Skip to content

Product1 publisher3 min readPublished

The ICO wants one documented role decision for every processing step in your model chain

Its contracts and third parties section asks AI buyers to decide and record controller, processor or joint controller roles across the whole supply chain, and it warns that the guidance is under review after the Data (Use and Access) Act.

The Product Desk · Product desk

Illustration accompanying The ICO wants one documented role decision for every processing step in your model chain

What happened

  • The ICO's contracts and third parties control measure asks for full consideration of the controller, processor or joint controller relationship throughout the supply chain of an AI system.
  • It also asks that the decision reached on that relationship be documented across all proposed processing activities, not just for the immediate supplier deal.
  • The stated risk is that where no decision on the controller and processor relationship has been made, all parties are likely to fail their obligations under the UK GDPR.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Role mapping stops being a legal formality after signature: the buyer has to settle who set the purpose for each processing operation while the deal is still negotiable, because the contract is supposed to record a decision already made.
  • constraint Compliance now has a documented basis to block a budgeted purchase, since an unmitigable bias finding is written into the framework as a reason not to buy.
  • exposure The consequence of skipping the role question lands on everyone in the chain, so a buyer cannot push the risk onto the model provider by leaving it undecided.
  • precedent Contract language drafted precisely to this text may be audited against a rewritten version. Buyers have reason to write terms that survive a change of guidance.

The page names senior management and compliance-focused roles, including DPOs, as accountable for the governance and data protection risk management of an AI system, with a note that a technical specialist may be needed to explain some of the details [7][8]. On a Monday that becomes a table. One row per distinct set of processing operations, with its purpose written next to it [9]. One row might be a fine-tune a team paid for; another is the prompt and output logging a vendor runs by default. The assessment is meant to cover the whole supply chain, not the tier-one vendor alone [10].

In my view the common failure is treating the processor addendum the vendor sent as the answer. The section asks for something earlier and messier than a signature: evidence that the relationship was considered at all, in emails, meeting minutes, model design or specification documents [11]. It also wants a requirement inside DPIA templates to assess it [12]. The ICO also wants conclusions that line up with its own and with sectoral or EU guidance on controllers and processors [13]. The contract comes after that work, formally documenting and agreeing the relationship [14], and privacy information has to communicate it [15]. For finding the decision makers in each activity, the page suggests information flow mapping [16].

Across the two control measures on the page there are 20 bulleted expectations: seven under the roles measure, thirteen under pre-procurement due diligence [27][28][29]. The procurement half is where compliance can refuse the purchase. Due diligence on accuracy, bias and design trade-offs is expected before procuring AI systems, datasets or coding [17]. One bullet tells buyers to "do not procure the services or datasets if bias or discrimination cannot be mitigated" [22]. Others are contract terms with numbers in them. Decide the acceptable level of accuracy before procurement [19]. Put accuracy-based KPIs or SLAs into written contracts with suppliers [21], and get guarantees on the source of the information, coding or models used to build the AI [20]. Request documentation from the model developer covering the training process, feature selection and hyperparameter tuning [23]. Fairness evidence is itemised too, down to demographic parity analysis [24].

Then the banner at the top. Because of changes made by the Data (Use and Access) Act, the ICO says this guidance is under review and may be subject to change [5]. It points to its Plans for new and updated guidance page for what gets updated and when [6]. The ICO does not say whether contracts already signed have to be reopened, or which of these bullets will move. The roles question comes from the UK GDPR, which the page cites as the source of the obligations [4]. The evidence list around it is the ICO's own, so a contract papered tightly to today's thirteen bullets may be checked later against a different thirteen.

The forcing function is two columns. For each distinct set of processing operations, write who decided its purpose and where that decision is recorded. Rows with a name in the first column and nothing in the second are the ones the ICO says are likely to leave all parties failing their obligations under the UK GDPR [4].

What to watch

  • The ICO's Plans for new and updated guidance page, which is where the timing of this AI section's rewrite is meant to appear.
  • Whether model vendors start supplying fairness metrics and demographic parity analysis on request, or only under NDA.
  • Whether DPIA templates in circulation add the controller and processor question as a required field.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories