As of 13 August 2026, AI can only partly create a record of processing activities for your business.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
2 hoursto something you’d act on.
Cost, all in£0
Skill neededpower-user
Who has to check ita professional
What the alternative costsiubenda generates and maintains privacy and cookie compliance documents.
If this goes wrong, important processing is omitted or described incorrectly and your business is left with a weak compliance record when it needs to demonstrate its arrangements.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, power-user skill, and roughly 2 hours until you can act on the result.
How to actually do it
- Open a document or spreadsheet and list every department, service, customer journey, internal process and system that handles personal data.
- Gather the current privacy notice, retention policy, data protection policy, processor contracts, supplier list, system list and any data-flow or security documentation.
- Paste the business information and documents into a chatbot, using the supplied prompt, and ask it to produce the draft record and gaps list without filling unknowns.
- Compare each drafted processing activity against the department and system list, adding any activity the model missed and correcting names, data categories, recipients and purposes from your source documents.
- Ask the chatbot to produce a second version containing only confirmed facts, with every unresolved item retained in a separate questions list.
- Send the confirmed draft, the gaps list and the underlying source documents to your data protection specialist or solicitor for a completeness and legal review before adopting it.
Prompt
Create a draft record of processing activities for a UK business under the UK GDPR using only the information I provide below. Do not invent processing activities, suppliers, data categories, retention periods, international transfers, lawful bases, security measures or other facts. Where information is missing or uncertain, write "To confirm" and add it to a separate gaps and questions list. Present the result as a clear table with one row for each processing activity and these columns: business area or owner; processing activity; purpose; categories of data subjects; categories of personal data; special category or criminal offence data; source of the data; recipients and processors; retention period or deletion rule; storage locations; international transfers and safeguards; lawful basis; additional condition where special category data is used; security measures; data protection impact assessment status; and notes. After the table, provide: 1. a list of missing information and precise questions for the business; 2. assumptions, with none treated as established facts; 3. a list of suppliers or systems that need their contracts checked; 4. a list of possible international transfer issues to confirm; 5. a short plain-English explanation of which parts must be checked by the business or a data protection professional before adoption. Use UK terminology and British English. Keep the record factual and concise. Do not decide that the business is compliant, do not give legal conclusions, and do not cite a lawful basis unless it is supported by the information supplied. Business information: [Paste your business description, departments, services, systems, suppliers, policies, contracts, data maps and any existing privacy or retention information here.]
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover processing that nobody tells it about, including informal spreadsheets, shared mailboxes and manual records.
- AI cannot establish the correct lawful basis or special condition from vague descriptions of what your business does.
- AI cannot confirm whether supplier contracts, international transfer safeguards or retention rules are actually adequate.
- AI cannot take responsibility for the record or maintain it when your systems, suppliers and processes change.
- The final completeness check still depends on someone who understands both your operations and data protection requirements.
What caps this at PARTLY: legal accountability, verification cost and context depth.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 1 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT create a record of processing activities?
- Yes, it can create a structured draft from your business information, systems and documents. It cannot know what your business has omitted, so a data protection professional should check the finished record before you adopt it.
- What information do I need for a record of processing activities?
- You need details such as processing purposes, data subjects, personal data categories, recipients, processors, retention, storage, transfers, lawful bases and security measures. Gather these from your systems, contracts, policies and the people who run each process rather than asking AI to fill gaps.
- Is an AI-generated record of processing activities legally compliant?
- An AI-generated document is not automatically compliant, because compliance depends on whether it is complete, accurate and suitable for your actual processing. This is not professional advice. A serious or complex case needs a solicitor or data protection specialist to check it.
- Can AI keep my record of processing activities up to date?
- AI can help you reorganise a record after you provide details of a changed system, supplier or process. It cannot reliably know that a change happened or take responsibility for maintaining the official record, so updates need a named owner and a review process.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.