PARTLY

As of 13 August 2026, AI can only partly create a GDPR data deletion procedure.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsA purpose-built alternative is Scribe, which turns software workflows into step-by-step guides automatically.

If this goes wrong: you delete records that must be retained or fail to delete personal data within the required process, leaving your organisation to handle the consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the ICO guidance on individual rights and your organisation's current data retention policy, then save the relevant source pages for checking.
    2. Gather a list of every live system, SaaS provider, processor, email store, paper archive and backup that may contain personal data.
    3. Gather your current retention schedule, legal holds, regulatory record-keeping duties, request channels, identity-check method and staff roles.
    4. Paste those materials into the prompt and ask the chatbot to produce the procedure, leaving unknown facts as [TO CONFIRM].
    5. Compare every drafted system, role, retention period, exception, deadline and ICO or GOV.UK citation with your source documents and mark unsupported statements for correction.
    6. Ask your data protection officer or a UK data protection solicitor to resolve the flagged legal points, especially exemptions, legal holds, processor duties and conflicts with retention obligations.
    7. Test the approved procedure with a sample request across each relevant system, record what was found and update the SOP before issuing it to staff.

    Prompt

    Create a UK GDPR personal-data deletion procedure for [organisation type] with [number] staff and these systems: [list systems, databases, SaaS tools, paper records and backups]. Use the information below as the only facts about the organisation.
    
    Organisation details:
    [Paste details]
    
    Data categories and data subjects:
    [Paste details]
    
    Retention schedules, legal holds and regulatory record-keeping duties:
    [Paste details]
    
    Current request channels, identity checks, access permissions and responsible roles:
    [Paste details]
    
    Vendors and processors that hold personal data:
    [Paste details]
    
    Draft a practical SOP covering: how a deletion request is received and logged; identity and authority checks; scope assessment; searches across live systems, email, paper files, backups and processors; exceptions and reasons for refusing or limiting deletion; legal holds; approvals; technical deletion or anonymisation; processor instructions; audit evidence; response communications; escalation; incident handling; and periodic testing.
    
    Separate the procedure into purpose, scope, definitions, roles, numbered steps, decision points, records to keep, templates, a RACI table, and an implementation checklist. Do not invent systems, retention periods, legal grounds, deadlines or regulator requirements. Mark missing information as [TO CONFIRM]. Distinguish UK GDPR requirements from organisational policy. Cite the relevant ICO or GOV.UK source for each legal requirement, using current sources that I can open, and flag any point that needs review by our data protection officer or a UK data protection solicitor. This is a draft operational document, not professional advice.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT write a GDPR data deletion policy?
It can draft a UK GDPR deletion procedure from your systems, roles and retention rules. It cannot supply those facts or take responsibility for legal decisions, so have your data protection officer or a UK data protection solicitor check the draft.
Is it legal to use AI to handle GDPR deletion requests?
AI can help organise a process, but using it does not transfer your organisation's data protection responsibilities. Do not paste personal data into a chatbot unless your approved privacy, security and processor arrangements permit it, and keep the final decision with an accountable person.
What should a GDPR data deletion procedure include?
It should cover request logging, identity checks, system searches, processors, exemptions, legal holds, approvals, deletion or anonymisation, evidence, communications and escalation. It should also identify what must be retained and how the procedure is tested.
Can AI decide whether personal data must be deleted?
No, not safely on its own. It can apply a decision tree to documented rules, but an accountable staff member and, for difficult cases, your data protection officer or a UK data protection solicitor must resolve conflicts between deletion and retention duties.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.