For Heads-of · Practitioner
Missing DPIA for high-risk AI processing
AI processing likely to result in high risk to individuals proceeds without a documented Data Protection Impact Assessment.
- high
- data-protection
- dpia
- uk-gdpr
How it happens
A new AI system or use case that profiles individuals, processes special category data, or operates at scale is built and shipped without anyone first running the DPIA that UK GDPR requires for likely-high-risk processing.
Why it matters
A missing DPIA isn't just a paperwork gap, it means the specific privacy risks of the system were never systematically identified, so any mitigations in place are incidental rather than designed.
Mitigating controls
The controls that address this risk, ranked by effectiveness.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| UK General Data Protection Regulation | Article 35 | Data protection impact assessment |
| Guidance on AI and data protection | Accountability | Accountability and governance |
Related resources
The external sources behind this risk, from the Resources library.