As of 13 August 2026, AI cannot complete a data protection impact assessment.
This still needs a person who signs their name to it.
Can you do it?
30 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0/month
Skill neededpower-user
Who has to check ita professional
What the alternative costsNo sourced alternative price is provided in the available tool data.
If this goes wrong, your organisation may start high-risk processing with an overlooked privacy risk and remain responsible for the resulting harm, enforcement or remedial work.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open your organisation's DPIA template, project proposal, records of processing, data inventory, retention policy, security assessment and processor contracts, then gather the current versions in one working folder.
- Ask the project owner, IT or security lead, procurement team and service owner for the data flow, systems, recipients, suppliers, international transfers, retention period, user groups and proposed safeguards.
- Paste the gathered factual material into the prompt under Project information, removing unnecessary personal data and labelling documents by source and date.
- Run the prompt and copy the draft into the organisation's approved DPIA template, preserving its questions, approval fields and risk-rating method.
- Compare every statement in the draft with the source documents, correct inaccurate data flows and safeguards, and replace every assumption or information request with an evidenced answer or an unresolved issue.
- Ask the DPO or a UK data-protection solicitor to test the lawful basis, necessity, proportionality, high-risk findings, international transfers, residual risks and whether consultation with the ICO is required.
- Record the specialist's decisions, named risk owners, mitigation deadlines and approval status, then obtain the organisation's required sign-off before the processing starts.
Prompt
Act as a drafting assistant for a UK organisation preparing a data protection impact assessment under UK GDPR. Do not give legal advice, state that a conclusion is compliant, invent facts, or decide that a risk is acceptable without evidence. Use only the information I provide. Create a DPIA working draft with these sections: 1. Project name, owner, purpose and proposed start date 2. Description of the processing and how it works in practice 3. Personal data, special category data and criminal offence data involved 4. Data subjects and expected scale 5. Data sources, recipients, processors, international transfers and retention 6. Lawful basis and any relevant condition for special category or criminal offence data, recorded as questions for a qualified reviewer where the evidence is incomplete 7. Necessity and proportionality, including less intrusive alternatives 8. Risks to individuals, with causes, affected people, likelihood, severity and overall risk 9. Existing and proposed technical and organisational measures 10. Residual risk after mitigation 11. Consultation required, including data protection officer, security, procurement, affected staff or users, and the ICO where applicable 12. Decisions, owners, deadlines, evidence required and approval status For every missing fact, make a clearly labelled information request. Separate facts supplied by me from assumptions, and mark every assumption for confirmation. Do not reduce a risk merely because a control is proposed. Use a table for the risk register and distinguish inherent from residual risk. End with a list of issues that a UK data-protection specialist or DPO must decide before approval. Project information: [Paste the project proposal, process map, data inventory, supplier or processor details, security measures, retention policy, transfer information, consultation notes and existing risk assessments here.]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover undocumented data flows, shadow systems or supplier practices that nobody has described in the input.
- AI cannot decide whether the processing is necessary and proportionate for your particular purpose.
- AI cannot reliably judge whether a stated control reduces a risk enough or whether the residual risk is acceptable.
- AI cannot take responsibility for the organisation's UK GDPR decisions, consultation duties or approval.
- AI cannot replace the DPO or solicitor's review where the processing is high risk or legally disputed.
What makes this a NO: legal accountability, regulated advice and verification cost.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 4 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT complete a DPIA?
- It can produce a structured DPIA draft from information you supply, including a risk register and a list of gaps. It cannot establish that the assessment is complete or adequate, so a DPO or UK data-protection solicitor must check serious cases.
- Does every new project need a DPIA?
- No. A DPIA is required where processing is likely to result in a high risk to individuals, and some types of processing require particular care. Ask your DPO or a UK data-protection solicitor to assess the threshold rather than relying on a model.
- Can AI identify the risks in a DPIA?
- AI can suggest risks from the facts and documents you provide, but it cannot see missing data flows, undocumented uses or operational weaknesses. Each risk and proposed control needs evidence and specialist review.
- Is an AI-written DPIA legally valid?
- The method used to draft it does not transfer responsibility from your organisation, and an incomplete or inaccurate DPIA may not meet your obligations. This is not professional advice; a DPO or UK data-protection solicitor should approve the assessment where the processing is serious or high risk.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.