Home · Business · Legal & Compliance · Data protection & GDPR

PARTLY

As of 13 August 2026, AI can only partly create a personal data deletion procedure.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsA purpose-built compliance product such as iubenda is an alternative for generating and maintaining privacy compliance documents; the supplied source does not give a price.

If this goes wrong: you delete data that must be retained, fail to remove data from a connected system or miss a legal exception, leaving your organisation to deal with the consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the ICO guidance on individual rights and your organisation's current privacy policy, retention schedule and data-protection procedures.
    2. Gather the names of every relevant database, file store, email system, backup, processor and shared service, plus the role responsible for each one.
    3. Paste the gathered information into the prompt, replacing each bracketed slot and leaving [TO CONFIRM] where the organisation does not yet know the answer.
    4. Ask the model to produce the procedure, deletion log and fictional-data testing checklist exactly in the requested format.
    5. Compare every stated process, retention period, exemption, response step and escalation route with the ICO material, your internal records and processor contracts, marking unresolved points for the data protection lead.
    6. Run the testing checklist with fictional records across each listed system, record failures, correct the procedure and obtain review from your DPO or a UK data-protection solicitor before putting it into use.

    Prompt

    Create a UK workplace personal data deletion procedure for [organisation name]. This is a drafting aid, not professional advice. Use the information below and do not invent systems, deadlines, legal bases, exemptions, retention periods or approval rights. Where information is missing, write [TO CONFIRM].
    
    Organisation context:
    - Business activities: [description]
    - Staff who handle requests: [roles]
    - Data protection lead or DPO: [role or none]
    - Relevant processors and third parties: [list]
    - Systems and storage locations: [list]
    - Existing retention schedule: [paste or describe]
    - Existing privacy policy and data protection procedures: [paste]
    - Request channels: [email, form or other]
    - Internal approval and escalation route: [details]
    
    Produce:
    1. Purpose, scope and definitions.
    2. Roles and responsibilities.
    3. How to receive and authenticate a deletion request.
    4. How to identify the requester, relevant data, systems, processors and backups without exposing personal data unnecessarily.
    5. How to decide what can be deleted, what may need to be retained, and what requires escalation under UK GDPR and related UK rules.
    6. A step-by-step workflow with owners, evidence to record and completion criteria.
    7. How to send the response to the requester.
    8. How to handle processors, shared systems, backups, disputes, exemptions and complaints.
    9. A deletion log template containing the minimum fields needed to demonstrate what was considered and done.
    10. A short testing checklist using fictional data only.
    
    Separate confirmed facts from assumptions. Flag every legal or factual point that needs checking against current ICO guidance, the organisation's retention schedule or advice from a UK data-protection solicitor. Do not decide whether a specific request is lawful without the required facts. Use plain British English and make the procedure practical for a small or medium-sized organisation.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • The model cannot know where your organisation actually stores copies, exports, backups or shadow records unless you provide and maintain that information.
  • It cannot decide reliably whether a particular record must be retained or may be deleted without the facts, legal basis and retention obligations for that case.
  • It cannot confirm that processors and connected systems have completed deletion or that backups will behave as the procedure assumes.
  • It cannot take responsibility for a missed request, unlawful deletion or incomplete evidence trail.
  • It cannot replace testing the procedure against your live access controls and escalation arrangements.

What caps this at PARTLY: legal accountability, context depth and verification cost.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT write a GDPR data deletion procedure?
Yes, it can draft a useful procedure if you provide your systems, processors, retention rules, request route and internal responsibilities. It cannot know whether the procedure matches your organisation or whether a specific deletion request is lawful.
Is an AI-generated data deletion procedure legally compliant?
Not automatically. Compare it with current ICO guidance, your records and processor contracts, then have a data protection lead or UK data-protection solicitor check the points that involve legal judgement. This is not professional advice.
What should a personal data deletion procedure include?
It should cover receiving and authenticating requests, locating data, checking retention duties and exemptions, contacting processors, handling backups, recording decisions, responding to the requester and escalating disputes. It should also define owners and evidence for each step.
Who should check an AI-written GDPR deletion procedure?
Your data protection lead or DPO should check whether it reflects your systems, contracts and operating controls. A serious or disputed case needs a UK data-protection solicitor because the organisation remains accountable for the result.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.