Snap’s errors provide a useful steer from the ICO on how to produce a compliant DPIA for generative AI products
Following an investigation into concerns that Snap had not adequately assessed the data protection risks posed by its new ‘My AI’ chatbot, the Information Commissioner’s Office (ICO) issued a Preliminary Enforcement Notice (PEN) to Snap on 6 October 2023 for failing to:
- carry out a compliant data protection impact assessment (DPIA) prior to launching My AI on Snapchat on 27 February 2023, and
- consult the ICO, despite concluding in its DPIA that My AI would result in a high risk to users aged 13-17 in the absence of measures taken to mitigate the risk.
The PEN set out the ICO’s intention to issue Snap with an Enforcement Notice requiring it to cease processing personal data of Snapchat users in the UK for any purpose connected to My AI until a revised DPIA had been carried out, provided to the ICO, and confirmed, in writing, by the ICO to comply with the requirements of Article 35 UK GDPR.
On 22 November 2023, Snap provided the ICO with a revised version of its DPIA – the lucky “Fifth DPIA” – which the ICO decided complied with the law, as confirmed in its Decision of 21 May 2024.
The decision recounts the reasons why Snap’s four previous DPIAs failed to comply with Article 35 GDPR and how the Fifth DPIA finally met the requirements. As such it provides an instructive read for any organisation embarking on a DPIA for a generative AI (GenAI) product.
The decision sets out how the Article 35 GDPR requirements + the ICO’s DPIA guidance apply to assessing the data protection risks of a GenAI product, providing granular detail about the information required to produce a compliant DPIA. This includes:
- Systematically describing the nature, scope and context of the processing in connection with the GenAI product, including:
- what data it uses/collects/generates/infers, how, and for what purposesany data sharing involved (e.g. with LLM and advertising providers)who can access the data (e.g. users, support and development staff)applicable retention periods for the different types of data
- the wider context, such as:
- public concern relating to GenAI
- relative novelty of the technology
- individuals’ expectations regarding the types of data used and the purposes for which they are used
- reliability and accuracy of AI-generated outputs
- over-reliance on AI-generated outputs
- similarities and differences between use of GenAI products and traditional query-based online services
- Assessing the necessity and proportionality of the processing, including how use of GenAI might affect the nature of the personal data shared and the type of processing operations compared to traditional online search functions and query-based services.
- Assessing the risks posed to users of the GenAI product and others, including those arising from:
- any targeting/profiling of users for marketing purposes
- processing of special category data
- use by vulnerable groups such as children, and
- the novelty and complexity of GenAI products.
Notably this should include risks to all rights and freedoms protected by the European Convention on Human Rights – not just data protection rights. And if the GenAI will be used by children, describing how the processing complies with the principles in the ICO’s Age Appropriate Design Code.
Snap’s Fifth DPIA identified the following risks, which are likely to be relevant to many GenAI products:

- Identifying specific mitigatory measures to address specific risks resulting from the GenAI product’s processing of personal data, the effect of such measures on the relevant risk and the resulting residual risk level. This should also cover alternative measures considered and explain why they were not deemed to be necessary, appropriate or feasible in the circumstances.
- Consulting the ICO before deploying the GenAI product if the DPIA identifies any residual high risk to users in the absence of measures taken to mitigate that risk (as required by Article 36 UK GDPR).
The decision also covers some useful detail about determining which group companies are controllers for particular processing purposes and the application of Article 3 GDPR (territorial scope) to non-UK based group companies. (The ICO found that both the ‘establishment’ and ‘offering services’ criteria applied to US company, Snap Inc.)
However, some may feel that this was a missed opportunity for the ICO to provide useful precedent on some key substantive compliance issues regarding GenAI, e.g.:
- Whether Snap’s retention periods accord with user expectations and comply with the storage limitation principle. (Interaction data are retained until deleted by the user or for the lifetime of their account; metadata for 180 days or until a user deletes their account.)
- The validity of particular legal bases for various GenAI-related processing activities. (Snap relies on consent, contract and legitimate interests (Arts 6(1)(a), (b) and (f)) and on consent and public interest (Arts 9(2)(a) and (g)) and the journalistic, academic, artistic and literary purposes exemption (paragraph 26, Part 5, Schedule 2 to the DPA 2018) for special category data.)
- The adequacy and suitability of Snap’s risk mitigation measures, such as the information/advice given to users via Snap’s just-in-time notices and Safety Support Page, its child-specific mitigatory measures including parental control and oversight via its “Family Centre”, technical purpose restrictions (no essay-writing!) and allowing users to delete their data and messages.
None of this fell within the remit of the ICO’s investigation or decision – it was solely concerned with the compliance of the My AI DPIA, not with any of its conclusions or the processing or mitigatory measures it described.
The decision seems to indicate significant leniency on the ICO’s behalf towards Snap, despite Snap being a large, well-resourced, market-dominant, global social media company with several million UK users including many under 18s.
The decision recounts a litany of errors by Snap, including 4 failed attempts to produce an adequate DPIA and replicating an erroneously recorded “high risk” rating for risks posed to 13–17-year-old users across all four previous versions of the DPIA, with Snap claiming it was always meant to be “medium risk”.
On the facts, Snap launched a GenAI product without having performed a compliant DPIA – so was in technical breach of the GDPR between launching My AI in February 2023 and producing the Fifth DPIA in November 2023. Plus, Snap initially refused to provide the ICO with all previous versions of the DPIA and related documents in unredacted form, despite several informal requests and two formal Information Notices from the ICO.
Perhaps smaller organisations can take some comfort from this – if the ICO is willing to show such leniency to a company like Snap despite the circumstances described above, surely it should extend even greater leniency to less well-resourced organisations that cooperate with the ICO.
DPIAs are undoubtedly challenging documents to complete – do get in touch if you need help to produce one or would benefit from a legal review of your existing DPIAs.
For more information on the relevant areas mentioned in this article please click below: