Home News ICO fines NHS Trust £750K · UK · Enforcement · Editor-reviewed · 31 Mar 2026
UK ICO · Enforcement · 31 March 2026

ICO fines NHS Trust £750,000 over AI diagnostic DPIA failure

An English NHS Foundation Trust deployed a commercial AI triage tool on radiology workflows without running a Data Protection Impact Assessment, without algorithmic-bias testing, and without documenting the lawful basis for the downstream profiling. The Commissioner called it "a systemic governance failure at the deployment stage, not a technical one."

The Information Commissioner's Office today imposed a fine of £750,000 on a large NHS Foundation Trust in the North West for deploying an AI-powered radiology triage tool without conducting the mandatory Data Protection Impact Assessment under Article 35 of the UK GDPR. The decision is the ICO's first public enforcement action specifically framed around AI deployment governance rather than a downstream personal-data breach.

The tool — deployed across two hospital sites from late 2024 — classified chest X-rays as high/low priority before clinician review. An internal audit in Q4 2025 found the triage model had been trained on a non-representative dataset and under-prioritised radiographs from patients with darker skin pigmentation. The Trust had no record of bias testing, no DPIA, and no clinical safety case mapped against the Article 35 process.

The ICO's decision notice names three specific failures: (i) no DPIA before processing began, despite automated decisions affecting individuals' access to timely care; (ii) no documented lawful basis for the secondary profiling used in performance monitoring; (iii) retrofit paperwork produced under audit pressure that the Commissioner characterised as "backdated and internally inconsistent."

The £750,000 figure is understood to reflect a discount for cooperation during the investigation but is the largest AI-related fine the Commissioner has issued to date. The Trust has been given six months to demonstrate a compliant DPIA regime, bias-testing cadence, and a clinical-safety-case register covering all AI-assisted pathways, with independent audit reports due at month 3 and month 6.

Operational notes
  • DPIAs are mandatory under Article 35 when AI is used for automated decisions affecting individuals — clinical pathways included.
  • Retrofit DPIAs after deployment do not cure the breach; the ICO treats them as aggravating.
  • Bias testing on training data must be documented before go-live, not retrospectively.
  • Where AI is clinically-deployed, the DPIA interlocks with DCB0129 / DCB0160 clinical-safety standards — treat as one workstream, not two.
  • UK GDPR fine cap remains higher of £17.5m or 4% global turnover — this £750K reflects a cooperation discount.
Sources

Every claim in this story is anchored to one of the primary sources above. The PAI editor reviews each alert against source before publication. Claim ID: pai-20260331-ico-nhs-adm-dpia.

Related