Home · Business · IT, Data & Security · Software development
As of 13 August 2026, AI can only partly check your app for UK GDPR risks.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededdeveloper
Who has to check ita professional
What the alternative costsThe alternative is a data protection consultant or solicitor; no price is stated here.
If this goes wrong, you miss a material processing risk and your organisation remains responsible for the resulting compliance or security consequences.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, developer skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open your repository, deployment configuration and current privacy documentation, and remove live personal data, credentials, access tokens and production secrets before copying anything.
- Write a data-flow description covering what personal data the app collects, why it collects it, who can access it, where it is hosted, which suppliers receive it, how long it is kept and how users exercise their rights.
- Paste the data-flow description, relevant application code, authentication and authorisation logic, storage and logging configuration, cookie or tracking code, deletion workflows and supplier details into a chatbot using the supplied prompt.
- Add the current ICO or GOV.UK material your organisation uses, and ask the model to distinguish evidence-based technical findings from questions requiring a DPO, privacy solicitor or security lead.
- Run the technical tests proposed for each finding, then compare the results with the relevant code, live configuration and documented data flow rather than accepting an untested claim.
- Send the prioritised findings and unresolved legal questions to your DPO or a UK privacy solicitor, and record their decisions, owners and remediation dates in your risk register.
Prompt
Act as a cautious UK privacy and application-security reviewer. Review only the code, architecture, data-flow description, configuration and policies I provide below. Do not claim that the app is compliant, do not invent facts, and do not treat missing information as evidence that a control exists. Identify possible risks under the UK GDPR and, where relevant, the Privacy and Electronic Communications Regulations. Separate technical observations from legal or governance questions that need a qualified UK data protection professional. For every finding, give: 1. severity: low, medium or high, with no claim of legal certainty; 2. the exact evidence from my material; 3. the affected personal data, processing activity or system component; 4. why it may create a UK privacy or security risk; 5. a practical remediation or investigation step; 6. a test I can run to check the technical part; 7. what information is still missing; 8. whether the point should be reviewed by my DPO, privacy solicitor or security lead. Check specifically for unnecessary collection or retention, unclear purposes, excessive permissions, insecure storage or transmission, access control failures, logging of personal data, secrets in code, third-party processors and transfers, cookies and tracking, subject-rights workflows, deletion and correction, breach detection, data protection by design, and documentation of lawful basis. Do not reproduce personal data or secrets in your answer. Mark any issue that cannot be assessed from the supplied material. At the end, produce a prioritised action list and a separate list titled "Questions for a UK data protection professional". Use the ICO and GOV.UK sources I provide for source checking, and quote links only when they are present in those materials. Application context: [describe the app, users, countries, purposes and environments] Data-flow and supplier information: [paste a data-flow description, hosting details, processors, retention rules and transfer information] Relevant code and configuration, with secrets and live personal data removed: [paste selected files or excerpts] Current privacy, security and retention documents: [paste the relevant text] Sources supplied for checking: [paste current ICO or GOV.UK links and extracts]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot know about processing, suppliers or staff practices that are absent from the material you provide.
- AI cannot decide your lawful basis, assess every individual's reasonable expectation or make a defensible risk decision for your organisation.
- AI cannot validate that production configuration, retention jobs, access permissions and deletion processes match the code it reviews.
- AI cannot accept responsibility for a breach, an unlawful processing decision or an incomplete record of processing activities.
- AI can point to possible ICO or GOV.UK material, but a serious case still needs a DPO or UK privacy solicitor to interpret the facts.
What caps this at PARTLY: legal accountability, verification cost and context depth.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can AI check my app for UK GDPR risks?
- Partly. It can review code, architecture and documents for possible issues such as excessive collection, weak access controls, insecure logging and missing deletion workflows. It cannot establish that your app is compliant or replace a DPO or UK privacy solicitor.
- Can ChatGPT review my code for GDPR compliance?
- It can review supplied code for technical warning signs, but it cannot certify GDPR compliance. Your organisation remains responsible for the legal decisions, and the review must include the data flows, suppliers, operational controls and current UK context.
- Can AI tell me if my app is GDPR compliant?
- No. AI can produce a structured risk review, but compliance depends on facts it may not have, including purposes, lawful basis, retention, international transfers, contracts and how the app operates in production. This is not professional advice, and a serious case needs your DPO or a UK privacy solicitor.
- What should I give AI to check my app for UK GDPR risks?
- Give it a redacted data-flow description, relevant code, authentication and authorisation logic, storage and logging settings, cookie or tracking behaviour, deletion workflows, supplier details and privacy documents. Remove personal data and secrets, and include the ICO or GOV.UK material you want it to use for checking.
Nearby answers
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.