Home · Business · Legal & Compliance · Data protection & GDPR
As of 13 August 2026, AI cannot check whether a supplier meets UK GDPR requirements.
This still needs a person who signs their name to it.
Can you do it?
30 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsHumata is a commercial AI tool for asking questions of long PDFs and getting cited answers.
If this goes wrong: you approve a supplier that cannot meet its data-protection obligations and expose your organisation to a compliance, security or contractual problem.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open your supplier onboarding or procurement record and write down the service, the personal data involved, your organisation's role, the supplier's role and every country from which the data may be accessed.
- Ask the supplier for its data processing agreement, security information, subprocessor list, international-transfer details, retention and deletion terms, breach process, audit arrangements and answers to your data-protection questionnaire.
- Remove unnecessary personal data and paste the supplier documents and written answers into a document-review tool, keeping document names and page numbers intact.
- Paste the supplied prompt and ask the tool to produce an evidence table with a status, source, missing evidence and follow-up question for each requirement.
- Send the follow-up questions to the supplier and add the dated answers and any replacement documents to the evidence set, without treating an unsupported assertion as proof of a control.
- Compare the completed evidence table with your organisation's supplier-risk process and refer unresolved high-risk gaps, unusual international transfers or disputed legal points to a solicitor or qualified data-protection specialist before approval.
Prompt
Act as a UK GDPR evidence-review assistant, not a solicitor and not the final decision-maker. Assess the supplier materials below against the requirements relevant to a controller using a processor, including the written processing instructions, confidentiality, security measures, subprocessor controls, assistance with data-subject rights, breach support, deletion or return of data, audit rights, international transfers and records of processing where evidenced. For each point, provide: status as evidenced, partly evidenced, not evidenced or not applicable; the exact source and page or section; what the document actually says; what is missing; and a precise follow-up question for the supplier. Separate documentary evidence from the supplier's unverified assertions. Do not say that the supplier is compliant, certify compliance, invent facts, infer technical controls from marketing language, or give a final legal conclusion. End with a short list of high-risk gaps and the evidence a solicitor or qualified data-protection specialist should review before approval. Supplier name: [SUPPLIER NAME] Services and data processing: [DESCRIBE THE SERVICE AND PERSONAL DATA] Your organisation's role: [CONTROLLER, PROCESSOR OR OTHER] Countries where data is accessed or stored: [COUNTRIES OR UNKNOWN] Supplier documents and answers: [PASTE THE MATERIALS HERE]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot prove that the supplier's stated security controls operate in practice.
- AI cannot inspect systems, interview the supplier's staff or verify every subprocessor and data flow.
- AI cannot decide whether the evidence is proportionate to your processing risk or whether a contractual gap is acceptable.
- AI cannot take responsibility for approving the supplier or for the consequences of unlawful processing.
- AI cannot replace specialist review where international transfers, special category data, large-scale monitoring or a serious breach is involved.
What makes this a NO: legal accountability, verification cost and private data access.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 1 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 3 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI check if a supplier is GDPR compliant?
- No, not reliably as a final check. AI can compare the supplier's documents with a UK GDPR checklist and identify missing evidence, but it cannot prove that the supplier's claims are true or take responsibility for your decision.
- What documents should I ask a supplier for under UK GDPR?
- Ask for the data processing agreement, security measures, subprocessor list, international-transfer information, retention and deletion terms, breach process, data-subject rights assistance and audit arrangements. The exact evidence depends on the service, the data and the risks involved.
- Can ChatGPT review a supplier's data processing agreement?
- It can review the text for missing or unclear provisions and produce follow-up questions. It cannot certify the agreement, verify the supplier's controls or decide whether the contractual risk is acceptable.
- Do I need a solicitor to check a supplier's GDPR compliance?
- You may not need one for a routine first-pass evidence check, but a serious or high-risk case needs a solicitor or qualified data-protection specialist. This is not professional advice, and your organisation remains responsible for the supplier decision.
Nearby answers
- Can AI check whether my employee monitoring complies with UK GDPR?NO
- Can AI complete a data protection impact assessment?NO
- Can AI create a record of processing activities for my business?PARTLY
- Can AI draft a response to a subject access request?PARTLY
- Can AI write a data retention policy for my business?NO
- Can AI assess the severity of a personal data breach?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.