Legal requirement
impact assessment
·
United Kingdom
ICO AI guidance · UK GDPR Article 35; ICO guidance, accountability and governance section
Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.
Source-linked
Legal requirement
impact assessment
·
European Union
EU AI Act · Article 27
Before deploying most Annex III high-risk systems, deployers that are bodies governed by public law or private entities providing public services, and deployers using systems for creditworthiness assessment or life and health insurance pricing, must assess the impact on fundamental rights: the processes, period and frequency of use, categories of affected persons, specific risks of harm, human-oversight measures and mitigation, and notify the market-surveillance authority of the results.
Source-linked
Applies from 2 Aug 2026
Legal requirement
impact assessment
·
United Arab Emirates
UAE PDPL · Article on data protection impact assessment (reviewer to cite article number)
Before processing that uses modern technologies and is likely to pose a high risk to privacy, controllers must assess the impact on personal data protection, covering the processing, its purposes, risks and safeguards.
Source-linked
Legal requirement
impact assessment
·
Colorado (United States)
Colorado AI Act · C.R.S. 6-1-1703(3)
Deployers must complete an impact assessment before deployment, annually, and within 90 days of any intentional and substantial modification, covering purpose, risks of algorithmic discrimination and mitigation, data categories, performance metrics, transparency measures and post-deployment monitoring, and retain assessments for at least three years.
Source-linked
Applies from 30 Jun 2026
Legal requirement
impact assessment
·
India
India DPDP Act · Section 10
Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.
Source-linked
Voluntary guidance
impact assessment
·
United States
NIST AI RMF · MAP function
Map establishes the context: intended purposes, users, deployment settings, legal requirements, risk categorisation, benefits and costs, and impacts on individuals, groups, communities and society.
Source-linked