The OECD.AI Policy Navigator

Our policy navigator is a living repository from more than 80 jurisdictions and organisations. Use the filters to browse initiatives and find what you are looking for.

Guidance on AI and Data Protection


Added by:   National contact point
Added on:   09 Jul 2025
Updated by:   OECD analyst
Updated on:   25 Dec 2025

The UK's Information Commissioners Office published a framework to audit AI and ensure data protection compliance.

Name in original language

Guidance on AI and Data Protection

Initiative overview

The framework gives a clear methodology for auditing as well as a toolkit for organisations to ensure compliance.The framework is split into four parts:1) addresses accountability and governance in AI, including data protection impact assessments (DPIAs);2) covers fair, lawful and transparent processing, including lawful bases, assessing and improving AI system performance, and mitigating potential discrimination;3) addresses data minimisation and security; and4) covers compliance with individual rights, including rights related to automated decision-making.The initiative has the following objective(s):To ensure data protection compliance.

Name of responsible organisation (in English)

Information Commissioners Office (ICO)

About the policy initiative


Organisation:

  • Information Commissioners Office (ICO)

Category:

  • Regulations, guidelines and standards

Initiative type:

  • Guidance document (instructions on how to implement a law, regulation, policy or other rule)

Status:

  • Active

Start Year:

  • 2020

Binding:

  • Non-binding

Other relevant urls: