ICO AI and Data Protection for Procurement
A buyer-focused guide to turning ICO AI and data-protection requirements into proportionate supplier questions and evidence requests.
The Information Commissioner's Office guidance on AI and data protection explains how data-protection obligations apply when AI systems process personal data. For procurement teams, the practical question is not simply whether a supplier says it is “GDPR compliant”; it is whether the proposed service gives the buyer enough evidence and control to meet its own obligations.
The ICO notes that its AI guidance is under review following changes made by the Data (Use and Access) Act, so buyers should check the current guidance and obtain legal advice where needed.
1. Establish the parties and processing roles
Start by identifying who determines the purposes and means of processing, which organisations act as processors or subprocessors, and which model or infrastructure providers sit behind the supplier.
Request evidence showing:
- contracting entity and processing roles;
- data-processing agreement structure;
- material subprocessors and locations;
- model/API providers that may receive personal data;
- responsibility for responding to rights requests and incidents;
- change controls when the supplier's processing chain changes.
Do not assume that a SaaS supplier is automatically a processor for every AI feature.
2. Understand the data lifecycle
Map the data used at each stage of the service, including prompts, uploaded files, retrieval sources, logs, feedback, generated outputs and any training or fine-tuning data.
For each data flow, establish:
- purpose and lawful basis where relevant;
- categories of personal data;
- storage and processing locations;
- retention and deletion rules;
- access controls;
- whether data is used to train, improve or evaluate models;
- whether the data may be embedded in models, indexes or derived artefacts.
3. Ask for accountability evidence, not a policy statement
The ICO describes accountability as responsibility for complying with data-protection law and demonstrating that compliance. A DPIA can be an important part of that evidence for higher-risk processing.
Procurement evidence may include:
- DPIA or supplier input suitable for the buyer's DPIA;
- records of processing and data-flow documentation;
- privacy and governance ownership;
- risk decisions and mitigations;
- evidence that policies are operating in practice;
- change and incident records.
4. Test lawfulness, fairness and transparency in the intended use
A supplier's generic privacy notice cannot establish that the buyer's specific use is lawful or fair. Ask how the product communicates AI involvement, limitations and data use to affected people, and whether the design supports the buyer's transparency duties.
Where the service influences consequential decisions, examine bias, discrimination, statistical performance and the practical ability for people to challenge outcomes.
5. Examine individual rights and meaningful human oversight
The ICO guidance highlights that individual rights apply wherever personal data is used across the AI lifecycle, and gives particular attention to solely automated decisions with legal or similarly significant effects.
Buyer questions can include:
- Can relevant personal data be located and retrieved?
- Can correction, restriction, deletion or objection be supported where applicable?
- What information is available to explain significant automated processing?
- Where is human review required?
- Does the reviewer have enough competence, authority and information to intervene meaningfully?
6. Assess security and data minimisation
AI may create new data flows and security risks, but ordinary data-protection principles still apply. Require evidence that the service only processes data appropriate to the intended purpose and that technical and organisational controls are proportionate to risk.
Cross-reference security evidence with the NCSC Secure AI procurement guide.
7. Put material privacy facts into the contract
Where procurement relies on specific privacy facts, preserve them through contractual controls. Depending on scope this can include:
- training and improvement restrictions;
- retention and deletion commitments;
- location and transfer controls;
- subprocessor notification or approval;
- assistance with rights requests and DPIAs;
- incident notification;
- audit/evidence rights;
- model/provider change notification;
- termination and verified deletion.
8. Create re-evaluation triggers
Revisit the data-protection assessment when material facts change, such as a new model provider, new data class, new significant decision use, new training practice, new subprocessor, major architecture change or regulatory update.
How AI TrustMark fits
AI TrustMark can independently verify supplier and product evidence such as data flows, policies, subprocessors, security controls, operational practice and evidence provenance. It does not provide legal advice or certify UK GDPR compliance.
The public guide explains the evidence areas. Organisation-specific data-flow mapping, DPIA support, tailored questionnaires, evidence-gap analysis, contract schedules and independent verification are professional services.
Return to the AI Procurement Knowledge Base or use the AI Procurement Route Finder.