For Heads-of · Practitioner

Missing DPIA for high-risk AI processing

AI processing likely to result in high risk to individuals proceeds without a documented Data Protection Impact Assessment.

  • high
  • data-protection
  • dpia
  • uk-gdpr

How it happens

A new AI system or use case that profiles individuals, processes special category data, or operates at scale is built and shipped without anyone first running the DPIA that UK GDPR requires for likely-high-risk processing.

Why it matters

A missing DPIA isn't just a paperwork gap, it means the specific privacy risks of the system were never systematically identified, so any mitigations in place are incidental rather than designed.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
UK General Data Protection RegulationArticle 35Data protection impact assessment
Guidance on AI and data protectionAccountabilityAccountability and governance

Related resources

The external sources behind this risk, from the Resources library.