Guides

A DPIA for AI: when a UK SME needs one, and a template that passes.

By Zain M · 1 October 2026 · 13 min read

A UK SME needs a data protection impact assessment before any AI processing that is likely to be high risk, which under the ICO’s criteria includes systematic profiling or scoring of individuals, processing special-category data at scale, monitoring people, and decisions with legal or similarly significant effects. Everyday drafting and summarising with no personal data does not need one; screening job applicants, triaging patients, scoring customers or monitoring staff does. The Data (Use and Access) Act 2025 widened the lawful bases for significant automated decisions but kept the safeguards: tell the person, let them contest, provide human review. The template below has the seven parts the ICO expects and is written to be filled in as it stands.

TriggerProcessing likely to be high risk
Usual AI triggersProfiling, special-category data, automated decisions
TemplateSeven parts, four pages

When a DPIA is required, and when it is not

UK GDPR requires a DPIA before processing that is likely to result in a high risk to individuals, and the ICO publishes screening criteria and a list of processing that always needs one. The criteria that AI use most often meets are: systematic and extensive profiling with significant effects; large-scale processing of special-category data or criminal-offence data; systematic monitoring of a publicly accessible place or of employees; innovative technology applied to personal data; and decisions about access to services made by automated means. The ICO’s own guidance on AI says that in most cases the use of AI to process personal data will trigger the requirement, because AI tends to involve one or more of those.

What does not need one: drafting a tender response, summarising a public document, writing marketing copy, analysing the firm’s own sales figures with no individuals identifiable. The test is whether personal data is processed and whether the processing is likely to be high risk, not whether AI is involved.

AI useDPIA?Why
Screening or scoring job applicantsYesProfiling with significant effects; the Act’s automated-decision safeguards apply
Triage of patient or client enquiries by health or needYesSpecial-category data, often at scale
Monitoring staff use of AI tools or productivityYesSystematic monitoring of employees
Chatbot answering customer questions from order dataUsuallyPersonal data at scale; innovative technology
Reading supplier invoices into the ledgerUsually notLimited personal data, low risk; document it
Drafting documents with no personal dataNoNo personal data processed

ICO screening criteria applied to common SME uses. Where in doubt, do a screening record and keep it.

What the Data (Use and Access) Act 2025 changed

The Act received Royal Assent on 19 June 2025 and, per the ICO’s guidance page updated in June 2026, all of its data protection provisions are now in force. On automated decisions it replaced Article 22 with Articles 22A to 22D, which, in the ICO’s words, open up the full range of lawful bases for significant automated decisions, including legitimate interests, provided the safeguards are in place: the individual is told, can make representations, can contest the decision, and can obtain human intervention. Decisions based on special-category data remain more restricted. For an SME using AI to screen, score or triage people, the practical effect is that the lawful basis is easier to find and the safeguards are not optional, and the DPIA is where both are recorded.

The Act also restated the transfer test for sending data outside the UK as whether protection would be “not materially lower”, and added a duty to have a data protection complaints procedure. Both belong in the template.

The template

Seven parts, matching the ICO’s guidance on what a DPIA must contain. Replace the bracketed items; keep the headings so an auditor recognises the shape.

011. Description of the processing. Purpose: [what decision or task]. Nature: [what the AI does, step by step, and what a person does]. Scope: [data categories, whose data, how much, how long retained, where processed and by which provider on which plan]. Context: [relationship with the individuals, their expectations, any children or vulnerable people]. Legitimate interests of the organisation: [stated plainly].
022. Consultation. [Who inside the firm was consulted, when.] [Whether individuals or their representatives were consulted and how, or why not.] [The processor’s DPA and security documentation reviewed, with references.] [DPO or external adviser, if any.]
033. Necessity and proportionality. Lawful basis: [which, and for special-category data the Article 9 condition]. Why this processing achieves the purpose and a less intrusive way would not: [reason]. Data minimisation: [what is excluded from the prompt or the model]. Accuracy: [how output is checked, the acceptance threshold as a number]. Retention: [period and why]. Individual rights: [how access, rectification, objection and, for automated decisions, contest and human review are provided]. Transfers: [mechanism, and residency if required]. Processor contract: [DPA, the ICO’s eight clauses covered].
044. Risks to individuals. For each: [risk], [likelihood: remote, possible, probable], [severity: minimal, significant, severe], [overall]. Typical AI risks: inaccurate output acted on; bias against a protected characteristic; personal data used for training by the provider; over-collection in prompts; retention beyond need; a decision made without a human; a breach at the provider.
055. Measures to reduce risk. For each risk: [measure], [effect on risk], [residual risk], [approved yes or no]. Typical measures: business plan with no training; human decides; explained scores; outcome monitoring by protected characteristic; prompt minimisation; retention setting; DPA and sub-processor list; access controls; staff policy and training; incident procedure.
066. Sign-off and outcomes. Residual risks approved by: [name, role, date]. DPO advice: [given, accepted or overruled, with reasons]. Consultation with the ICO required: [yes if high residual risk remains, otherwise no]. Summary of measures adopted and who owns each.
077. Review. Review date: [six months]. Triggers: [change of provider or plan, new data category, new decision type, incident, complaint]. Version history.

How to fill in part four so it is not a formality

The risk register is where most DPIAs turn into paperwork, because they list generic risks and score them all as low. Do it from the process instead. Walk one real case through: an applicant, a patient, a customer. At each step ask what the AI sees, what it produces, what a person does with it, and what happens to that individual if it is wrong. The risks that fall out are specific, they have owners, and the measures against them are things the firm will actually do, which is what the ICO means by an assessment rather than a document.

Two risks are nearly always underrated. Inaccuracy acted on without checking, which is why the acceptance threshold and the review step belong in part three as numbers. And bias, which for any scoring of people means monitoring outcomes by protected characteristic and being able to show the monitoring, because the firm, not the vendor, answers for the result.

What good looks like, in practice

A four-page document that a new manager could read and understand what the system does, which data it touches, who decides, and what to do if it goes wrong. A processor recorded, a DPA on file, a retention setting made deliberately, a policy staff have read, and a review date in the calendar. It is less work than it sounds when it is done before the build, and far more than it sounds when it is done after a complaint. Our GDPR guides for Claude and ChatGPT cover the provider side; this template covers yours.

Common questions

Do I need a DPIA to use AI?

Where personal data is processed and the processing is likely to be high risk: profiling or scoring people, special-category data at scale, monitoring, or significant automated decisions. The ICO says most AI processing of personal data will trigger it. Drafting with no personal data does not.

Do I need a DPIA to use ChatGPT or Claude?

Not for the tool itself. You need one for a specific use that meets the criteria, such as screening candidates or triaging patients with it. Ordinary drafting and analysis with a business plan and a policy does not.

What must a DPIA contain?

A description of the processing, consultation, an assessment of necessity and proportionality, the risks to individuals, the measures to reduce them, sign-off, and a review plan. The template above follows that shape.

What did the Data (Use and Access) Act 2025 change for AI decisions?

It replaced Article 22 with Articles 22A to 22D, widening the lawful bases for significant automated decisions, including legitimate interests, while keeping the safeguards: tell the person, allow representations and contest, provide human review. Special-category data remains more restricted.

Does a DPIA have to go to the ICO?

Only if a high residual risk remains after the measures. Most SME DPIAs reduce risk to an accepted level and are kept on file.

How long should a DPIA take?

A day for a firm with its records in order, done before the build. Weeks if done after a complaint.

Who signs off a DPIA?

A named senior person, with the data protection officer’s advice recorded if the firm has one. The owner of the process should be involved throughout.

How often should a DPIA be reviewed?

Every six months and on any trigger: change of provider or plan, a new data category, a new decision type, an incident or a complaint.

Want the DPIA written from the real process?

We write the DPIA alongside the build, from a walk-through of the actual process, with the measures wired into the system rather than promised on paper.

Start a conversation →