Skip to content

DPIA template for AI projects

A free data protection impact assessment (DPIA) template for AI tools, in Word, with no email needed. It follows the seven steps set by the ICO, the UK's data protection regulator, plus the questions an AI tool raises.

Last checked 05/10/2026

What is a DPIA?

A data protection impact assessment (DPIA) is a written check you do before using personal data in a way that could put people at high risk. It records the risks to people and how you'll reduce them, and the duty comes from Article 35 of the UK GDPR.

The guide What is a DPIA? covers the rest, including what it must contain and what the data protection officer does.

When is a DPIA required?

Before any processing that's likely to result in a high risk to people, especially with new technology. Large-scale use of sensitive data, automated decisions with significant effects and large-scale monitoring of public places always need one, and the ICO lists ten more types, including AI used alongside another risk factor.

The guide sets out the ICO's full list. If you decide you don't need a DPIA, record why.

Do you need a DPIA for an AI tool?

Usually, if personal data goes into it. The ICO's guidance on AI says that in the vast majority of cases, using AI involves processing likely to result in a high risk, which makes a DPIA a legal requirement.

That covers tools you buy as well as tools you build, including Microsoft 365 Copilot, ChatGPT and meeting-notes tools. Personal data turns up in names in emails, meeting recordings and CVs.

What should a DPIA for an AI tool include?

Every DPIA needs four things: a description of the processing and its purpose, an assessment of whether it's necessary and proportionate, the risks to people, and the measures to address them. For an AI tool, the ICO also expects the data flows, how much a person checks the output, and how the tool's accuracy could affect fairness.

The template adds these in step 2.

QuestionWhat to write down
What goes in?Prompts, documents, emails, recordings or files, and the personal data inside them.
What comes out, and who sees it?Drafts, summaries or answers, and whether they're shared or stored.
Where is it processed?The country and service, including where the supplier's support staff sit.
What does the supplier keep?Inputs and outputs, for how long, and whether they're used to train its models.
Who checks the output?The person who reviews an output before it's used about someone.

The DPIA template

Fill in the parts in square brackets, and keep the finished version with your project records.

Data protection impact assessment (DPIA) for an AI tool

Fill in the parts in square brackets. Keep the finished version with your project records and review it whenever anything changes. This template follows the ICO's seven steps. It isn't legal advice: your data protection officer or adviser makes the call.

Organisation
[Your business]
AI tool or project
[What it is, and the supplier]
Project owner
[Name, role]
Data protection officer or lead
[Name, role]
Started
[DD/MM/YYYY]
Version
[1.0]
  1. 1Why you need a DPIA

    • What will the AI tool do, in one sentence?
    • Tick each that applies. Any tick is a reason to complete this DPIA:
    • Personal data goes into the tool, or comes out of it
    • It uses new technology, including AI
    • It uses health, financial hardship or other sensitive data, or criminal offence data
    • It helps make decisions about people that affect them significantly
    • It monitors or tracks people
    • It combines personal data from different sources
    • It involves children or vulnerable people
  2. 2Describe the processing

    What goes in
    [Prompts, documents, emails, recordings or files, and the personal data in them]
    What comes out
    [Drafts, summaries, answers or decisions, and who sees them]
    Where it's processed and stored
    [Country and service, including where support staff sit]
    The supplier's role
    [Processor acting on your instructions, or a controller in its own right]
    What the supplier keeps
    [Inputs and outputs kept, for how long, and whether they train its models]
    Whose data, and how much
    [Staff, customers or the public; roughly how many people; how often]
    What people would expect
    [Would they expect this use? Have concerns been raised before?]
    The purpose
    [What you want to achieve, and the benefit to you and to the people involved]
  3. 3Consultation

    Inside the business
    [IT, security, the team who'll use it, and how you asked them]
    The supplier
    [What you asked for: terms, security information, data locations]
    Your DPO
    [When you asked for advice]
    The people whose data it is
    [How you asked them, or why you didn't]
  4. 4Necessity and proportionality

    Lawful basis
    [Which basis applies, and why]
    Less data
    [Could you do this with less personal data, or none?]
    Human checks
    [Who checks an output before it's used about a person?]
    Telling people
    [Which privacy notice you'll update]
    People's rights
    [How you'll find and correct or delete their data in the tool]
    The supplier contract
    [Data processing terms in place, and their date]
    Transfers
    [Any processing outside the UK, and the safeguard used]
  5. 5Risks to people

    Risk to people
    Personal data goes in that the tool didn't need
    Staff can see documents through the tool that they couldn't open before
    An inaccurate output about a person is used without being checked
    The supplier keeps inputs longer than expected, or uses them to train its models
    Data is processed or supported outside the UK without a safeguard
    Outputs treat some groups of people less fairly than others
    [Add your own]

    Likelihood, Severity, Overall: filled in for each row in the Word file.

  6. 6Measures to reduce the risks

    Risk
    [Risk from step 5]
    [Risk from step 5]
    [Risk from step 5]

    Measure, Effect, Remaining risk, Approved: filled in for each row in the Word file.

  7. 7Sign off and record outcomes

    Measures approved by
    [Name, role, DD/MM/YYYY]
    Remaining risks approved by
    [Name, role, DD/MM/YYYY. If any high risk remains, consult the ICO before you start]
    DPO advice given
    [Yes or no, DD/MM/YYYY]
    Summary of DPO advice
    [What they advised]
    DPO advice followed or overruled by
    [Name. If overruled, say why]
    Consultation responses reviewed by
    [Name]
    Kept under review by
    [Name, and the next review date]

Free to use and change.

How do you carry out a DPIA?

Follow the ICO's seven steps, and start before you buy or switch anything on, so the findings can still change the plan.

  1. Decide whether you need one. Use the triggers in step 1 of the template.
  2. Describe the processing. Including the AI questions above.
  3. Consult. The people who'll use it, IT and security, the supplier, your data protection officer (DPO), and where you can, the people whose data it is.
  4. Check it's necessary and proportionate. Your lawful basis, whether less data would do, and how people will be told.
  5. Identify and assess the risks. For each risk to people, how likely it is and how serious it would be.
  6. Decide how to reduce them. A measure for each risk, and what risk remains afterwards.
  7. Sign off and record the outcome. Who approved the measures, who accepted the remaining risk, and the DPO's advice.

What does a DPIA look like for an AI tool?

Part of step 6 for a tool that records internal meetings and writes up the notes:

See a filled-in example
Risk to peopleMeasureRemaining risk
A colleague's health is discussed and ends up in the written notes.Don't record HR or health discussions. A named person reads the notes before they're shared.Low
The supplier keeps recordings longer than needed.Set the shortest retention the tool allows, and confirm it in the supplier's terms.Low
The notes get wrong who agreed to what.Attendees check the notes before they're filed.Low

Who signs off a DPIA?

Someone with the authority to accept the remaining risk on the business's behalf. If you have a DPO, you must ask for their advice, record it, and record whether you followed it.

What if the risk is still high?

If a high risk remains after your measures, you must consult the ICO before you start, and you can't go ahead until you have. The ICO gives written advice within eight weeks, or up to 14 weeks in complex cases. Changing the plan, such as using less personal data, may bring the risk down first.

Is a DPIA a one-off?

No. The ICO calls it a living process. Review it while the tool is in use, and repeat it after any substantial change, such as new data, new people affected, a new supplier, a new purpose or a supplier's update.

The ICO is reviewing its DPIA and AI guidance after the Data (Use and Access) Act 2025, so check the linked pages for changes.