What is a DPIA?
A DPIA, or data protection impact assessment, is a written check you carry out before you start using personal data in a way that could put people at high risk. It describes the processing, tests whether it's necessary and proportionate, sets out the risks to people and records how you'll reduce them. The ICO calls it a living process.
The duty comes from Article 35 of the UK GDPR. A DPIA doesn't have to remove every risk. It shows you've thought the risks through and decided what's acceptable before anyone's data is used.
When is a DPIA required?
UK GDPR requires a DPIA before any processing that's likely to result in a high risk to people's rights and freedoms, especially when it uses new technology. Three cases always need one: systematic evaluation of people by automated means, including profiling, with legal or similarly significant effects; large-scale use of sensitive data; and large-scale monitoring of public places.
The ICO's list of processing that needs a DPIA includes:
- new technology, including AI, when combined with another risk factor;
- profiling people on a large scale;
- combining or matching personal data from different sources;
- using data you didn't collect from the people themselves, without telling them;
- tracking people's location or behaviour;
- biometric or genetic data;
- targeting children or vulnerable people.
If you decide a DPIA isn't needed, the ICO says you should document your reasons. If in doubt, it recommends doing one.
Do you need a DPIA for an AI tool?
Usually, if personal data goes into it. The ICO's guidance on AI says that in the vast majority of cases, using AI involves processing likely to result in a high risk, which makes a DPIA a legal requirement. If the tool handles no personal data at all, write down why you decided you don't need one.
That covers tools you buy as well as tools you build: Microsoft 365 Copilot, ChatGPT, a meeting-notes tool or a supplier's custom build. Personal data turns up in more places than people expect, such as names in emails, meeting recordings and CVs.
What should a DPIA for an AI tool include?
Every DPIA needs four things: a description of the processing and its purpose, an assessment of whether it's necessary and proportionate, the risks to people, and the measures to address them. For an AI tool, the ICO also expects the data flows, how much a person checks the output, and how the tool's accuracy could affect fairness.
These are the questions an AI tool adds. The template asks each of them in step 2.
| Question | What to write down |
|---|---|
| What goes in? | Prompts, documents, emails, recordings or files, and the personal data inside them. |
| What comes out, and who sees it? | Drafts, summaries or answers, and whether they're shared or stored. |
| Where is it processed? | The country and service, including where the supplier's support staff sit. |
| What does the supplier keep? | Inputs and outputs, for how long, and whether they're used to train its models. |
| Who checks the output? | The person who reviews an output before it's used about someone. |
The DPIA template
This is the same template as the Word file. Fill in the parts in square brackets, and keep the finished version with your project records.
Data protection impact assessment (DPIA) for an AI tool
Fill in the parts in square brackets. Keep the finished version with your project records and review it whenever anything changes. This template follows the ICO's seven steps. It isn't legal advice: your data protection officer or adviser makes the call.
- Organisation
- [Your business]
- AI tool or project
- [What it is, and the supplier]
- Project owner
- [Name, role]
- Data protection officer or lead
- [Name, role]
- Started
- [DD/MM/YYYY]
- Version
- [1.0]
1Why you need a DPIA
- What will the AI tool do, in one sentence?
- Tick each that applies. Any tick is a reason to complete this DPIA:
- Personal data goes into the tool, or comes out of it
- It uses new technology, including AI
- It uses health, financial hardship or other sensitive data, or criminal offence data
- It helps make decisions about people that affect them significantly
- It monitors or tracks people
- It combines personal data from different sources
- It involves children or vulnerable people
2Describe the processing
- What goes in
- [Prompts, documents, emails, recordings or files, and the personal data in them]
- What comes out
- [Drafts, summaries, answers or decisions, and who sees them]
- Where it's processed and stored
- [Country and service, including where support staff sit]
- The supplier's role
- [Processor acting on your instructions, or a controller in its own right]
- What the supplier keeps
- [Inputs and outputs kept, for how long, and whether they train its models]
- Whose data, and how much
- [Staff, customers or the public; roughly how many people; how often]
- What people would expect
- [Would they expect this use? Have concerns been raised before?]
- The purpose
- [What you want to achieve, and the benefit to you and to the people involved]
3Consultation
- Inside the business
- [IT, security, the team who'll use it, and how you asked them]
- The supplier
- [What you asked for: terms, security information, data locations]
- Your DPO
- [When you asked for advice]
- The people whose data it is
- [How you asked them, or why you didn't]
4Necessity and proportionality
- Lawful basis
- [Which basis applies, and why]
- Less data
- [Could you do this with less personal data, or none?]
- Human checks
- [Who checks an output before it's used about a person?]
- Telling people
- [Which privacy notice you'll update]
- People's rights
- [How you'll find and correct or delete their data in the tool]
- The supplier contract
- [Data processing terms in place, and their date]
- Transfers
- [Any processing outside the UK, and the safeguard used]
5Risks to people
Risk to people Personal data goes in that the tool didn't need Staff can see documents through the tool that they couldn't open before An inaccurate output about a person is used without being checked The supplier keeps inputs longer than expected, or uses them to train its models Data is processed or supported outside the UK without a safeguard Outputs treat some groups of people less fairly than others [Add your own] Likelihood, Severity, Overall: filled in for each row in the Word file.
6Measures to reduce the risks
Risk [Risk from step 5] [Risk from step 5] [Risk from step 5] Measure, Effect, Remaining risk, Approved: filled in for each row in the Word file.
7Sign off and record outcomes
- Measures approved by
- [Name, role, DD/MM/YYYY]
- Remaining risks approved by
- [Name, role, DD/MM/YYYY. If any high risk remains, consult the ICO before you start]
- DPO advice given
- [Yes or no, DD/MM/YYYY]
- Summary of DPO advice
- [What they advised]
- DPO advice followed or overruled by
- [Name. If overruled, say why]
- Consultation responses reviewed by
- [Name]
- Kept under review by
- [Name, and the next review date]
Free to use and change, with no email needed.
How do you carry out a DPIA?
Follow the ICO's seven steps: decide whether you need one, describe the processing, consult the people involved, check it's necessary and proportionate, identify and assess the risks, decide how to reduce them, then sign off and record the outcome. Start before you buy or switch anything on, so the findings can still change the plan.
- Decide whether you need one. Use the triggers in step 1 of the template. If you decide you don't, record why.
- Describe the processing. What goes in, what comes out, where it's processed, what the supplier keeps.
- Consult. The people who'll use it, IT and security, the supplier, your DPO, and where you can, the people whose data it is.
- Check it's necessary and proportionate. Your lawful basis, whether less data would do, and how people will be told.
- Identify and assess the risks. For each risk to people, how likely it is and how serious it would be.
- Decide how to reduce them. A measure for each risk, and what risk remains afterwards.
- Sign off and record the outcome. Who approved the measures, who accepted the remaining risk, and the DPO's advice.
What does a DPIA look like for an AI tool?
This is part of step 6 for an AI tool that records internal meetings and writes up the notes. It shows the level of detail that's useful.
| Risk to people | Measure | Remaining risk |
|---|---|---|
| A colleague's health is discussed and ends up in the written notes. | Don't record HR or health discussions. A named person reads the notes before they're shared. | Low |
| The supplier keeps recordings longer than needed. | Set the shortest retention the tool allows, and confirm it in the supplier's terms. | Low |
| The notes get wrong who agreed to what. | Attendees check the notes before they're filed. | Low |
Who signs off a DPIA?
Someone with the authority to accept the remaining risk on the business's behalf. If you have a data protection officer (DPO), you must ask for their advice, record it, and record whether you followed it. The ICO's sample template asks who approved the measures and who accepted the residual risk.
What if the risk is still high?
If a high risk remains after your measures, you must consult the ICO before you start, and you can't go ahead until you have. The ICO gives written advice within eight weeks, or up to 14 weeks in complex cases. Changing the plan, such as using less personal data, may bring the risk down first.
Is a DPIA a one-off?
No. The ICO calls a DPIA a living process. Review it while the tool is in use, and repeat it if anything substantial changes: new data going in, a new group of people affected, a new supplier, or a new purpose. For AI tools, a supplier's update can count as a change worth checking.
The ICO's DPIA and AI guidance carries a notice that it is under review following the Data (Use and Access) Act 2025. Check the linked ICO pages for changes before you rely on them.