Do I need a Data Protection Impact Assessment (DPIA) before using AI?

Contrasting

Almost always yes for AI involving personal data. The ICO says the vast majority of AI uses are high risk and trigger a DPIA; document any conclusion that a use is not. Introduction to AI assurance states all systems using personal data must carry out a DPIA. Consult the ICO before starting if residual high risk cannot be reduced. Involve your DPO early.

Warning Conflicting or tensioned advice across sources

Introduction to AI assurance says all systems using personal data must carry out a DPIA. ICO AI guidance says the vast majority of AI uses are high risk and therefore trigger a DPIA, but you still assess case by case and document if you conclude it is not high risk.

How to navigate this: Treat DPIA as the default for AI involving personal data. If you think a use is not high risk, document that assessment carefully and take legal/DPO advice — do not skip lightly.

From the guidance

Primary (how) ICO: Accountability and governance implications of AI

In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA. You will need to make this assessment on a case by case basis. In those cases where you assess that a particular use of AI does not involve high risk processing, you still need to document how you have made this assessment.

Section: What do we need to consider when undertaking data protection impact assessments for AI?

Read this in ICO: Accountability and governance implications of AI (opens in new tab)

Secondary (normative) ICO: Accountability and governance implications of AI

Article 35(3)(a) of the UK GDPR requires you to undertake a DPIA if your use of AI involves: systematic and extensive evaluation of personal aspects based on automated processing, including profiling, on which decisions are made that produce legal or similarly significant effects; large-scale processing of special categories of personal data; or systematic monitoring of publicly-accessible areas on a large scale.

Secondary (normative) AI Playbook for the UK Government

Before implementing AI solutions, you need to undertake a data protection impact assessment (DPIA). This involves an assessment of data protection and privacy risks, and the implementation of appropriate technical and organisational measures to sufficiently mitigate them.

Secondary (normative) Data and AI Ethics Framework

You need to carry out a Data Protection Impact Assessment (DPIA) before you process personal data when the processing is likely to result in a high risk to the rights and freedoms of individuals. It’s good practice to publish your completed DPIA to demonstrate that you’re taking the appropriate precautions to protect personal data and ensure your system is fair.

Section: Data protection-related transparency

Read this in Data and AI Ethics Framework (opens in new tab)

Contrasting Introduction to AI assurance

Position: All systems using personal data must carry out a DPIA.

All organisations processing data must comply with existing legal requirements, in particular, UK GDPR and the Data Protection Act 2018. All systems using personal data must carry-out a data protection impact assessment (DPIA).

Section: 5.3 Assuring data, models, systems and governance in practice

Read this in Introduction to AI assurance (opens in new tab)

Related questions