LegisGate · UK DPIA

The UK DPIA: our half written, and the ICO’s guidance beside every question.

The ICO publishes DPIA guidance and a sample template, which makes the UK the straightforward case. In LegisGate the DPIA opens when the determination calls for one, your half is laid out as guided questions with the ICO’s own guidance beside them, and it exports as a Word document in the ICO sample template.

Basis
UK GDPR Art. 35 · DPA 2018
Authority
Information Commissioner’s Office
Format
ICO sample template

How a UK DPIA is done in LegisGate

Six steps. The first three happen without you.

Add the AI use case and answer fifteen minutes of intake. Everything below follows from those answers, and nothing is asked twice.

Step 01

The determination says whether a DPIA is called for

Article 35 of the UK GDPR applies on conditions. The determination tests your AI use case against them. If a DPIA is not required, you have the dated record saying so.

Step 02

The draft opens on the use case

Where a DPIA is required, it opens as a draft the moment the determination runs. Choose the ICO sample template as its version. If the use case also reaches the EU, the same DPIA covers both.

Step 03

Our half is written

Each section opens with what your intake already answered and the findings that belong to that section, each cited to the UK GDPR or the DPA 2018. That half is read-only.

Step 04

You answer your half, with the ICO beside you

Each guided question says why it is asked, and its Guidance block quotes the ICO’s DPIA guidance and sample template on that point, with the licence they are published under. We quote it. We do not turn it into advice.

Step 05

Send each question to the person who knows

Assign a question, or a whole section, to a teammate with a due date, or invite a contributor by email for the questions that are theirs. A contributor creates a password from the link and sees only the questions assigned to them. Each answer is Open, Answered, In review, then Accepted, or Returned with a note.

Step 06

You rate the risks on the ICO’s scale, export, and record the review

The assessment register lists each risk the determination raised, and uses the likelihood and severity scale from the ICO’s sample template. Your organisation gives the rating, before and after the measures against it. The DPIA exports as a Word document in the ICO sample template, with a status line on its cover. Mark reviewed records who reviewed it and when; it does not say the assessment is sufficient.

Monitoring is included and automatic: when the law behind a question changes, that question is flagged, and the activity log records who answered, accepted, assigned and exported.

Your first five AI use cases are free, with everything included: the laws, the obligations, the written assessments and monitoring. No card. Past five, it is a subscription.

What it looks like

The reason for the question, and the ICO’s own words about it.

A question in your half, opened: the article that requires it, the ICO’s guidance with its source and licence, your answer, and who it is assigned to.

One question in a DPIA, opened to show the Why we ask line with the article that requires it, the Guidance block quoting the ICO with its Open Government Licence attribution, the answer, and the Assign, Return and Accept controls

The two halves

Everything in our half is research. Everything in yours is judgement.

The split is not arbitrary. One side has an answer that can be checked against a source. The other has a defensible answer that depends on your organisation and its appetite for risk.

ICO sectionOur halfYour half
Describe the processing Nature, scope, context and purposes, drawn from your intake Anything the intake could not know about internal workflow
Consultation process Whether the shape of this processing points toward consulting data subjects Who you consulted, or the reasoned decision not to
Necessity and proportionality The lawful-basis framing and the questions the section expects answered The answer. The paragraph the assessment turns on
Identify and assess risks The risks the determination raised, each cited to where it comes from Likelihood and severity for your population, in the assessment register
Identify measures to reduce risk The controls the obligations expect, each tied to its provision Which you actually operate, and what you will do about the rest
Sign off and record outcomes — All of it. The DPO’s advice and the controller’s decision

We bring the regulatory intelligence and the intake. You bring the privacy and legal judgment for your use case and organization. The document is built to hold both.

The division of labour

What this is not. LegisGate produces regulatory intelligence and assessment-preparation materials. Nothing we produce is legal advice, a legal opinion, a certification, or a determination of compliance, and no document we deliver satisfies a legal obligation on its own. Sufficiency is determined by your counsel. A completed DPIA from us does not satisfy Art. 35. It is the document your controller and DPO complete and sign. The ICO’s template is a sample, not a mandatory form.

The half that is yours

We will not write your necessity argument.

It depends on facts only your organisation knows, and it has to be defended by the people who made the decision. We write everything around it.

Talk to usWe're here to help
UK GDPR DPIA in the ICO's Own Template | LegisGate