
When does your firm need a DPIA for its AI tools?
If your AI use handles personal data and is likely high risk, UK law requires a DPIA before you start, not after. For a small firm, it can be short.
If your firm uses AI on people's personal data, and that use could be high risk, the law requires you to assess it before you switch the tool on, not after. That assessment is a Data Protection Impact Assessment, or DPIA, and for a small firm it can be short.
This matters more this year because AI is now built into the everyday tools firms already use, and those AI features are often switched on by default. Microsoft has built its Copilot assistant into the base Microsoft 365 plans. On 24 July 2026 it switched OpenAI-operated models on for eligible business customers by default, unless an admin turns them off. So whether you are processing personal data with AI is no longer a project you choose to start. It is often a decision that has already been made for you.
One note before we go on: this is general information, not legal advice. The aim is to help you see where a DPIA applies in your firm, and when to get proper advice. Here is when the law actually requires one, what a proportionate version contains, and a plain template you can fill in an afternoon.
When you actually need one
The rule is set out in Article 35 of the UK GDPR. Where a type of processing is likely to result in a high risk to people, in particular where it uses new technology, you must carry out a DPIA before the processing starts. The law names three cases that always require one: systematic automated profiling used to make decisions with legal or similarly serious effects on people; large-scale use of special category data (the most sensitive tier, such as health) or criminal-offence data; and large-scale monitoring of a public space.
On top of those, the ICO publishes its own list of ten further kinds of processing it treats as high risk. Two of them apply to everyday AI: using innovative technology, which the ICO says expressly includes AI, and any decision about a person's access to a service, opportunity or benefit that runs to any extent on automated scoring. As a general guide, the ICO says a DPIA is usually needed where two of these factors are present, though one can be enough.
In practice, look more closely if your AI tool:
- scores, ranks or profiles people;
- influences hiring, eligibility, pricing or access to a service;
- uses health or other sensitive information at scale;
- monitors people's behaviour or location;
- combines large amounts of information about individuals;
- involves children, or others who need more protection.
Those map onto the ICO's high-risk criteria, and the more of them a tool touches, the more likely a DPIA is needed.
This is easier to see with real tools. An AI CV screener that ranks job applicants clearly needs a DPIA: it uses new technology to shape a decision about a person's access to a job. So does a tool that scores new clients for risk before you take them on, for the same reason. Both help decide about a named individual.
Two common tools probably do not need one on their own. A general assistant you use to draft and summarise your own internal documents is new technology, but novelty by itself is not enough. An AI notetaker transcribing an internal team meeting is much the same. Neither makes a decision about a person or handles sensitive data at scale.
That is a judgement you reach by screening the tool, not a permanent exemption. If either tool starts to read health details, make decisions about clients, or monitor people at scale, it may then need a DPIA. There is a related question here: whether a human, rather than the software, is really making the decision. The rules on that changed in UK law this year, and our article on it is worth reading alongside this one.
It can be short
A DPIA does not have to be a heavy document. The ICO is clear that the process is flexible and scalable, that you can match the time and effort to the size of the project, and that it does not need to be a time-consuming process in every case. For a small firm assessing a straightforward tool, the finished assessment may be only a few pages.
Someone still has to be responsible for it. If your firm has a data protection officer, you must ask for their advice and write down what they said. Most small firms do not have one, and that is fine: the owner, or whoever runs the business, is then responsible, signs the assessment off and keeps it.
The small-business DPIA template
Here is the structure, following the ICO's own seven steps. Under each is one plain line you can overwrite with your own.
- Decide whether you need one. Screen the tool against the triggers above. If you decide you do not, write one line saying why and keep it. Example: "We screened our CV-screening tool. It scores applicants, so we are doing a full DPIA."
- Describe the processing. Say what the tool does, what personal data it uses, why, and who else the data goes to. Example: "The tool reads CVs and scores candidates against the role. It runs on our supplier's servers, and its AI provider processes the text."
- Consider who to consult. The ICO says you should seek the views of the people affected where practical, unless there is a good reason not to, and record why if you do not. Ask staff who understand the process and its risks as well. Example: "We will tell candidates the tool is used and how to ask for a human review, and we asked our hiring managers where it might go wrong."
- Test necessity and proportionality. Ask whether you need to do this at all, and whether there is a less risky way to get the same result. Note your lawful basis for using the data, and whether you could use less of it. Example: "Scoring saves time on 800 applications, and we use only the CV, not other records. A person still reviews the shortlist and can overturn it."
- Identify the risks to people. Name what could go wrong for the applicant or client, how serious the harm could be, and how likely it is. Keep the focus on them, not only on you. Example: "The tool could rank someone down for a reason we cannot see, and they would never know."
- Decide how to reduce each risk. Write the measure next to the risk. Example: "A hiring manager reviews the tool's rejections, and we can explain any score."
- Record what is left, sign it off, and keep it under review. Write down the risk that remains after your safeguards. If a high risk is still left that you cannot reduce, you must consult the ICO before you go ahead. Record who approved the DPIA and when, and revisit it if the tool or its use changes. Example: "Low risk left over. Approved by the owner, July 2026. Review if we change tools or add automated rejection."
Those are the seven parts of a DPIA. For a straightforward use they can still fit in a short document, as long as each answer carries enough detail for the risks involved. The ICO is updating some of its data-protection guidance after recent UK changes, so check its current DPIA pages when you run one.
The step firms get stuck on
In practice, firms get stuck on step two, describing the processing, because they cannot say who actually touches their data. And the tools keep changing without the firm being told. On 23 June 2026 Microsoft added OpenAI to the list of subprocessors that can handle Microsoft 365 Copilot data, and from 24 July it turned those models on for business customers by default. A firm that wrote its data description in May would already be out of date.
You do not have to trace every server yourself. A processor like Microsoft publishes its subprocessor list, and you can point to that in your description and check it now and then. What matters is knowing where to look, so a change like this one does not go unnoticed. Our checklist of what to ask before you buy an AI tool and our note on whether staff can put client data into a chatbot both look at this from the buying side.
Keep the person affected in mind while you do this. The law asks for the description for a reason: so that the applicant, client or employee whose data flows to those providers has someone who has thought about the risk to them. A firm that maps its own AI properly usually finds this is the hardest and most useful hour of the exercise. If you would like help with it, a readiness review walks a firm through where AI touches personal data and what to check.
The less-risky-alternatives question
One part of step four deserves a line of its own, because it is the part firms most often leave vague. The ICO expects you to ask whether there is another reasonable way to achieve the same result with less risk, and to note why you did not take it. This is the regulator's reading of the necessity test in the law, not a separate rule, but it is the part an assessor looks for. "We considered a simple keyword filter and a fully manual sift, and chose scoring with a human review because of the volume" is the kind of sentence that shows you actually considered it.
What to do this week
None of this needs a lawyer to begin. Look across the firm for any AI tool that touches people's personal data: hiring, client onboarding, anything that scores or sorts individuals. For each one, run the short screen. Where a tool helps decide about a person, do the two-page DPIA before it goes live, and keep the record. Where it clearly does not, note that decision and move on. Our AI readiness checklist is a good place to start.
If you would rather not work this out on your own, book a short call and we will help you map your AI use and the checks that go with it.
Do you need a DPIA for ChatGPT or Copilot?
It depends on what you do with it, not on the tool's name. Using an assistant to draft your own internal documents usually does not need a DPIA. Using it on people's personal data to make or shape decisions about them, or feeding it sensitive data at scale, can require one. Screen the specific use each time.
Who signs off a DPIA if we do not have a data protection officer?
The person responsible for the business. A data protection officer, where you have one, must be asked for advice and their view recorded. Most small firms do not have one, so the owner or senior person signs the assessment off and keeps it. You remain responsible for it even if you ask someone else to write it.
How long should a DPIA take for a small firm?
A straightforward assessment can often be done in an afternoon. The ICO says the process is meant to be scalable and need not be time-consuming, so a few pages that honestly work through the seven steps are usually enough. A bigger or more sensitive use deserves more time.
This is general information, not legal advice. Where a DPIA is genuinely required, or you are unsure whether your use is high risk, take advice from a data protection specialist.