Home · Business · Legal & Compliance · Data protection & GDPR

PARTLY

As of 13 August 2026, AI can only partly complete a UK GDPR transfer risk assessment.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

2 hoursto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsA data protection solicitor or specialist adviser is the alternative; no price is given in the supplied sources.

If this goes wrong, you may approve a transfer without adequate protection and expose your organisation to regulatory action, contractual disputes or harm to individuals.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 2 hours until you can act on the result.

    How to actually do it

    1. Open your organisation's data map, supplier register and international transfer records, then list every exporter, importer, sub-processor, access country, storage country and support country involved.
    2. Gather the relevant data processing agreement, transfer clauses, supplier security documentation, sub-processor list, audit reports, access-control details, encryption information and incident records.
    3. Remove unnecessary personal data from the working material, replace names and identifiers with neutral labels, and paste the factual transfer details and documents into the prompt.
    4. Ask the model to produce the assessment, keeping verified facts, assumptions and missing evidence in separate sections and leaving unsupported conclusions unresolved.
    5. Compare each drafted data flow, country, processing purpose, safeguard and supplier statement against the source records, then correct the draft and mark any unresolved item as evidence required.
    6. Send the corrected assessment and its source pack to your DPO, privacy lead or UK data protection solicitor to verify the legal analysis, residual risk and proposed decision before the transfer proceeds.

    Prompt

    Act as a drafting assistant, not as a solicitor. Prepare a UK GDPR international transfer risk assessment for the proposed transfer described below. Use only the information and documents I provide, and do not invent facts, safeguards, laws or conclusions.
    
    Transfer details:
    - Exporter: [organisation and UK location]
    - Importer and group companies involved: [names and locations]
    - Countries where data is accessed, stored or supported: [countries]
    - Data subjects: [categories of people]
    - Personal data: [categories of data]
    - Special category or criminal offence data: [yes/no and details]
    - Purpose and processing activities: [details]
    - Frequency and duration: [details]
    - Controller, processor or joint-controller roles: [details]
    - Existing transfer mechanism: [details]
    - Contractual, technical and organisational safeguards: [details]
    - Supplier and sub-processor information: [details]
    - Relevant policies, audits, certifications and incident history: [details]
    
    Documents and sources supplied:
    [Paste the relevant contract clauses, supplier answers, technical evidence, policies and current ICO or government guidance here.]
    
    Produce:
    1. A clear description of the data flows and all countries involved.
    2. The transfer mechanism and the assumptions needed to assess it.
    3. A table separating verified facts, missing evidence and assumptions.
    4. An assessment of the laws and practices that could affect access to the data in each destination country, citing the supplied sources and identifying anything that must be checked against current official guidance.
    5. An assessment of whether the safeguards reduce the identified risks, without treating a policy statement as proof that a control works.
    6. Residual risks, affected individuals, mitigating actions, owners and deadlines, leaving unknown fields marked as 'evidence required'.
    7. A draft decision section with the options 'proceed subject to actions', 'pause pending evidence' and 'seek specialist advice'. Do not choose the final option for me.
    8. A short list of questions for the importer and supplier, plus a list of points that a UK data protection solicitor or suitably qualified DPO must verify.
    
    Keep the assessment specific to the evidence supplied. Do not claim that a transfer is lawful merely because a contract or transfer mechanism exists. This is not professional advice, and the final decision must be approved by the organisation's accountable privacy or legal function.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot discover hidden onward transfers, remote access routes or sub-processors that your records do not disclose.
  • AI cannot prove that a supplier's encryption, access controls or deletion process works in practice.
  • AI cannot reliably decide how foreign laws and government access powers apply to your exact data flow without specialist legal analysis and current evidence.
  • AI cannot accept the organisation's accountability for the transfer decision or provide the professional sign-off a serious case needs.

What caps this at PARTLY: legal accountability, verification cost and judgement under ambiguity.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta1
Total6 / 10

FAQ

Can ChatGPT complete a UK GDPR transfer risk assessment?
It can produce a useful draft from your data flows, contracts and supplier evidence. It cannot prove the safeguards, resolve uncertain foreign-law issues or take responsibility for the final transfer decision, so a DPO or UK data protection solicitor must check a serious assessment.
What information does AI need for a UK GDPR transfer risk assessment?
Give it the full data flow, every country involved, the parties' roles, the data categories, the transfer mechanism, supplier and sub-processor details, and evidence of technical and organisational safeguards. Missing evidence should be marked as missing rather than filled with assumptions.
Is an AI-generated transfer risk assessment legally valid?
An AI-generated document is not a substitute for the organisation's own assessment and accountability. It may support your records, but the legal reasoning, evidence and final decision need review by your privacy function or a UK data protection solicitor.
Can AI decide whether my international data transfer is lawful?
No. AI can organise the evidence, identify questions and draft risk analysis, but it cannot safely make the final decision where the facts, foreign law or safeguards are uncertain. This is not professional advice; a serious case needs a UK data protection solicitor or suitably qualified DPO.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.