As of 13 August 2026, AI cannot check an AI tool for UK GDPR risks.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
n/ait cannot be self-verified.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsA solicitor or qualified data protection specialist is the alternative; no price is provided here.
If this goes wrong: you approve a tool without identifying a material UK GDPR risk and your business carries the resulting compliance and operational consequences.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface gets you a draft, but you cannot verify it yourself. That is the catch.
How to actually do it
- Open the AI supplier's privacy notice, data processing terms, terms of service, security information, subprocessor list, international transfer information and retention information.
- Write down the proposed use, the people affected, the data categories, the business purpose, the expected retention and whether special category or criminal offence data is involved.
- Ask the supplier for any missing information about controller and processor roles, hosting locations, subprocessors, international transfers, model training, deletion, security and support access.
- Redact unnecessary personal data and confidential credentials from the documents, then paste the prompt and the labelled material into a chatbot.
- Compare every supplier-specific finding in the output with the exact passage in the supplied documents, and mark unsupported claims as unknown rather than accepting them.
- Send the risk register, unanswered questions and source documents to your solicitor or qualified data protection specialist before approving the tool or putting personal data into it.
Prompt
Assess the proposed use of an AI tool for UK GDPR risks in a UK business. This is not professional advice and must not be presented as a final legal conclusion. Business and use case: - Business type and location: [describe] - Proposed AI tool and supplier: [name and website] - What the tool will do: [describe] - Who will use it and why: [describe] - Whether the business decides the purposes and means of processing: [known, unknown or explain] - Personal data involved: [list categories, or say none known] - Special category or criminal offence data: [known, unknown or explain] - People affected: [customers, staff, children, patients, or other groups] - Expected volume and retention period: [details or unknown] - Existing safeguards and policies: [details] Paste below only information you are authorised to share. Redact names, contact details, account numbers, access tokens, unique identifiers and unnecessary personal data. Supplier material: [Paste the supplier privacy notice, data processing terms, terms of service, security information, subprocessor list, international transfer information and retention information. Label each document and include its date if shown.] Produce: 1. A factual description of the proposed processing and any unknowns. 2. A table with each potential UK GDPR risk, the evidence for it, the affected people or rights, the likelihood and impact as qualitative labels only, existing controls, and a proposed next action. 3. Separate checks for controller or processor roles, lawful basis, transparency, purpose limitation, data minimisation, accuracy, retention, security, processor terms, subprocessors, international transfers, data subject rights, automated decision-making, special category data and whether a DPIA may be needed. 4. A list of claims that cannot be assessed from the supplied material. 5. Questions to send to the supplier and questions for our solicitor or qualified data protection specialist. 6. A clear conclusion using only: lower apparent risk based on the supplied information, material unanswered questions, or do not proceed without specialist review. Do not invent facts, legal requirements, supplier practices or risk ratings. Quote or identify the source passage for every supplier-specific finding.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover supplier practices that are absent from the documents you provide.
- AI cannot decide whether your proposed processing has a lawful basis or whether your safeguards are legally sufficient.
- AI cannot turn an incomplete supplier answer into evidence that the processing is compliant.
- AI cannot carry responsibility for your business's controller decisions, contracts or data protection failures.
What makes this a NO: legal accountability, verification cost and private data access.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 0 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 4 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI do a GDPR risk assessment for my business?
- It can organise your documents, identify possible issues and draft a risk register. It cannot provide a final, reliable legal assessment where important facts or specialist judgement are missing.
- What information do I need to give AI to check an AI tool for GDPR risks?
- Give it the proposed use, data categories, people affected, retention, supplier privacy and processing terms, security information, subprocessors and transfer details. Remove unnecessary personal data and credentials, and label anything you do not know.
- Can I rely on an AI-generated GDPR assessment?
- No, not as the approval for a high-stakes business use. This is not professional advice, and a solicitor or qualified data protection specialist should check the assessment before you approve the processing.
- What should I do if an AI tool handles personal data?
- Document what data it receives, why it receives it, where it goes, how long it is kept and which supplier terms apply. Do not put it into production until a solicitor or qualified data protection specialist has dealt with material unanswered risks.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
- Can AI check my privacy notice for UK GDPR compliance?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.