Home · Business · Legal & Compliance · Data protection & GDPR
As of 13 August 2026, AI can only partly decide whether your UK business needs a DPIA.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe available tool information gives no price for a solicitor or privacy consultant.
If this goes wrong, your business records the wrong DPIA decision or misses a high-risk processing activity and remains responsible for the resulting compliance work and exposure.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the current ICO guidance on Data Protection Impact Assessments and save the relevant screening criteria and source links.
- Create a one-page fact sheet for the processing activity covering its purpose, data types, people affected, scale, technology, data sources, recipients, retention and safeguards.
- Paste the fact sheet and the relevant ICO extracts into a chatbot with the copyable prompt, and ask it to identify missing facts before giving an outcome.
- Check every factual assumption in the model's analysis against your project documents, supplier information, data map and security assessment.
- Compare each cited criterion and quotation with the current ICO source you opened, correcting any unsupported or outdated citation.
- Send the fact sheet, checked analysis and draft decision record to your DPO or a UK data protection solicitor when the activity involves high-risk technology, vulnerable people, extensive monitoring, profiling, special category data or unresolved uncertainty.
- Record the final decision, owner, evidence and review trigger in your compliance records, and start a DPIA if the checked conclusion is that one is required.
Prompt
Act as a UK data-protection compliance research assistant, not a solicitor and not the accountable decision-maker. Help me screen whether the processing activity below is likely to require a Data Protection Impact Assessment under the UK GDPR and current ICO guidance. Processing activity: [describe the project or processing] Purpose: [what the processing is intended to achieve] Personal data: [ordinary personal data and any special category or criminal offence data] People affected: [customers, employees, children, vulnerable people or other groups] Scale: [approximate number of people, records, frequency and geographical scope, if known] Technology or method: [profiling, automated decision-making, monitoring, tracking, biometrics, AI or other technology] Data sources and sharing: [where the data comes from and who receives it] Retention: [how long it is kept] Security and safeguards: [access controls, minimisation, pseudonymisation and other safeguards] Existing assessments or policies: [paste relevant extracts] Use only the UK GDPR and current ICO guidance that I provide or that you can identify with a source link and access date. Do not invent facts, legal tests, risk levels or citations. First list missing facts that could change the result. Then map the known facts to each relevant DPIA screening criterion, quoting or closely paraphrasing the source and linking it. Give a cautious outcome of one of: likely required, likely not required, or cannot determine. Explain the strongest reasons on both sides, distinguish legal requirements from good practice, and state what evidence would resolve uncertainty. Draft a short decision record with the processing description, risks considered, sources, assumptions, decision, owner and review trigger. Do not present this as legal advice. Flag the points that a UK data protection solicitor or suitably qualified DPO should check before I rely on the decision.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot know whether your description leaves out a material feature of the actual processing.
- AI cannot take responsibility for the DPIA decision or transfer your UK GDPR accountability to its output.
- AI cannot settle borderline judgements where the scale, likely harm or combination of technologies is unclear.
- AI cannot guarantee that a cited ICO page or legal interpretation remains current unless you check the source yourself.
- AI cannot replace a DPO or privacy solicitor where the consequences of getting the screening decision wrong are serious.
What caps this at PARTLY: legal accountability, judgement under ambiguity and verification cost.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 2 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT tell me if I need a DPIA?
- It can produce a useful first-pass screen against UK GDPR and ICO criteria if you provide the processing facts and check the sources. It cannot take responsibility for the decision, and the final judgement should go to your DPO or a UK data protection solicitor where the activity is high risk or unclear.
- What information does AI need to decide if I need a DPIA?
- Give it the purpose, data types, people affected, scale, technology, data sources, sharing, retention and safeguards. Include whether the activity involves monitoring, profiling, automated decisions, biometrics, special category data, children or vulnerable people.
- Is an AI DPIA assessment legally valid?
- An AI-generated assessment can help you organise evidence, but the tool does not make it legally valid or transfer accountability away from your business. It is not professional advice, and a serious or borderline case needs review by your DPO or a UK data protection solicitor.
- Can I use AI instead of a data protection solicitor for a DPIA?
- Use AI for the initial fact gathering, criteria mapping and draft decision record, not as a substitute for accountable legal review. A data protection solicitor or suitably qualified DPO should check a serious case, especially where the processing involves high-risk technology, extensive monitoring or vulnerable people.
Nearby answers
- Can AI draft an ICO data breach notification?PARTLY
- Can AI write a GDPR-compliant data protection clause for a UK contract?NO
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether my employee monitoring complies with UK GDPR?NO
- Can AI complete a UK GDPR transfer risk assessment?PARTLY
- Can AI create a record of processing activities for my business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.