What it is, and what it is not #
A data protection impact assessment is a piece of thinking done before processing starts and written down. It describes what you intend to do and why, whether it is necessary and proportionate to the purpose, what could go wrong for the people whose data is involved, and what you will do about that.
It is not a submission. You do not send it to the ICO in the ordinary course, and nobody approves it. The only time it goes to the regulator is when you have identified a high risk you cannot mitigate, in which case you must consult before starting.
The threshold #
The requirement bites where processing is likely to result in a high risk to the rights and freedoms of individuals. The ICO's guidance sets out the factors that push processing towards that threshold, and the ones that come up in automation projects are these.
-
Innovative technology
Applying a novel approach to personal data. AI in a decision making role sits here more comfortably than AI in a drafting role.
-
Decisions with a significant effect
Screening, scoring, pricing or declining people. The effect on the individual is what matters, not the sophistication of the method.
-
Large scale processing
Volume relative to the number of people affected, not relative to your business.
-
Invisible processing
Using personal data in ways the person would not expect and has not been told about.
-
Vulnerable individuals
Patients, children, people receiving care, anyone with an imbalance of power in the relationship.
-
Systematic and extensive processing
Building up a picture of people over time rather than handling a single transaction.
The ICO publishes screening checklists alongside the guidance. Working through them takes minutes and is the correct way to answer this question, rather than reasoning from a list like the one above.
Two projects that sound similar and are not #
Automating payment reminders
- A system reads your own ledger, identifies invoices past their due date, drafts a reminder and a person approves it
- The data is already yours
- The purpose is one the customer expects
- No decision is being made about the person, and nothing sensitive is involved
This does not look like high risk processing.
Automating applicant screening
- A system reads applications and ranks or filters them
- A decision with a significant effect on individuals is being made or substantially shaped by software
- At scale, over people who cannot see how it works
That is a different proposition, and it is the kind of thing a DPIA exists for.
The difference is not the technology. It is what happens to a person at the other end, which is also the distinction that runs through how to tell which jobs are worth automating.
The short version, which is worth doing anyway #
Even where the threshold is nowhere near met, half an hour on the same questions is one of the better uses of time at the start of a project. Answer these in writing:
-
What personal data does this touch, and whose is it?
-
Why is it necessary to use it, and could the project work with less?
-
Who would be affected if it went wrong, and how badly?
-
What would tell us it had gone wrong, and how quickly?
-
Who checks the output, and what can they do about it?
Where the ground is still moving #
The ICO's AI specific guidance was last updated on 15 March 2023 and carries a notice saying it is under review following the Data (Use and Access) Act, which we checked on 19 September 2026. The DPIA requirement itself is not the part in flux, but how the regulator frames AI specific risk may be refined.
The practical response is the same as everywhere else on this subject: keep the record of what you decided and when, so that if the framing changes you can see what needs revisiting. More on where the regulator currently stands is in what the ICO actually says about AI, and the surrounding duties are in what UK GDPR asks of a business using AI.