A quiet reading corner in a modern office at blue hour, an armchair and floor lamp by tall glazing

Data protection

Do you need a DPIA for an automation project?

You need one if the processing is likely to result in a high risk to people, which UK GDPR and the ICO flesh out with specific triggers including innovative technology, large scale processing, and decisions that significantly affect individuals. Plenty of business automation does not meet that threshold, and some plainly does.

Last checked 19 September 2026

What it is, and what it is not #

A data protection impact assessment is a piece of thinking done before processing starts and written down. It describes what you intend to do and why, whether it is necessary and proportionate to the purpose, what could go wrong for the people whose data is involved, and what you will do about that.

It is not a submission. You do not send it to the ICO in the ordinary course, and nobody approves it. The only time it goes to the regulator is when you have identified a high risk you cannot mitigate, in which case you must consult before starting.

The threshold #

The requirement bites where processing is likely to result in a high risk to the rights and freedoms of individuals. The ICO's guidance sets out the factors that push processing towards that threshold, and the ones that come up in automation projects are these.

  • Innovative technology

    Applying a novel approach to personal data. AI in a decision making role sits here more comfortably than AI in a drafting role.

  • Decisions with a significant effect

    Screening, scoring, pricing or declining people. The effect on the individual is what matters, not the sophistication of the method.

  • Large scale processing

    Volume relative to the number of people affected, not relative to your business.

  • Invisible processing

    Using personal data in ways the person would not expect and has not been told about.

  • Vulnerable individuals

    Patients, children, people receiving care, anyone with an imbalance of power in the relationship.

  • Systematic and extensive processing

    Building up a picture of people over time rather than handling a single transaction.

The ICO publishes screening checklists alongside the guidance. Working through them takes minutes and is the correct way to answer this question, rather than reasoning from a list like the one above.

Two projects that sound similar and are not #

Automating payment reminders

  • A system reads your own ledger, identifies invoices past their due date, drafts a reminder and a person approves it
  • The data is already yours
  • The purpose is one the customer expects
  • No decision is being made about the person, and nothing sensitive is involved

This does not look like high risk processing.

Automating applicant screening

  • A system reads applications and ranks or filters them
  • A decision with a significant effect on individuals is being made or substantially shaped by software
  • At scale, over people who cannot see how it works

That is a different proposition, and it is the kind of thing a DPIA exists for.

The difference is not the technology. It is what happens to a person at the other end, which is also the distinction that runs through how to tell which jobs are worth automating.

The short version, which is worth doing anyway #

Even where the threshold is nowhere near met, half an hour on the same questions is one of the better uses of time at the start of a project. Answer these in writing:

  1. What personal data does this touch, and whose is it?

  2. Why is it necessary to use it, and could the project work with less?

  3. Who would be affected if it went wrong, and how badly?

  4. What would tell us it had gone wrong, and how quickly?

  5. Who checks the output, and what can they do about it?

Where the ground is still moving #

The ICO's AI specific guidance was last updated on 15 March 2023 and carries a notice saying it is under review following the Data (Use and Access) Act, which we checked on 19 September 2026. The DPIA requirement itself is not the part in flux, but how the regulator frames AI specific risk may be refined.

The practical response is the same as everywhere else on this subject: keep the record of what you decided and when, so that if the framing changes you can see what needs revisiting. More on where the regulator currently stands is in what the ICO actually says about AI, and the surrounding duties are in what UK GDPR asks of a business using AI.

Questions people ask

What is a DPIA?
A data protection impact assessment: a written exercise carried out before processing starts, which describes what you plan to do, why it is necessary, what could go wrong for the people affected, and what you will do to reduce that risk. It is a document and a thought process, not a form to file with anyone.
Does automating invoice chasing need one?
Usually not. Sending a reminder about a genuine debt, using data you already hold, for a purpose the customer would expect, is ordinary processing. The answer changes if the system starts making decisions about people or handling sensitive information.
What happens if the assessment shows a high risk?
You work out how to reduce it. If you cannot reduce it sufficiently, you have to consult the ICO before you start. That consultation step is rare for business automation and is a real obligation when it applies.
Is a DPIA worth doing even when it is not required?
Often, in a shorter form. Writing down what data a project touches, what could go wrong and who would be affected takes very little time and regularly changes the design. Plenty of projects get smaller and safer as a direct result of somebody writing it down.

Where these numbers come from

  1. ICO, Data protection impact assessments (DPIAs) , read 19 September 2026 . Covers what a DPIA is, when and how to carry one out, consulting the ICO, and examples of processing likely to result in high risk.
  2. ICO, Guidance on AI and data protection , read 19 September 2026 . Last updated 15 March 2023 and currently under review following the Data (Use and Access) Act.

Last checked 19 September 2026.

Our workings are on the methodology page .

Free audit

Find out what the repeated work costs you

The audit counts every job the business repeats, ranks them by the hours they eat, and maps the five worth automating first. It is free, you keep everything, and there is no obligation at the end of it.

AI automation, explained

Plain answers to what businesses ask before they automate anything.

All of ai automation, explained

Read next