PARTLY

As of 13 August 2026, AI can only partly create a record of processing activities for your business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

2 hoursto something you’d act on.

Cost, all in£0

Skill neededpower-user

Who has to check ita professional

What the alternative costsiubenda generates and maintains privacy and cookie compliance documents.

If this goes wrong, important processing is omitted or described incorrectly and your business is left with a weak compliance record when it needs to demonstrate its arrangements.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, power-user skill, and roughly 2 hours until you can act on the result.

    How to actually do it

    1. Open a document or spreadsheet and list every department, service, customer journey, internal process and system that handles personal data.
    2. Gather the current privacy notice, retention policy, data protection policy, processor contracts, supplier list, system list and any data-flow or security documentation.
    3. Paste the business information and documents into a chatbot, using the supplied prompt, and ask it to produce the draft record and gaps list without filling unknowns.
    4. Compare each drafted processing activity against the department and system list, adding any activity the model missed and correcting names, data categories, recipients and purposes from your source documents.
    5. Ask the chatbot to produce a second version containing only confirmed facts, with every unresolved item retained in a separate questions list.
    6. Send the confirmed draft, the gaps list and the underlying source documents to your data protection specialist or solicitor for a completeness and legal review before adopting it.

    Prompt

    Create a draft record of processing activities for a UK business under the UK GDPR using only the information I provide below. Do not invent processing activities, suppliers, data categories, retention periods, international transfers, lawful bases, security measures or other facts. Where information is missing or uncertain, write "To confirm" and add it to a separate gaps and questions list.
    
    Present the result as a clear table with one row for each processing activity and these columns: business area or owner; processing activity; purpose; categories of data subjects; categories of personal data; special category or criminal offence data; source of the data; recipients and processors; retention period or deletion rule; storage locations; international transfers and safeguards; lawful basis; additional condition where special category data is used; security measures; data protection impact assessment status; and notes.
    
    After the table, provide:
    1. a list of missing information and precise questions for the business;
    2. assumptions, with none treated as established facts;
    3. a list of suppliers or systems that need their contracts checked;
    4. a list of possible international transfer issues to confirm;
    5. a short plain-English explanation of which parts must be checked by the business or a data protection professional before adoption.
    
    Use UK terminology and British English. Keep the record factual and concise. Do not decide that the business is compliant, do not give legal conclusions, and do not cite a lawful basis unless it is supported by the information supplied.
    
    Business information:
    [Paste your business description, departments, services, systems, suppliers, policies, contracts, data maps and any existing privacy or retention information here.]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta1
Total6 / 10

FAQ

Can ChatGPT create a record of processing activities?
Yes, it can create a structured draft from your business information, systems and documents. It cannot know what your business has omitted, so a data protection professional should check the finished record before you adopt it.
What information do I need for a record of processing activities?
You need details such as processing purposes, data subjects, personal data categories, recipients, processors, retention, storage, transfers, lawful bases and security measures. Gather these from your systems, contracts, policies and the people who run each process rather than asking AI to fill gaps.
Is an AI-generated record of processing activities legally compliant?
An AI-generated document is not automatically compliant, because compliance depends on whether it is complete, accurate and suitable for your actual processing. This is not professional advice. A serious or complex case needs a solicitor or data protection specialist to check it.
Can AI keep my record of processing activities up to date?
AI can help you reorganise a record after you provide details of a changed system, supplier or process. It cannot reliably know that a change happened or take responsibility for maintaining the official record, so updates need a named owner and a review process.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.