ICO launches new AI and data protection guidance

The Information Commissioner’s Office (ICO) has launched new guidance on how to ensure data protection compliance when deploying artificial intelligence (AI).

Following an open consultation earlier this year, which techUK responded to, the ICO has released new guidance on AI and data protection. This is the culmination of two years of research and part of the ICO’s commitment to enable good data protection practice in AI.

The guidance is intended to “mitigate the risks specifically arising from a data protection perspective, explaining how data protection principles apply to AI projects without losing sight of the benefits such projects can deliver”. The guidance includes recommendations on best practice and technical measures that organisations can use to mitigate risks but is not intended as a guide to the ethical or design principles of the use of AI.

This guidance is primarily aimed at two audiences, those with a compliance focus (including the ICO's own auditors) and technology specialists. We believe from the guidance published that a “toolkit designed to provide further practical support to organisations auditing the compliance of their own AI systems” is also forthcoming.

It is worth noting that this guidance is not a statutory code. There is no penalty if you fail to adopt good practice recommendations, as long as you find another way to comply with the law. The ICO have used the terms ‘must’ and ‘should’ to mark the distinction between compliance with data protection law and general good practice.

The structure of guidance relates to key data protection principles- accountability and governance, fairness and transparency, data minimisation and security and individual rights.

The guidance states that when it comes to trade-offs, the “right balance depends on the specific sectoral and social context you operate in, and the impact the processing may have on individuals”. Significant emphasis is placed on the importance of Data Protection Impact Assessments (DPIA’s) for AI systems using personal data.

The guidance also points to the need to take care to identify and understand the relationship between the data controller/data processor. The guidance states that Government will explore this issue in more detail when they come to reviewing the Cloud Computing Guidance in 2021.

The ICO has said that it will continue to adapt the guidelines to keep pace with the “fast moving innovation and evolution” of AI. The ICO would like to continue to consult with those using the guidance to understand how it works in practice and are open to ideas on the tools they could create to support implementation of the guidance. To provide feedback, please provide your details at the bottom of this page here.

Finally, if you’d like to discuss any aspect of this guidance or better understand what it means for your organisation, please get in touch.

  • Katherine Mayes

    Katherine Mayes

    Programme Manager | Cloud, Data, Analytics and AI
    T 020 7331 2019

Share this


We are looking forward to our session this PM and leading on the work of WP4 of the #EVET 2.0 @RD_ESC and Randolph… https://t.co/hB7ytGPsJ9
We are excited to announce @ShadiARazak, CTO/CISO at @CynationLtd as techUK's #CloudSecurityChampion for October. Y… https://t.co/qM7b0YdDdZ
If you have a digital solution that can help improve housing or prevent homelessness then join our pitch fest on 05… https://t.co/EkJVTXF20r
Join us for our next Partnering & Networking event with @VSfromCrisis on 05 Nov to connect with innovators across h… https://t.co/rZu7NoSkDl
Looking forward to having you there! #GeospatialFuture https://t.co/q3lcNWdhvT
Don't forget to sign up to techUK's upcoming #AIlunchtimelectures on 28 October 12:00-13:00, when @helen_mayhew of… https://t.co/VOra7E3jmM
Become a Member

Become a techUK Member

By becoming a techUK member we will help you grow through:

Click here to learn more...