A DPIA for AI: when a UK SME needs one, and a template that passes.
By Zain M · 1 October 2026 · 13 min read
A UK SME needs a data protection impact assessment before any AI processing that is likely to be high risk, which under the ICO’s criteria includes systematic profiling or scoring of individuals, processing special-category data at scale, monitoring people, and decisions with legal or similarly significant effects. Everyday drafting and summarising with no personal data does not need one; screening job applicants, triaging patients, scoring customers or monitoring staff does. The Data (Use and Access) Act 2025 widened the lawful bases for significant automated decisions but kept the safeguards: tell the person, let them contest, provide human review. The template below has the seven parts the ICO expects and is written to be filled in as it stands.
When a DPIA is required, and when it is not
UK GDPR requires a DPIA before processing that is likely to result in a high risk to individuals, and the ICO publishes screening criteria and a list of processing that always needs one. The criteria that AI use most often meets are: systematic and extensive profiling with significant effects; large-scale processing of special-category data or criminal-offence data; systematic monitoring of a publicly accessible place or of employees; innovative technology applied to personal data; and decisions about access to services made by automated means. The ICO’s own guidance on AI says that in most cases the use of AI to process personal data will trigger the requirement, because AI tends to involve one or more of those.
What does not need one: drafting a tender response, summarising a public document, writing marketing copy, analysing the firm’s own sales figures with no individuals identifiable. The test is whether personal data is processed and whether the processing is likely to be high risk, not whether AI is involved.
| AI use | DPIA? | Why |
|---|---|---|
| Screening or scoring job applicants | Yes | Profiling with significant effects; the Act’s automated-decision safeguards apply |
| Triage of patient or client enquiries by health or need | Yes | Special-category data, often at scale |
| Monitoring staff use of AI tools or productivity | Yes | Systematic monitoring of employees |
| Chatbot answering customer questions from order data | Usually | Personal data at scale; innovative technology |
| Reading supplier invoices into the ledger | Usually not | Limited personal data, low risk; document it |
| Drafting documents with no personal data | No | No personal data processed |
ICO screening criteria applied to common SME uses. Where in doubt, do a screening record and keep it.
What the Data (Use and Access) Act 2025 changed
The Act received Royal Assent on 19 June 2025 and, per the ICO’s guidance page updated in June 2026, all of its data protection provisions are now in force. On automated decisions it replaced Article 22 with Articles 22A to 22D, which, in the ICO’s words, open up the full range of lawful bases for significant automated decisions, including legitimate interests, provided the safeguards are in place: the individual is told, can make representations, can contest the decision, and can obtain human intervention. Decisions based on special-category data remain more restricted. For an SME using AI to screen, score or triage people, the practical effect is that the lawful basis is easier to find and the safeguards are not optional, and the DPIA is where both are recorded.
The Act also restated the transfer test for sending data outside the UK as whether protection would be “not materially lower”, and added a duty to have a data protection complaints procedure. Both belong in the template.
The template
Seven parts, matching the ICO’s guidance on what a DPIA must contain. Replace the bracketed items; keep the headings so an auditor recognises the shape.
How to fill in part four so it is not a formality
The risk register is where most DPIAs turn into paperwork, because they list generic risks and score them all as low. Do it from the process instead. Walk one real case through: an applicant, a patient, a customer. At each step ask what the AI sees, what it produces, what a person does with it, and what happens to that individual if it is wrong. The risks that fall out are specific, they have owners, and the measures against them are things the firm will actually do, which is what the ICO means by an assessment rather than a document.
Two risks are nearly always underrated. Inaccuracy acted on without checking, which is why the acceptance threshold and the review step belong in part three as numbers. And bias, which for any scoring of people means monitoring outcomes by protected characteristic and being able to show the monitoring, because the firm, not the vendor, answers for the result.
What good looks like, in practice
A four-page document that a new manager could read and understand what the system does, which data it touches, who decides, and what to do if it goes wrong. A processor recorded, a DPA on file, a retention setting made deliberately, a policy staff have read, and a review date in the calendar. It is less work than it sounds when it is done before the build, and far more than it sounds when it is done after a complaint. Our GDPR guides for Claude and ChatGPT cover the provider side; this template covers yours.
Common questions
Do I need a DPIA to use AI?
Where personal data is processed and the processing is likely to be high risk: profiling or scoring people, special-category data at scale, monitoring, or significant automated decisions. The ICO says most AI processing of personal data will trigger it. Drafting with no personal data does not.
Do I need a DPIA to use ChatGPT or Claude?
Not for the tool itself. You need one for a specific use that meets the criteria, such as screening candidates or triaging patients with it. Ordinary drafting and analysis with a business plan and a policy does not.
What must a DPIA contain?
A description of the processing, consultation, an assessment of necessity and proportionality, the risks to individuals, the measures to reduce them, sign-off, and a review plan. The template above follows that shape.
What did the Data (Use and Access) Act 2025 change for AI decisions?
It replaced Article 22 with Articles 22A to 22D, widening the lawful bases for significant automated decisions, including legitimate interests, while keeping the safeguards: tell the person, allow representations and contest, provide human review. Special-category data remains more restricted.
Does a DPIA have to go to the ICO?
Only if a high residual risk remains after the measures. Most SME DPIAs reduce risk to an accepted level and are kept on file.
How long should a DPIA take?
A day for a firm with its records in order, done before the build. Weeks if done after a complaint.
Who signs off a DPIA?
A named senior person, with the data protection officer’s advice recorded if the firm has one. The owner of the process should be involved throughout.
How often should a DPIA be reviewed?
Every six months and on any trigger: change of provider or plan, a new data category, a new decision type, an incident or a complaint.
Want the DPIA written from the real process?
We write the DPIA alongside the build, from a walk-through of the actual process, with the measures wired into the system rather than promised on paper.