data (Use and Access) Act 2025. Building Filyst, our case management product for immigration firms, taught us that the measures a DPIA asks for are cheaper to design in than to add later. The sections cover the test, the triggers, a screening template, the contents and when to consult the regulator.

The seven steps of a DPIA for an AI toolSeven steps from the regulator's DPIA guidance: identify the need for a DPIA; describe the processing; consider consultation; assess necessity and proportionality; identify and assess risks; identify measures to mitigate the risks; sign off and record outcomes.ScreenIs a DPIAneeded?DescribeData, purposeand the AI'sroleConsultPeopleaffected,DPO, vendorNecessityNeeded andproportionate?RisksLikelihoodand severityMeasuresReduce eachriskSign offRecord theoutcome
Step 1 is the screening decision. All seven steps come before the tool processes personal data, and the DPIA is reviewed when the risk changes, for example a new model or a new use.

What is a data protection impact assessment (DPIA)?

A data protection impact assessment (DPIA), sometimes called a privacy impact assessment, is a written assessment of how a planned use of personal data affects people’s rights and freedoms and how the risks will be reduced. UK GDPR Article 35(1)requires the controller to carry it out “prior to the processing”.

The controller is the organisation that decides the purposes and means of the processing (Article 4(7)). A firm that chooses an AI tool and puts client data into it is the controller. The AI vendor is usually a processor, an organisation that processes personal data on the controller’s behalf (Article 4(8)).

The Information Commission is the UK data protection regulator. Section 117 of the Data (Use and Access) Act 2025 established it, and section 118abolished the office of Information Commissioner on 30 September 2026. Its website is still ico.org.uk and its guidance pages still say “ICO”.

Does using an AI tool require a DPIA?

In most cases, yes. The regulator’s guidance on AI and data protectionsays: “In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA.”

The same passage says the assessment is made case by case, and the guidance acknowledges that not all uses of AI are likely to result in a high risk. Where a firm decides a particular use is not high risk, the guidance says: “you still need to document how you have made this assessment.” The safe default for a firm handling client data is to do the DPIA and to treat “no DPIA” as the outcome that needs written reasons.

Which triggers make a DPIA mandatory?

Three sets of triggers apply to a controller: the general test in Article 35(1), the three cases in Article 35(3), and the regulator’s list under Article 35(4). Article 35(1) covers any processing, “in particular using new technologies”, that is likely to result in a high risk.

Article 35(3) names three cases where a DPIA is always required:

  • “a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person” (Article 35(3)(a));
  • processing on a large scale of special category data or of personal data relating to criminal convictions and offences (Article 35(3)(b));
  • a systematic monitoring of a publicly accessible area on a large scale (Article 35(3)(c)).

Article 35(4) requires the regulator to publish a list of processing operations that need a DPIA. The list, published under the ICO name, has ten items. Five need a DPIA on their own and five need one when combined with another criterion.

Operation on the regulator's listDPIA required
Innovative technology, including AIWhen combined with any criterion from the European guidelines
Denial of service: decisions on access to a product, service, opportunity or benefit, based to any extent on automated decision-making or involving special category dataOn its own
Large-scale profilingOn its own
Biometric dataWhen combined with any criterion from the European guidelines
Genetic data, other than by a GP or health professional for direct health careWhen combined with any criterion from the European guidelines
Data matching: combining, comparing or matching personal data from multiple sourcesOn its own
Invisible processing: data not obtained from the person, where telling them is judged impossible or disproportionateWhen combined with any criterion from the European guidelines
Tracking of geolocation or behaviourWhen combined with any criterion from the European guidelines
Targeting of children or other vulnerable individuals for marketing, profiling or automated decisions, or online services offered directly to childrenOn its own
Risk of physical harm from a personal data breachOn its own

The European guidelines are the Article 29 Working Party’s guidelines on DPIAs (WP248). They give nine criteria that indicate likely high risk:

  1. evaluation or scoring;
  2. automated decision-making with legal or similar significant effect;
  3. systematic monitoring;
  4. sensitive data or data of a highly personal nature;
  5. data processed on a large scale;
  6. matching or combining datasets;
  7. data concerning vulnerable data subjects;
  8. innovative use or applying new technological or organisational solutions;
  9. preventing data subjects from exercising a right or using a service or contract.

The regulator names artificial intelligence, machine learning and deep learning as examples of innovative technology. An AI tool therefore starts with one factor already present, and any one of the other criteria completes the trigger.

How do the triggers apply to common AI uses?

Most AI uses in a regulated firm meet a second criterion, because client files hold financial, health or immigration data. The table applies the list to five uses. It is our reading of the published criteria, not a ruling from the regulator.

AI use in a regulated firmSecond factorDPIA?
AI drafts a letter that a person rewrites and signs offNone, if the prompt holds no financial, health or other highly personal dataNot required by the list. Record the reasons. The guidance calls a DPIA good practice even where only one factor is present.
AI extracts data from client bank statementsData of a highly personal nature: WP248 gives financial data usable for payment fraud as an exampleYes
AI scores clients for risk or suitabilityEvaluation or scoringYes
AI reads immigration files with health or ethnicity dataSensitive dataYes
AI decides, or helps decide, whether a client gets a serviceDenial of service, which is on the list in its own rightYes

DPIA screening template for an AI tool

A screening template records the step 1 decision: whether a full DPIA is needed and why. Copy the table below and adapt it. It is a starting point built from Article 35 and the guidance above, not an official form, and it does not replace the DPIA itself.

Screening questionAnswer to record
1. Tool, vendor and version
2. What the tool will do, and for which task
3. Personal data it will read or produce, and whose
4. Does it evaluate or score people, or inform a decision with a legal or similarly significant effect on them?Yes / No, with reasons
5. Does it process special category, criminal offence, financial or other highly personal data?Yes / No, with reasons
6. Does it process data on a large scale, match datasets, track people or involve children or other vulnerable people?Yes / No, with reasons
7. Does any other item on the regulator's list or any other European criterion apply?Yes / No, with reasons
8. Which person reviews the output, at what stage, and can that person overturn it?
9. Decision: full DPIA needed? If no, the reasons the processing is not likely to result in a high riskYes / No, with reasons
10. Decided by, data protection officer's advice (if the firm has one), date, and next review date

A “yes” to any of questions 4 to 7 means a full DPIA under the regulator’s list, because AI already counts as innovative technology. For the full assessment, the regulator publishes a sample DPIA templateand says: “You don’t have to use this template.” The sample is general and not written for AI.

What must a DPIA for an AI tool contain?

Article 35(7) sets four items that every DPIA must contain “at least”. The regulator’s AI guidance adds what each item should show for an AI system.

Article 35(7) requiresThe AI guidance adds
(a) A systematic description of the processing and its purposesData flows and the stages where AI affects people; margins of error that affect fairness; the degree of human involvement and the stage it happens; the controller and any processors
(b) An assessment of necessity and proportionalityEvidence that AI is a sensible solution to a real problem; less risky alternatives considered; trade-offs, for example between statistical accuracy and data minimisation
(c) An assessment of the risks to people's rights and freedomsA score for each risk by likelihood and severity; harms beyond privacy, including discrimination learnt from historic data
(d) The measures to address the risks, including safeguards and security measuresWhether each measure reduces or eliminates its risk; staff training; the residual risk that remains

Three other people have a part. Article 35(2) requires the controller to seek the advice of its data protection officer (DPO), the person designated to advise on data protection, where it has one. Article 35(9) requires the controller to seek the views of the people affected “where appropriate”. Article 28(3)(f) requires the contract with a processor to make the processor assist with the DPIA, which is one of the terms a UK GDPR Article 28(3) processor contract must contain.

When must a firm consult the Information Commission?

A controller must consult the Information Commission before processing where the DPIA shows the processing would result in a high risk “in the absence of measures taken by the controller to mitigate the risk” (Article 36(1)). The regulator’s consultation guidance reads this as the residual risk: a firm that has reduced the risk so it is no longer high need not consult.

Article 36(3) lists what the controller sends: the responsibilities of the controller, joint controllers and processors, where applicable; the purposes and means of the processing; the measures and safeguards; the DPO’s contact details, where applicable; the DPIA; and any other information the Commission requests. Article 36(2) gives the Commission up to eight weeks from receipt to give written advice, and allows a six-week extension for complex processing. The firm cannot start the processing until it has consulted.

When is a DPIA reviewed, and what does a missing one cost?

Article 35(11) requires a review “at least when there is a change of the risk represented by processing operations”. For an AI tool, a new model, a new category of client data or a new use of the output are changes to check against the DPIA.

Article 83(4)(a)sets the maximum fine for breaching the controller’s obligations under Articles 25 to 39, which include Article 35. The maximum is £8,700,000 or, for an undertaking, 2% of total worldwide annual turnover in the preceding financial year, whichever is higher.

Which controls reduce AI risk in a DPIA?

The controls that reduce AI risk most are design choices: a person who reviews the output and can overturn it, fixed rules for anything with a right answer, the minimum client data, and a log. A DPIA is one of the records described in our guide to AI in regulated industries: UK rules and human review, and these controls are where the two meet.

We built two of these measures into Filyst on the server instead of in a policy document. A case cannot advance a stage on the approval of the person who requested it, and actions are written to an audit log. What we learnt is that a measure the system enforces takes one sentence to describe in a DPIA and can be evidenced from the log.

The AI guidance says a DPIA should record the degree of human involvement. Article 22A defines a decision as based solely on automated processing when no person is meaningfully involved in taking it, which Human in the loop AI: UK GDPR Article 22A explained covers. The log that proves the review happened is set out in AI audit trail for UK regulated firms: what to log. A staff policy applies the DPIA’s measures to general tools, as in our AI policy for UK firms using ChatGPT.

Frequently asked questions

Does every AI tool need a DPIA?

Not every one, but the regulator's AI guidance says that in the vast majority of cases the use of AI triggers the legal requirement for a DPIA. Where a firm decides a use is not high risk, it still needs to document how it made that assessment.

Is there an official DPIA template for AI?

No. The regulator publishes a general sample DPIA template and says firms don't have to use it. The screening template on this page is our starting point for the first step, to adapt.

Who does the DPIA, the firm or the AI vendor?

The firm, as controller, under UK GDPR Article 35(1). The vendor, as processor, assists under the contract terms Article 28(3)(f) requires, and the firm stays responsible.

When do we have to consult the regulator?

Before processing, where the DPIA shows a high risk that the firm's measures do not reduce (Article 36(1)). The Information Commission then has up to eight weeks to give written advice, extendable by six weeks.

Is a DPIA the same as a privacy impact assessment?

Yes. The European guidelines on DPIAs note that the term privacy impact assessment is often used for the same concept. UK GDPR Article 35 uses data protection impact assessment.

Sources

  1. UK GDPR Article 35 (data protection impact assessment), legislation.gov.uk
  2. UK GDPR Article 36 (prior consultation), legislation.gov.uk
  3. UK GDPR Article 83 (administrative fines), legislation.gov.uk
  4. UK GDPR Article 28 (processor), legislation.gov.uk
  5. UK GDPR Article 22A (automated processing and significant decisions), legislation.gov.uk
  6. UK GDPR Article 4 (definitions), legislation.gov.uk
  7. Data (Use and Access) Act 2025, section 117 (the Information Commission)
  8. Data (Use and Access) Act 2025, section 118 (abolition of the office of Information Commissioner)
  9. Information Commission (ICO guidance), What are the accountability and governance implications of AI?
  10. Information Commission (ICO guidance), When do we need to do a DPIA?
  11. Information Commission (ICO guidance), How do we do a DPIA? (sample template)
  12. Information Commission (ICO guidance), Do we need to consult the ICO?
  13. Article 29 Working Party, Guidelines on DPIAs (WP248 rev.01)

Start with two weeks and £950.

You get a map of your systems and a fixed price to fix them. If you build with us, the £950 comes off.