DPIA template for AI in social care
Published 19 September 2026 · 9 minute read · General information, not legal advice
If your staff use AI with anything about the people you support, you almost certainly need a data protection impact assessment (DPIA). This template is pre-filled for the most common case in care: staff using an AI tool to help write notes, reports and letters.
It follows the seven steps in the ICO’s DPIA guidance and the structure of its sample template, with example answers and the risks that actually come up. The full text is below, and as a Word file you can edit. It is general information, not legal advice.
Download the DPIA template
Editable .docx, about 17 KB. Free, no sign-up.
When a care provider needs a DPIA for AI
UK GDPR requires a DPIA before any processing that is likely to result in a high risk to people’s rights and freedoms, in particular processing that uses new technologies. The ICO’s list of processing likely to be high risk includes:
“Processing involving the use of new technologies, or the novel application of existing technologies (including AI).”
The ICO says a DPIA is required when that is combined with any other high-risk criterion, and care records usually bring two: health information, which is special category data, and people who may be vulnerable, including children and adults who lack capacity. CQC’s May 2026 statement on AI expects a DPIA too:
“A DPIA assesses and documents risks to privacy and data subject rights to understand and minimise any interference with people’s rights, to enable lawful use of AI.”
In practice: if staff will use AI with anything about the people you support, complete a DPIA before they start.
How to use this template
- Download the Word file and replace everything in [square brackets].
- Work through the seven steps in order. The example answers describe a typical setup; delete what does not apply and add what is specific to your service.
- Rate each risk in step 5 for your own service, then record the measures and the residual risk in step 6.
- Ask your data protection officer or lead to review it and sign off step 7. If a high risk remains that you cannot reduce, you must consult the ICO before you start.
- Keep it with your governance evidence, pair it with an AI acceptable use policy, and review it whenever anything changes.
The structure follows the ICO’s sample DPIA template and its seven steps, so if your organisation already uses the ICO template, the content here drops straight into it.
The template
The full text of the template, as it appears in the Word download. Example answers are shown in boxes; fill in the [highlighted fields] and rate the risks for your service.
About this assessment
| Name of controller | [Organisation name] |
|---|---|
| Processing being assessed | [e.g. Staff use of an AI writing tool to help draft care notes, reports and letters] |
| DPIA owner | [Name and role] |
| Data protection officer or lead | [Name and role] |
| Date started | [Date] |
| Version | [1.0] |
Step 1: Identify the need for a DPIA
Explain what the project aims to achieve, what processing it involves, and why you identified the need for a DPIA.
Example answer
Staff want to use AI to reduce the time spent writing care notes, incident reports, care plan reviews and letters. The processing involves text about the people we support, which often includes health information about people who may be vulnerable. The ICO lists artificial intelligence among the processing likely to result in high risk, and CQC expects a DPIA before AI is used. We are therefore completing a DPIA before approving any AI tool for use with information about people.
Step 2: Describe the processing
Nature: how will you collect, use, store and delete the data? What is the source? Will you share it with anyone, including processors? Which types of processing identified as likely high risk are involved?
Example answer
Staff paste text they have written into our approved tool, [approved tool]. Before anything is sent to the AI model, the tool replaces names, addresses, NHS numbers and other identifiers with placeholders, and the member of staff reviews the detections and adds any that were missed. Only the placeholder version is sent to the AI model. The finished document is exported with the details restored and saved in [our care records system]. The link between placeholders and real details is held by [approved tool], encrypted, and deleted when the document is finished or at the end of [retention period]. [Approved tool] is our processor under a written data processing agreement. High-risk factors: innovative technology (AI), special category data, vulnerable individuals.
Scope: what data is involved, including any special category or criminal offence data? How much, how often, how long will you keep it, how many people are affected, and what geographical area does it cover?
Example answer
Text about the people we support, their families and our staff, including health, medication, behaviour and safeguarding information (special category data) and occasionally information about offences. Around [number] documents a week, written by up to [number] staff, relating to up to [number] people. Documents in the tool are kept for no longer than [retention period]. Processing and storage take place in the UK.
Context: what is your relationship with the individuals, how much control will they have, would they expect this use, do they include children or other vulnerable groups, and are there concerns or issues of public interest?
Example answer
The individuals are people we provide care to, some of whom lack capacity or are children, and who have limited control over what we record. They would not expect their details to be shared with an AI company, which is why identifiers are removed first. There is public concern about staff pasting personal information into consumer AI tools, and professional guidance, such as BASW's, advises against entering sensitive personal information into generic tools.
Purposes: what do you want to achieve, what is the intended effect on individuals, and what are the benefits?
Example answer
To reduce the time spent writing so staff can spend more time with the people we support; to improve the clarity and consistency of records; and to replace unapproved use of consumer AI tools with a controlled route.
Step 3: Consultation
Describe how you will seek the views of individuals or their representatives, or why that is not appropriate, and who else you will involve, including processors and security experts.
Example answer
We will consult [staff representatives], [our data protection officer], [IT support] and the tool provider. We will explain the proposed use to [a residents' or families' forum, or advocates] and record their views. Where views are not sought, we will record why.
Step 4: Assess necessity and proportionality
Record your lawful basis, whether the processing achieves the purpose, whether there is another way, how you will prevent function creep, how you will ensure data quality and minimisation, what you will tell individuals, how you support their rights, how you ensure processors comply, and how you safeguard any international transfers.
| Question | Your answer |
|---|---|
| Lawful basis (UK GDPR Article 6) | [Confirm with your DPO] |
| Condition for special category data (Article 9) | [e.g. Article 9(2)(h), provision of health or social care, with the matching condition in Schedule 1 to the Data Protection Act 2018. Confirm with your DPO.] |
| Data minimisation | [e.g. Identifiers are removed before text reaches the AI model; only the placeholder version is sent] |
| Accuracy | [e.g. Staff check every AI-assisted document against what happened before it is used, as set out in our AI policy] |
| Preventing function creep | [e.g. The tool is approved only for the uses listed in our AI policy] |
| Information for individuals | [e.g. Privacy notice updated to explain AI use; staff can explain it on request] |
| Individuals' rights | [e.g. Requests handled through our existing process; finished documents are held in our records system] |
| Processor compliance | [e.g. Written data processing agreement with the tool provider, dated [date]] |
| International transfers | [e.g. None: processing and storage in the UK, confirmed in the data processing agreement] |
Step 5: Identify and assess risks
Describe each source of risk and its potential impact on individuals. Rate likelihood as remote, possible or probable; severity as minimal, significant or severe; and overall risk as low, medium or high. The risks below are the ones that most often arise when care providers use AI. Rate them for your service and add your own.
| Risk to individuals | Likelihood | Severity | Overall risk |
|---|---|---|---|
| 1. Staff enter personal data into an unapproved AI tool, so it leaves our control with no contract or lawful basis | [ ] | [ ] | [ ] |
| 2. The anonymisation step misses an identifier, which then reaches the AI model | [ ] | [ ] | [ ] |
| 3. A person is identified from context left in the text, such as a rare condition, a place or a combination of details | [ ] | [ ] | [ ] |
| 4. Inaccurate, exaggerated or invented AI output enters a care record and affects decisions about someone's care | [ ] | [ ] | [ ] |
| 5. AI output uses biased or stigmatising language about a person | [ ] | [ ] | [ ] |
| 6. The link between placeholders and real details is accessed without authorisation | [ ] | [ ] | [ ] |
| 7. People are not told that AI is used in writing about their care | [ ] | [ ] | [ ] |
| 8. Data is kept in the AI tool longer than necessary | [ ] | [ ] | [ ] |
| 9. Data is processed outside the UK without an appropriate safeguard | [ ] | [ ] | [ ] |
Step 6: Identify measures to reduce risk
For each risk rated medium or high, record the measures that reduce or eliminate it, the effect (eliminated, reduced or accepted), the residual risk (low, medium or high) and whether the measure is approved.
| Risk | Measures | Effect on risk | Residual risk | Approved |
|---|---|---|---|---|
| 1 | Approve one AI route and name it in the AI policy; ban personal AI accounts for work; train staff; monitor use | [ ] | [ ] | [ ] |
| 2 | Automatic detection of identifiers, with a review screen where staff confirm and add detections before anything is sent | [ ] | [ ] | [ ] |
| 3 | Train staff to remove contextual identifiers; review detections; keep the placeholder map separate and secure | [ ] | [ ] | [ ] |
| 4 | Staff check every AI-assisted document against what happened; the author remains accountable; AI never adds facts | [ ] | [ ] | [ ] |
| 5 | Staff review wording before use; guidance on respectful, factual language in the AI policy | [ ] | [ ] | [ ] |
| 6 | Placeholder map encrypted, held only by the tool provider and deleted when the document is finished; two-factor authentication on staff accounts | [ ] | [ ] | [ ] |
| 7 | Privacy notice updated; staff able to explain AI use on request | [ ] | [ ] | [ ] |
| 8 | Retention period set in the tool; finished documents exported to our records system | [ ] | [ ] | [ ] |
| 9 | UK processing and storage confirmed in the data processing agreement | [ ] | [ ] | [ ] |
Step 7: Sign off and record outcomes
| Item | Name, position and date | Notes |
|---|---|---|
| Measures approved by | [ ] | Integrate actions back into the project plan, with dates and responsibility for completion |
| Residual risks approved by | [ ] | If accepting any residual high risk, consult the ICO before going ahead |
| DPO advice provided | [ ] | The DPO should advise on compliance, the step 6 measures and whether processing can proceed |
| Summary of DPO advice | [ ] | |
| DPO advice accepted or overruled by | [ ] | If overruled, you must explain your reasons |
| Consultation responses reviewed by | [ ] | If your decision departs from individuals' views, you must explain your reasons |
| This DPIA will be kept under review by | [ ] | The DPO should also review ongoing compliance with the DPIA |
Download the DPIA template (Word)
Questions
Is a DPIA a legal requirement for using AI in care?
A DPIA is legally required when processing is likely to result in a high risk. The ICO lists AI among the processing likely to be high risk when combined with another criterion, and care records usually involve health data about people who may be vulnerable, so in practice the answer is yes.
Who should complete it?
The person introducing the AI tool, usually a registered manager, nominated individual or project lead, with advice from your data protection officer or lead. The DPO should advise on the outcome and it should be signed off in step 7.
What if a high risk remains after the measures?
UK GDPR requires you to consult the ICO before you start the processing if the DPIA shows a high risk that you have not been able to reduce. The ICO’s sample template makes the same point in its sign-off section.
Sources
- [1]ICO, Examples of processing likely to result in high risk
- [2]CQC, Artificial intelligence in health and social care: CQC’s role, expectations and plans (21 May 2026)
- [3]ICO, How do we do a DPIA?
- [4]ICO, Sample DPIA template (Word)
- [5]UK GDPR, Article 35 (data protection impact assessment)
- [6]UK GDPR, Article 36 (prior consultation)