As of 13 August 2026, AI can only partly build a data protection policy for your UK business.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsiubenda is a purpose-built software alternative that generates and maintains privacy and cookie compliance documents.
If this goes wrong, your policy can appear complete while missing controls that matter to your actual processing, leaving your business exposed when something goes wrong.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the ICO and GOV.UK data protection guidance, then create a working document containing the business details listed in the prompt.
- Gather your data map, supplier and processor list, contracts, retention schedule, security procedures, breach procedure, rights-request process and staff training records.
- Paste the completed business details and documents into a chatbot with the prompt, asking it to keep unknown information marked as [TO CONFIRM].
- Export the draft policy, assumptions register, questions and source-check list into your internal document system.
- Ask the people responsible for IT, HR, marketing, customer operations and procurement to answer the marked questions and correct the descriptions of real processing activities.
- Compare every legal or regulatory statement and source against current ICO and GOV.UK guidance, and compare every operational statement against your systems, contracts and procedures.
- Send the revised policy and gap register to a UK data protection solicitor or suitably qualified data protection specialist before adopting it.
- Approve a named owner, review process and implementation actions, then circulate the signed-off policy to the people who must follow it.
Prompt
Act as a UK data protection policy drafting assistant, not a solicitor. Draft an internal data protection policy for this business using only the information I provide and clearly mark every missing fact or decision as [TO CONFIRM]. Do not invent processing activities, legal bases, retention periods, security controls, contracts, certifications or regulatory requirements. Keep the policy separate from a public privacy notice. Business details: - Business name: [BUSINESS NAME] - Sector and size: [SECTOR AND APPROXIMATE SIZE] - Locations and countries served: [LOCATIONS] - Staff, contractors and volunteers: [PEOPLE WHO HANDLE PERSONAL DATA] - Data protection lead or responsible person: [NAME OR ROLE] - Personal data processed: [CATEGORIES OF DATA] - People whose data is processed: [CUSTOMERS, STAFF, SUPPLIERS, USERS, ETC.] - Main systems and suppliers: [SYSTEMS, CLOUD SERVICES, SOFTWARE AND PROCESSORS] - Sharing and transfers: [WHO DATA IS SHARED WITH AND WHETHER IT LEAVES THE UK] - Purposes and processing activities: [WHAT YOU DO WITH THE DATA] - Retention rules: [KNOWN RETENTION PERIODS OR RULES] - Security measures: [ACCESS, BACKUPS, DEVICE, PASSWORD, ENCRYPTION AND OTHER CONTROLS] - Existing procedures: [SUBJECT ACCESS, BREACHES, DELETION, CORRECTION, COMPLAINTS AND STAFF TRAINING] - Relevant documents: [CONTRACTS, PROCESSOR TERMS, RECORDS, RISK ASSESSMENTS AND POLICIES] Produce: 1. A practical policy with headings, scope, responsibilities, data protection principles, handling procedures, individual rights, security, breach response, supplier management, records, training, monitoring and review. 2. A separate assumptions and gaps register showing what I must confirm before adoption. 3. A list of questions for the business owner and data protection lead. 4. A list of provisions that need checking against current ICO guidance, UK GDPR, the Data Protection Act 2018 and our actual contracts and systems. 5. Draft wording only where the facts support it. Where the facts do not support a conclusion, explain the issue without deciding it. Use plain British English. Do not claim that the policy makes the business compliant. Cite the source or say [SOURCE TO CHECK] for each legal or regulatory proposition. State clearly that this is a working draft and not professional advice.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover processing activities that nobody tells it about, including informal spreadsheets, shared inboxes and supplier arrangements.
- AI cannot decide whether your stated purposes, legal bases, retention periods and international transfers are correct for your particular operations.
- AI cannot verify that your policy matches the controls your systems and staff actually use.
- AI cannot accept responsibility for a compliance failure, investigation or data breach.
- AI cannot provide the specialist judgement needed for unusual, high-risk or disputed processing.
What caps this at PARTLY: legal accountability, verification cost and context depth.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 2 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT write a data protection policy for my business?
- It can produce a useful working draft from your business information, including responsibilities, procedures and a list of gaps. It cannot confirm that the policy fits your processing or makes you compliant, so a serious case needs a UK data protection solicitor or suitably qualified data protection specialist.
- Is an AI data protection policy legally compliant?
- Not by default. A policy can sound correct while missing processing activities, supplier terms, retention decisions or security controls that apply to your business.
- What information does AI need to write a data protection policy?
- Give it your data map, processing purposes, categories of people and data, systems, suppliers, sharing arrangements, retention rules, security controls, rights procedures and responsible roles. It also needs your existing contracts and procedures if the policy is to describe how the business actually operates.
- Do I need a solicitor to check an AI data protection policy?
- For a simple internal starting point, you can compare general wording with ICO and GOV.UK guidance. If the policy covers sensitive or high-risk processing, complex suppliers, international transfers, a data breach or a regulatory concern, have a UK data protection solicitor or specialist check it.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
- Can AI check my privacy notice for UK GDPR compliance?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.