Legal requirement Impact assessment United Kingdom Guidance

Carry out a data protection impact assessment for high-risk AI processing

Under ICO AI guidance, UK GDPR Article 35; ICO guidance, accountability and governance section

Source-linked Open official source

What does it require?

Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.

Practical action

Use the ICO's DPIA template and add AI-specific sections on bias, explainability and human oversight.

Who does it apply to?

Controllers using personal data in AI where processing is likely high risk.

Evidence examples

  • Data protection impact assessment (report)

Framework mappings

Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.

Framework mappings
FrameworkReferenceNoteConfidence
ISO/IEC 42001:2023Clause 6.1.4 AI system impact assessmentOriginal editorial mapping.high
NIST AI RMF 1.0MAP 5.1Impact assessment.medium

Similar obligations in other instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.