Carry out a data protection impact assessment for high-risk AI processing
Under ICO AI guidance, UK GDPR Article 35; ICO guidance, accountability and governance section
What does it require?
Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.
Practical action
Use the ICO's DPIA template and add AI-specific sections on bias, explainability and human oversight.
Who does it apply to?
Controllers using personal data in AI where processing is likely high risk.
- Sectors
- Cross-sector / all sectors
Evidence examples
- Data protection impact assessment (report)
Framework mappings
Original editorial crosswalks. They cite clause numbers only and reproduce no standard text; confidence reflects how direct the mapping is.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001:2023 | Clause 6.1.4 AI system impact assessment | Original editorial mapping. | high |
| NIST AI RMF 1.0 | MAP 5.1 | Impact assessment. | medium |
Similar obligations in other instruments
- Carry out a fundamental rights impact assessment before deployment — EU AI Act, European Union
- Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits — India DPDP Act, India
- Deployers must complete impact assessments for high-risk AI — Colorado AI Act, Colorado (United States)
- Conduct a data protection impact assessment for high-risk processing using new technologies — UAE PDPL, United Arab Emirates
- Map context, intended use and potential impacts (Map) — NIST AI RMF, United States (voluntary)
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.