What is a DPIA and when do we need one?
Chris Duffy
Certified Chief AI Officer • • 2 Min Read
A DPIA, or Data Protection Impact Assessment, is a structured check you do before higher-risk processing of personal data. UK GDPR requires one when a use is likely to be high-risk, and a lot of AI use qualifies. It's a short document that names the risk, who it affects, and how you're reducing it.
You need one when you're doing something new or higher-risk with personal data: profiling people, processing at scale, or feeding sensitive data into a tool. If you're unsure whether a use crosses the line, that uncertainty is usually the signal to do one.
Done well, a DPIA takes a morning and saves you a far worse conversation later. It's also the kind of evidence a client's due diligence team likes to see. The ICO publishes a template; the work is in answering it truthfully for the AI tool you actually use.
Read next: Is AI use covered by UK GDPR · How to write an AI policy · Book a call