Do you need a DPIA for an AI tool? A UK screening test
Five common AI uses run through the UK GDPR test for a data protection impact assessment, and what to write down when you decide one isn't needed.
Often, though not for every tool. UK GDPR requires a data protection impact assessment, or DPIA, before any processing that’s likely to result in a high risk to people. The ICO lists AI as an innovative technology and says AI plus one more risk factor needs a DPIA. Plenty of everyday AI use clears that bar. Some doesn’t, and for those you write down why.
When is a DPIA mandatory under UK GDPR?
Article 35 requires one before you start processing that’s likely to result in a high risk to people’s rights and freedoms, and it singles out processing that uses new technologies. It then names three cases where a DPIA is always needed:
- systematic and extensive profiling that leads to decisions with legal or similarly significant effects on people
- large-scale use of special category data or criminal records
- large-scale systematic monitoring of a publicly accessible area
Most AI tools a small organisation adopts won’t fall squarely into those three. For them the question is whether the ICO’s wider list catches them.
Does using AI count as high risk?
On its own it doesn’t, but it gets you halfway. The ICO publishes a list of processing it treats as likely to be high risk. AI sits under innovative technology, and the ICO requires a DPIA when innovative technology is combined with any other criterion from the European guidelines it relies on. Those criteria include evaluating or scoring people, sensitive data, large-scale processing and combining datasets.
The ICO’s AI guidance goes further, saying that in the vast majority of cases AI use will involve processing that’s likely to be high risk. And the list has rows that catch some AI uses directly. Decisions about whether someone gets a product, service, opportunity or benefit, made to any extent by automated means, are on it. So is tracking people’s behaviour.
Both ICO pages now carry a notice that the guidance is under review following the Data (Use and Access) Act 2025. The Act didn’t change when a DPIA is required, so these tests still hold.
A six-question screening test
Run each tool, or each use of a tool, through these.
- Does it process personal data at all? If not, you don’t need a DPIA. Record that and stop.
- Does it make or shape decisions about people’s access to a job, a service, credit or a benefit?
- Does it handle health or other special category data, or criminal records?
- Does it monitor or track what people do, staff included?
- Does it work across large volumes of records, or combine data from different sources?
- Does it involve children or other vulnerable people?
Because AI already counts as innovative technology on the ICO’s list, a yes to any of questions 2 to 6 points to a DPIA. If every answer is no, you can usually justify going without one, as long as you record why. When the screening is part of approving a new tool, the seven questions to ask before you approve a new AI tool cover the rest of that decision.
How five common AI uses come out
These are likely answers for a typical organisation of 10 to 250 staff. Your own facts decide the real one.
| Use | Likely answer | Why |
|---|---|---|
| A tool that screens or ranks CVs | Yes | It shapes decisions about access to a job, which the ICO lists in its own right |
| Transcribing and summarising meetings | Often yes | HR, health and client matters come up in meetings, which puts sensitive data alongside AI |
| Copilot across your shared drives | Often yes | It reaches whatever each user can open, and most drives hold HR and client files |
| A chatbot answering general questions on your website | Often no | If it takes little personal data and decides nothing about anyone, AI alone doesn’t trigger one |
| Drafting client letters on an approved business plan | Often no | It’s usually fine when staff paste only what each letter needs. Work that routinely involves health or criminal matters changes the answer |
CV screening carries one more duty since 5 February 2026, when the Data (Use and Access) Act replaced the old Article 22 with new rules on automated decisions. If a tool rejects candidates with no meaningful human involvement, Article 22C requires safeguards. You have to tell candidates about the decision, let them make representations, give them a way to have a person look at it, and let them contest it. Where special category data is involved, Article 22B allows decisions like that only in narrow cases, such as the candidate’s explicit consent.
What should you record if you don’t need one?
The ICO says you may be able to justify not doing a DPIA if you’re confident the processing is unlikely to be high risk, and that you should document your reasons. A short note covers it:
- the tool, the plan and what it’s used for
- the personal data that goes in, if any
- your answers to the screening questions
- who decided, and on what date
- what would make you look again, such as a new use or a change to the supplier’s terms
Keep the note with the tool’s approval record. When a client questionnaire asks whether you’ve assessed your AI tools for data protection risk, that note is your answer.
What goes in a DPIA for an AI tool?
Article 35(7) sets the minimum. You describe the processing and its purpose, assess whether it’s necessary and proportionate, assess the risks to people, and set out the measures you’ll take to address them.
For an AI tool the risk section usually turns on a few questions. Does the supplier train on your data, and where does it hold it? How accurate is the output, and could it treat some groups of people unfairly? Who checks the output before anyone relies on it? If a high risk remains after your measures, Article 36 requires you to consult the ICO before you start.
The AI risk assessment template works through this for a single tool. Its data protection section asks the DPIA question, and its register lists seven common risks with room for the controls and an owner.
What changes if the EU AI Act reaches you?
The Act sits alongside UK GDPR for the organisations it reaches, and that includes UK firms whose AI output is used in the EU. AI used to recruit or select people is a high-risk use under Annex III. If you deploy a high-risk system, Article 26(9) has you use the provider’s instructions for use to carry out your DPIA.
Some deployers also owe a fundamental rights impact assessment under Article 27. That mainly means public bodies, private firms providing public services, and firms using AI to assess creditworthiness or price life and health insurance. Since the 2026 amendments, that assessment can cross-refer to your DPIA or reuse parts of it. For Annex III systems these duties apply from 2 December 2027.
The guide to AI risk assessment under the EU AI Act covers how classification works, and the EU AI Act check tells you whether the Act reaches you at all.