GovernanceCore
EnforcedUnited KingdomExtraterritorial reach

ICO Guidance on AI and Data Protection

The ICO's operative guidance on lawful AI under UK data protection law, covering fairness, accountability, transparency and the trade-offs in AI-specific DPIAs. Backed by real enforcement powers.

Status
Enforced
Jurisdiction
United Kingdom · National
Adopted
Jul 30, 2020
In force
Jul 30, 2020
Enforcement date
Regulator / body
Information Commissioner's Office
Sectors
Cross-sector
Extraterritorial
Yes

Key dates

  • Jul 30, 2020
    First published
  • Mar 15, 2023
    Updated following the ICO's AI and data protection risk toolkit

Risk areas addressed

PrivacyBias & discriminationTransparencyHuman oversightGovernance & accountability

Who it applies to

Organisations processing personal data with AI systems under UK GDPR and the Data Protection Act 2018.

Penalties & enforcement

UK GDPR enforcement: up to £17.5M or 4% of global annual turnover.

Enforced by: Information Commissioner's Office

Getting ready

UK ICO AI Guidance is enforced by Information Commissioner's Office. Its obligations are already live, so a gap is a present exposure rather than a future one. In practice that means knowing which of your AI systems fall in scope across every sector you operate in, holding assessments that speak to privacy, bias & discrimination and transparency, and being able to produce that evidence on request, including for systems built outside the jurisdiction.

Official source

Information Commissioner's Office

Related regulations

← All regulations