What is a DPIA?
A DPIA is a written check you carry out before you start using personal data in a way that's likely to put people at high risk. It describes what you plan to do, tests whether it's necessary and proportionate, and records the risks to people and how you'll reduce them.
The ICO, the UK's data protection regulator, calls it a process to "systematically analyse, identify and minimise the data protection risks of a project or plan". It doesn't have to remove every risk, and it isn't a one-off. The ICO calls it a "living" process to keep under review.
What does DPIA stand for?
DPIA stands for data protection impact assessment. The term comes from Article 35 of the UK GDPR, the UK General Data Protection Regulation, which sets the duty. You'll often see it next to DPO, which stands for data protection officer, the person some organisations must appoint to advise on data protection.
When is a DPIA required?
Before any processing that's likely to result in a high risk to people's rights and freedoms, "in particular using new technologies". UK GDPR names three cases that always need one:
- systematic and extensive evaluation of people by automated means, including profiling, where decisions based on it have legal or similarly significant effects on them;
- large-scale use of special category data, such as health data, or of data about criminal convictions and offences;
- systematic monitoring of a publicly accessible area on a large scale.
Beyond those, ask whether the plan has features that point to high risk. The ICO says that in most cases, two of the nine risk factors in the European guidelines mean you need one, though one can be enough.
If you decide you don't need a DPIA, record why. If in doubt, the ICO recommends doing one.
What processing is on the ICO's list?
The ICO lists ten types of processing that need a DPIA. Some need one on their own. Others need one when combined with another risk factor, such as large scale, sensitive data or vulnerable people.
| Processing | Needs a DPIA |
|---|---|
| New technology, or a new use of existing technology, including AI | With another factor |
| Decisions about someone's access to a product, service, opportunity or benefit that rely on automated decision-making or special category data | On its own |
| Profiling people on a large scale | On its own |
| Biometric data | With another factor |
| Genetic data | With another factor |
| Combining, comparing or matching personal data from different sources | On its own |
| Using personal data you didn't get from the people themselves, without telling them | With another factor |
| Tracking people's location or behaviour | With another factor |
| Using children's or other vulnerable people's data for marketing, profiling or automated decisions, or offering online services directly to children | On its own |
| Processing where a data breach could put people's physical health or safety at risk | On its own |
What must a DPIA contain?
Article 35(7) of the UK GDPR sets the minimum. A DPIA must contain:
- a systematic description of the processing and its purposes, including any legitimate interest you rely on;
- an assessment of whether the processing is necessary and proportionate to those purposes;
- an assessment of the risks to the people whose data it is;
- the measures you'll take to address those risks, including safeguards and security.
There's no set form. The ICO says you can use its sample template, make your own or use an existing project method, as long as it covers seven steps: identify the need, describe the processing, consider consultation, assess necessity and proportionality, identify and assess the risks, identify measures to reduce them, and sign off and record the outcomes.
The DPIA template for AI projects follows those seven steps, adds the questions an AI tool raises, and shows a filled-in example. It's free in Word and PDF, with no email needed.
Who carries out a DPIA?
Your organisation, as the controller deciding how and why the data is used. You choose who does it and who signs it off. You can get outside help, but the ICO says you stay responsible. Alongside whoever leads the project, the ICO says to involve:
- your data protection officer (DPO), if you have one;
- information security staff;
- any processor, such as the supplier of the tool;
- legal advisers or other experts, where relevant.
Where appropriate, ask the people whose data it is, or their representatives, for their views. If you decide not to, record why.
What does the DPO do in a DPIA?
If you have a DPO, you must ask for their advice when you carry out a DPIA. The ICO says they should advise on whether you need one, how to do it, what would reduce the risks, whether it's been done correctly and whether the processing can go ahead. Record their advice, and if you don't follow it, record why.
The DPO also monitors how the DPIA is carried out. Not every business must appoint one. UK GDPR requires a DPO for public authorities, and where core activities involve large-scale, regular monitoring of people or large-scale use of special category or criminal offence data. Without a DPO, the DPIA duty still applies.
When do you have to consult the ICO?
When your DPIA shows a high risk that your measures can't reduce. You must consult the ICO before the processing starts, and you can't go ahead until you have. If your measures bring the risk down so it's no longer high, you don't need to.
You send the DPIA, the purposes and methods of the processing, the measures and safeguards, who is responsible for what, and your DPO's contact details. The ICO says it will tell you within 10 days whether it has accepted the DPIA for consultation, and give written advice within eight weeks, or up to 14 weeks in complex cases.
Do you need a DPIA for an AI tool?
Usually, if personal data goes into it. The ICO's guidance on AI says that in the vast majority of cases, using AI involves processing likely to result in a high risk, which makes a DPIA a legal requirement. That covers tools you buy as well as tools you build.
The ICO's list counts AI as new technology, which needs a DPIA alongside another risk factor. It also says staff can count as vulnerable, because of the power imbalance with an employer. For an AI tool, the ICO expects the DPIA to cover:
- how data flows through the tool, and at what point its outputs affect people;
- how much a person checks the output, and when;
- how errors or variation in the tool's performance could affect fairness;
- your role and the supplier's, including whether the supplier is your processor;
- less risky ways to do the same job, and why you didn't choose them.
A supplier's own material can inform your DPIA, but the ICO says not to copy large sections of it. If you decide a use of AI isn't high risk, record how you reached that view.
The DPIA template puts these questions in step 2. If the tool is Microsoft 365 Copilot or ChatGPT, see what each one keeps first.
Has the Data (Use and Access) Act 2025 changed DPIAs?
Not the duty itself. On 30/09/2026 the Information Commission took over from the Information Commissioner under the Act, so the UK GDPR articles on DPIAs and consulting the regulator now name the Commission. It is still called the ICO, and the government says its role, responsibilities and powers haven't changed.
The ICO's DPIA and AI guidance carries a notice that it is under review because of the Act, so check the linked pages for changes.