Skip to main content

    DPIA template for AI in social care

    Published 19 September 2026 · 9 minute read · General information, not legal advice

    If your staff use AI with anything about the people you support, you almost certainly need a data protection impact assessment (DPIA). This template is pre-filled for the most common case in care: staff using an AI tool to help write notes, reports and letters.

    It follows the seven steps in the ICO’s DPIA guidance and the structure of its sample template, with example answers and the risks that actually come up. The full text is below, and as a Word file you can edit. It is general information, not legal advice.

    Download the DPIA template

    Editable .docx, about 17 KB. Free, no sign-up.

    Download Word file

    When a care provider needs a DPIA for AI

    UK GDPR requires a DPIA before any processing that is likely to result in a high risk to people’s rights and freedoms, in particular processing that uses new technologies. The ICO’s list of processing likely to be high risk includes:

    “Processing involving the use of new technologies, or the novel application of existing technologies (including AI).”
    ICO, Examples of processing likely to result in high risk [1]

    The ICO says a DPIA is required when that is combined with any other high-risk criterion, and care records usually bring two: health information, which is special category data, and people who may be vulnerable, including children and adults who lack capacity. CQC’s May 2026 statement on AI expects a DPIA too:

    “A DPIA assesses and documents risks to privacy and data subject rights to understand and minimise any interference with people’s rights, to enable lawful use of AI.”
    CQC, Artificial intelligence in health and social care, 21 May 2026 [2]

    In practice: if staff will use AI with anything about the people you support, complete a DPIA before they start.

    How to use this template

    • Download the Word file and replace everything in [square brackets].
    • Work through the seven steps in order. The example answers describe a typical setup; delete what does not apply and add what is specific to your service.
    • Rate each risk in step 5 for your own service, then record the measures and the residual risk in step 6.
    • Ask your data protection officer or lead to review it and sign off step 7. If a high risk remains that you cannot reduce, you must consult the ICO before you start.
    • Keep it with your governance evidence, pair it with an AI acceptable use policy, and review it whenever anything changes.

    The structure follows the ICO’s sample DPIA template and its seven steps, so if your organisation already uses the ICO template, the content here drops straight into it.

    The template

    The full text of the template, as it appears in the Word download. Example answers are shown in boxes; fill in the [highlighted fields] and rate the risks for your service.

    About this assessment

    Name of controller[Organisation name]
    Processing being assessed[e.g. Staff use of an AI writing tool to help draft care notes, reports and letters]
    DPIA owner[Name and role]
    Data protection officer or lead[Name and role]
    Date started[Date]
    Version[1.0]

    Step 1: Identify the need for a DPIA

    Explain what the project aims to achieve, what processing it involves, and why you identified the need for a DPIA.

    Example answer

    Staff want to use AI to reduce the time spent writing care notes, incident reports, care plan reviews and letters. The processing involves text about the people we support, which often includes health information about people who may be vulnerable. The ICO lists artificial intelligence among the processing likely to result in high risk, and CQC expects a DPIA before AI is used. We are therefore completing a DPIA before approving any AI tool for use with information about people.

    Step 2: Describe the processing

    Nature: how will you collect, use, store and delete the data? What is the source? Will you share it with anyone, including processors? Which types of processing identified as likely high risk are involved?

    Example answer

    Staff paste text they have written into our approved tool, [approved tool]. Before anything is sent to the AI model, the tool replaces names, addresses, NHS numbers and other identifiers with placeholders, and the member of staff reviews the detections and adds any that were missed. Only the placeholder version is sent to the AI model. The finished document is exported with the details restored and saved in [our care records system]. The link between placeholders and real details is held by [approved tool], encrypted, and deleted when the document is finished or at the end of [retention period]. [Approved tool] is our processor under a written data processing agreement. High-risk factors: innovative technology (AI), special category data, vulnerable individuals.

    Scope: what data is involved, including any special category or criminal offence data? How much, how often, how long will you keep it, how many people are affected, and what geographical area does it cover?

    Example answer

    Text about the people we support, their families and our staff, including health, medication, behaviour and safeguarding information (special category data) and occasionally information about offences. Around [number] documents a week, written by up to [number] staff, relating to up to [number] people. Documents in the tool are kept for no longer than [retention period]. Processing and storage take place in the UK.

    Context: what is your relationship with the individuals, how much control will they have, would they expect this use, do they include children or other vulnerable groups, and are there concerns or issues of public interest?

    Example answer

    The individuals are people we provide care to, some of whom lack capacity or are children, and who have limited control over what we record. They would not expect their details to be shared with an AI company, which is why identifiers are removed first. There is public concern about staff pasting personal information into consumer AI tools, and professional guidance, such as BASW's, advises against entering sensitive personal information into generic tools.

    Purposes: what do you want to achieve, what is the intended effect on individuals, and what are the benefits?

    Example answer

    To reduce the time spent writing so staff can spend more time with the people we support; to improve the clarity and consistency of records; and to replace unapproved use of consumer AI tools with a controlled route.

    Step 3: Consultation

    Describe how you will seek the views of individuals or their representatives, or why that is not appropriate, and who else you will involve, including processors and security experts.

    Example answer

    We will consult [staff representatives], [our data protection officer], [IT support] and the tool provider. We will explain the proposed use to [a residents' or families' forum, or advocates] and record their views. Where views are not sought, we will record why.

    Step 4: Assess necessity and proportionality

    Record your lawful basis, whether the processing achieves the purpose, whether there is another way, how you will prevent function creep, how you will ensure data quality and minimisation, what you will tell individuals, how you support their rights, how you ensure processors comply, and how you safeguard any international transfers.

    QuestionYour answer
    Lawful basis (UK GDPR Article 6)[Confirm with your DPO]
    Condition for special category data (Article 9)[e.g. Article 9(2)(h), provision of health or social care, with the matching condition in Schedule 1 to the Data Protection Act 2018. Confirm with your DPO.]
    Data minimisation[e.g. Identifiers are removed before text reaches the AI model; only the placeholder version is sent]
    Accuracy[e.g. Staff check every AI-assisted document against what happened before it is used, as set out in our AI policy]
    Preventing function creep[e.g. The tool is approved only for the uses listed in our AI policy]
    Information for individuals[e.g. Privacy notice updated to explain AI use; staff can explain it on request]
    Individuals' rights[e.g. Requests handled through our existing process; finished documents are held in our records system]
    Processor compliance[e.g. Written data processing agreement with the tool provider, dated [date]]
    International transfers[e.g. None: processing and storage in the UK, confirmed in the data processing agreement]

    Step 5: Identify and assess risks

    Describe each source of risk and its potential impact on individuals. Rate likelihood as remote, possible or probable; severity as minimal, significant or severe; and overall risk as low, medium or high. The risks below are the ones that most often arise when care providers use AI. Rate them for your service and add your own.

    Risk to individualsLikelihoodSeverityOverall risk
    1. Staff enter personal data into an unapproved AI tool, so it leaves our control with no contract or lawful basis[ ][ ][ ]
    2. The anonymisation step misses an identifier, which then reaches the AI model[ ][ ][ ]
    3. A person is identified from context left in the text, such as a rare condition, a place or a combination of details[ ][ ][ ]
    4. Inaccurate, exaggerated or invented AI output enters a care record and affects decisions about someone's care[ ][ ][ ]
    5. AI output uses biased or stigmatising language about a person[ ][ ][ ]
    6. The link between placeholders and real details is accessed without authorisation[ ][ ][ ]
    7. People are not told that AI is used in writing about their care[ ][ ][ ]
    8. Data is kept in the AI tool longer than necessary[ ][ ][ ]
    9. Data is processed outside the UK without an appropriate safeguard[ ][ ][ ]

    Step 6: Identify measures to reduce risk

    For each risk rated medium or high, record the measures that reduce or eliminate it, the effect (eliminated, reduced or accepted), the residual risk (low, medium or high) and whether the measure is approved.

    RiskMeasuresEffect on riskResidual riskApproved
    1Approve one AI route and name it in the AI policy; ban personal AI accounts for work; train staff; monitor use[ ][ ][ ]
    2Automatic detection of identifiers, with a review screen where staff confirm and add detections before anything is sent[ ][ ][ ]
    3Train staff to remove contextual identifiers; review detections; keep the placeholder map separate and secure[ ][ ][ ]
    4Staff check every AI-assisted document against what happened; the author remains accountable; AI never adds facts[ ][ ][ ]
    5Staff review wording before use; guidance on respectful, factual language in the AI policy[ ][ ][ ]
    6Placeholder map encrypted, held only by the tool provider and deleted when the document is finished; two-factor authentication on staff accounts[ ][ ][ ]
    7Privacy notice updated; staff able to explain AI use on request[ ][ ][ ]
    8Retention period set in the tool; finished documents exported to our records system[ ][ ][ ]
    9UK processing and storage confirmed in the data processing agreement[ ][ ][ ]

    Step 7: Sign off and record outcomes

    ItemName, position and dateNotes
    Measures approved by[ ]Integrate actions back into the project plan, with dates and responsibility for completion
    Residual risks approved by[ ]If accepting any residual high risk, consult the ICO before going ahead
    DPO advice provided[ ]The DPO should advise on compliance, the step 6 measures and whether processing can proceed
    Summary of DPO advice[ ]
    DPO advice accepted or overruled by[ ]If overruled, you must explain your reasons
    Consultation responses reviewed by[ ]If your decision departs from individuals' views, you must explain your reasons
    This DPIA will be kept under review by[ ]The DPO should also review ongoing compliance with the DPIA

    Download the DPIA template (Word)

    Questions

    Is a DPIA a legal requirement for using AI in care?

    A DPIA is legally required when processing is likely to result in a high risk. The ICO lists AI among the processing likely to be high risk when combined with another criterion, and care records usually involve health data about people who may be vulnerable, so in practice the answer is yes.

    Who should complete it?

    The person introducing the AI tool, usually a registered manager, nominated individual or project lead, with advice from your data protection officer or lead. The DPO should advise on the outcome and it should be signed off in step 7.

    What if a high risk remains after the measures?

    UK GDPR requires you to consult the ICO before you start the processing if the DPIA shows a high risk that you have not been able to reduce. The ICO’s sample template makes the same point in its sign-off section.

    Sources

    1. [1]ICO, Examples of processing likely to result in high risk
    2. [2]CQC, Artificial intelligence in health and social care: CQC’s role, expectations and plans (21 May 2026)
    3. [3]ICO, How do we do a DPIA?
    4. [4]ICO, Sample DPIA template (Word)
    5. [5]UK GDPR, Article 35 (data protection impact assessment)
    6. [6]UK GDPR, Article 36 (prior consultation)