ICO Guidance on AI and Data Protection
The ICO's operative guidance on lawful AI under UK data protection law, covering fairness, accountability, transparency and the trade-offs in AI-specific DPIAs. Backed by real enforcement powers.
Key dates
- Jul 30, 2020First published
- Mar 15, 2023Updated following the ICO's AI and data protection risk toolkit
Risk areas addressed
Who it applies to
Organisations processing personal data with AI systems under UK GDPR and the Data Protection Act 2018.
Penalties & enforcement
UK GDPR enforcement: up to £17.5M or 4% of global annual turnover.
Enforced by: Information Commissioner's Office
UK ICO AI Guidance is enforced by Information Commissioner's Office. Its obligations are already live, so a gap is a present exposure rather than a future one. In practice that means knowing which of your AI systems fall in scope across every sector you operate in, holding assessments that speak to privacy, bias & discrimination and transparency, and being able to produce that evidence on request, including for systems built outside the jurisdiction.