PARTLY

As of 13 August 2026, AI can only partly build a data protection policy for your UK business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsiubenda is a purpose-built software alternative that generates and maintains privacy and cookie compliance documents.

If this goes wrong, your policy can appear complete while missing controls that matter to your actual processing, leaving your business exposed when something goes wrong.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the ICO and GOV.UK data protection guidance, then create a working document containing the business details listed in the prompt.
    2. Gather your data map, supplier and processor list, contracts, retention schedule, security procedures, breach procedure, rights-request process and staff training records.
    3. Paste the completed business details and documents into a chatbot with the prompt, asking it to keep unknown information marked as [TO CONFIRM].
    4. Export the draft policy, assumptions register, questions and source-check list into your internal document system.
    5. Ask the people responsible for IT, HR, marketing, customer operations and procurement to answer the marked questions and correct the descriptions of real processing activities.
    6. Compare every legal or regulatory statement and source against current ICO and GOV.UK guidance, and compare every operational statement against your systems, contracts and procedures.
    7. Send the revised policy and gap register to a UK data protection solicitor or suitably qualified data protection specialist before adopting it.
    8. Approve a named owner, review process and implementation actions, then circulate the signed-off policy to the people who must follow it.

    Prompt

    Act as a UK data protection policy drafting assistant, not a solicitor. Draft an internal data protection policy for this business using only the information I provide and clearly mark every missing fact or decision as [TO CONFIRM]. Do not invent processing activities, legal bases, retention periods, security controls, contracts, certifications or regulatory requirements. Keep the policy separate from a public privacy notice.
    
    Business details:
    - Business name: [BUSINESS NAME]
    - Sector and size: [SECTOR AND APPROXIMATE SIZE]
    - Locations and countries served: [LOCATIONS]
    - Staff, contractors and volunteers: [PEOPLE WHO HANDLE PERSONAL DATA]
    - Data protection lead or responsible person: [NAME OR ROLE]
    - Personal data processed: [CATEGORIES OF DATA]
    - People whose data is processed: [CUSTOMERS, STAFF, SUPPLIERS, USERS, ETC.]
    - Main systems and suppliers: [SYSTEMS, CLOUD SERVICES, SOFTWARE AND PROCESSORS]
    - Sharing and transfers: [WHO DATA IS SHARED WITH AND WHETHER IT LEAVES THE UK]
    - Purposes and processing activities: [WHAT YOU DO WITH THE DATA]
    - Retention rules: [KNOWN RETENTION PERIODS OR RULES]
    - Security measures: [ACCESS, BACKUPS, DEVICE, PASSWORD, ENCRYPTION AND OTHER CONTROLS]
    - Existing procedures: [SUBJECT ACCESS, BREACHES, DELETION, CORRECTION, COMPLAINTS AND STAFF TRAINING]
    - Relevant documents: [CONTRACTS, PROCESSOR TERMS, RECORDS, RISK ASSESSMENTS AND POLICIES]
    
    Produce:
    1. A practical policy with headings, scope, responsibilities, data protection principles, handling procedures, individual rights, security, breach response, supplier management, records, training, monitoring and review.
    2. A separate assumptions and gaps register showing what I must confirm before adoption.
    3. A list of questions for the business owner and data protection lead.
    4. A list of provisions that need checking against current ICO guidance, UK GDPR, the Data Protection Act 2018 and our actual contracts and systems.
    5. Draft wording only where the facts support it. Where the facts do not support a conclusion, explain the issue without deciding it.
    
    Use plain British English. Do not claim that the policy makes the business compliant. Cite the source or say [SOURCE TO CHECK] for each legal or regulatory proposition. State clearly that this is a working draft and not professional advice.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta2
Total6 / 10

FAQ

Can ChatGPT write a data protection policy for my business?
It can produce a useful working draft from your business information, including responsibilities, procedures and a list of gaps. It cannot confirm that the policy fits your processing or makes you compliant, so a serious case needs a UK data protection solicitor or suitably qualified data protection specialist.
Is an AI data protection policy legally compliant?
Not by default. A policy can sound correct while missing processing activities, supplier terms, retention decisions or security controls that apply to your business.
What information does AI need to write a data protection policy?
Give it your data map, processing purposes, categories of people and data, systems, suppliers, sharing arrangements, retention rules, security controls, rights procedures and responsible roles. It also needs your existing contracts and procedures if the policy is to describe how the business actually operates.
Do I need a solicitor to check an AI data protection policy?
For a simple internal starting point, you can compare general wording with ICO and GOV.UK guidance. If the policy covers sensitive or high-risk processing, complex suppliers, international transfers, a data breach or a regulatory concern, have a UK data protection solicitor or specialist check it.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.