Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →ICO Guidance on AI and Data Protection
Issued by
UK Information Commissioner's Office
- September 30, 2026 · Source update — Restored this entry's own page. Confirmed the guidance is under review following the Data (Use and Access) Act. (Cody Maxwell)
Guidance from the Information Commissioner's Office (ICO) on AI and data protection sets out how UK GDPR obligations apply to organisations that develop or deploy AI systems processing personal data. It covers lawful basis, fairness, transparency, and the technical and organisational measures required to protect individuals. The guidance is currently under active review following amendments introduced by the Data (Use and Access) Act and may be subject to material change.
Applies To
Overview
Originally issued to help organisations align AI system design and deployment with UK GDPR requirements, this ICO guidance addresses the full lifecycle of personal data use in AI contexts, from data collection and model training through to automated decision-making and output generation. Key provisions cover identifying an appropriate lawful basis for processing, meeting transparency obligations toward data subjects, and implementing fairness assessments to detect and mitigate discriminatory outcomes. The ICO has signalled that the Data (Use and Access) Act introduces changes that directly affect the guidance, placing it under formal review as of September 2026. Organisations relying on this guidance for compliance programmes should monitor the ICO website for revised versions and avoid treating current text as settled. Enforcement of UK GDPR in AI contexts continues under the ICO's existing powers during the review period, meaning compliance obligations remain active even while the guidance itself is in flux.
Key Requirements
- •Identify and document a valid lawful basis under UK GDPR for each stage of personal data processing in AI pipelines, including training, validation, and inference.
- •Conduct and record fairness assessments to identify risks of discrimination or unjustified differential treatment arising from AI outputs.
- •Provide intelligible transparency information to data subjects about how their data is used in AI systems, including meaningful explanations where automated decisions are made.
- •Implement appropriate technical and organisational measures, such as data minimisation, access controls, and model governance, proportionate to the risk posed by the AI system.
- •Carry out a Data Protection Impact Assessment for high-risk AI processing activities before deployment.
- •Monitor the ICO website for revised guidance following the Data (Use and Access) Act review, as current text is subject to change and updated obligations may apply retrospectively to existing systems.
What Your Organization Must Do
- →Audit all AI systems that process personal data and map each processing activity to a documented lawful basis under UK GDPR.
- →Review existing fairness and bias assessments against the ICO's current criteria and schedule re-assessment once revised guidance is published.
- →Update privacy notices and data subject information materials to ensure transparency disclosures accurately reflect AI-driven processing, including any automated decision-making logic.
- →Re-examine vendor and processor contracts to confirm that data protection obligations, including audit rights and technical measures, extend to any third-party AI components.
- →Assign ownership of the ICO guidance review to a named compliance lead who will track ICO publications and assess the impact of any changes on current AI programmes.
- →Treat existing Data Protection Impact Assessments for AI systems as living documents and schedule reviews to coincide with publication of the updated ICO guidance.
Governance Controls
Operational controls that implement requirements from this regulation.
