United Kingdom Guidance Guidance Non-binding

ICO AI guidance: requirements, deadlines and compliance actions

ICO Guidance on AI and data protection

What is the ICO AI guidance?

The ICO's guidance explains how UK GDPR and the Data Protection Act 2018 apply when organisations develop or use AI that processes personal data. It covers accountability and governance, lawfulness and fairness, transparency, data minimisation, security, individual rights, and automated decision-making. The guidance is not itself law, but it reflects how the regulator interprets binding obligations and is the reference point in ICO enforcement.

Who does it apply to?

Any controller or processor using personal data in AI systems in the UK, at any lifecycle stage. It does not apply to AI that processes no personal data.

Controllers and processors under UK GDPR, including developers and deployers of AI.

When do the requirements apply?

First published July 2020, updated March 2023. Consultations on generative AI and data protection ran in 2024. The Data (Use and Access) Act 2025 changed the rules on automated decision-making, so a reviewer should confirm the current version.

What must organisations do?

Complete a data protection impact assessment for high-risk AI, document lawful bases, provide meaningful information about automated decisions, implement safeguards for solely automated decisions with legal or similarly significant effects, and test for bias and accuracy.

Legal requirement Carry out a data protection impact assessment for high-risk AI processing UK GDPR Article 35; ICO guidance, accountability and governance section

Where AI processing of personal data is likely to result in a high risk to individuals, UK GDPR requires a DPIA before processing begins. The ICO treats most AI involving profiling, large-scale processing or novel technology as meeting this threshold.

Practical action: Use the ICO's DPIA template and add AI-specific sections on bias, explainability and human oversight.

Evidence examples: Data protection impact assessment

Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment; NIST AI RMF 1.0 MAP 5.1

Obligation page Source-linked

Legal requirement Apply safeguards to solely automated decisions with significant effects UK GDPR Article 22 as amended by the Data (Use and Access) Act 2025

Individuals have rights in relation to solely automated decisions that produce legal or similarly significant effects, including being told about the decision, obtaining human intervention, and contesting it. The Data (Use and Access) Act 2025 amended these rules; the reviewer must confirm the current wording.

Practical action: Map every significant automated decision, add a human-review route and a notice to affected people.

Evidence examples: Automated decision register and review procedure

Framework mapping (original, editorial): NIST AI RMF 1.0 GOVERN 5.x, MANAGE 4.x

Obligation page Source-linked

Penalties

Underlying UK GDPR breaches can attract fines up to GBP 17.5 million or 4 % of global annual turnover.

Official sources

  1. Guidance on AI and data protection
    Information Commissioner's Office · Tier 2 source
  2. Data (Use and Access) Act 2025
    legislation.gov.uk · 19 Jun 2025 · Tier 1 source

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.