As of 13 August 2026, AI can only partly create a UK GDPR compliance checklist for your small business.
This still needs a person who signs their name to it.
Can you do it?
5 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsiubenda is a purpose-built service that generates and maintains privacy and cookie compliance documents.
If this goes wrong: the checklist misses a material processing activity or legal obligation, and your business relies on it while carrying the consequences.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the ICO data protection guidance and GOV.UK data protection pages, then save the current links you intend to use as sources.
- Gather your privacy notice, cookie notice, processor contracts, supplier list, security policy, retention schedule, breach procedure and any record of processing activities.
- Ask the people responsible for sales, marketing, HR, IT and customer support to list the personal data they collect, why they use it, where it is stored, who receives it and how long it is kept.
- Paste the business details, documents, source links and the copyable prompt into a chatbot, then ask it to produce the checklist with a separate owner and status for every item.
- Compare each legal statement and linked source in the draft against the current ICO or GOV.UK page, removing any item that rests on an invented fact or unsupported source.
- Send the unanswered questions, high-priority gaps and any item marked 'needs legal assessment' to a solicitor or data protection specialist before treating the checklist as a compliance conclusion.
- Assign owners and dates in the checked checklist, then store evidence such as signed contracts, training records, assessments and policy approvals beside the completed items.
Prompt
Create a practical UK GDPR compliance checklist for a small business in the United Kingdom. Business details: - Business type and sector: [insert] - Number of staff: [insert] - Customers or users: [insert] - Countries where we operate or sell: [insert] - Types of personal data handled: [insert] - Special category or criminal offence data handled: [insert] - Main processing activities: [insert] - Systems and suppliers used, including cloud services: [insert] - Whether we use cookies, direct marketing, profiling, monitoring or automated decision-making: [insert] - Whether we share data with processors, group companies, public bodies or other third parties: [insert] - Current policies, records, contracts and security measures: [insert] Produce a table with these columns: checklist item, why it may apply, evidence to collect, responsible owner, priority, and status. Separate actions that are likely to apply to most businesses from actions that depend on the facts. Include data protection principles, lawful bases, transparency, data subject rights, processor contracts, international transfers, records of processing, security, personal data breaches, retention, data protection impact assessments, direct marketing, cookies, children’s data, data protection officer requirements, and regulator contact arrangements where relevant. For every item, state the factual assumption or business answer that makes it applicable. Do not invent facts, legal deadlines, exemptions, regulator decisions or supplier capabilities. Where the answer depends on circumstances, write 'needs legal assessment' and list the facts a solicitor or data protection specialist would need. Use current official UK sources where possible, preferably ICO or GOV.UK, and provide a link for each legal or regulatory statement. Distinguish UK GDPR requirements from the Data Protection Act 2018, PECR and general good practice. End with a list of unanswered questions and a short verification plan. This is a working checklist, not legal advice, and do not present it as proof that the business is compliant.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover processing activities that nobody tells it about, including informal spreadsheets, shared inboxes and supplier access.
- AI cannot decide reliably whether a difficult lawful-basis, international-transfer, special-category or monitoring question applies to your facts.
- AI cannot confirm that a cited source is current or that your interpretation of it is legally sound without you checking the source and, for serious issues, obtaining specialist advice.
- AI cannot take responsibility for your compliance, respond as your accountable adviser or replace approval by the people who run your data-processing systems.
What caps this at PARTLY: legal accountability, verification cost and judgement under ambiguity.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 1 |
| Effort delta | 2 |
| Total | 7 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT make a GDPR checklist for my business?
- Yes, it can draft and organise a useful UK GDPR checklist from your business facts and documents. It cannot prove that the checklist is complete, and you need to verify legal points against ICO or GOV.UK sources and obtain specialist help for difficult issues.
- What should be on a UK GDPR compliance checklist?
- It should cover the data you process, purposes and lawful bases, privacy information, individual rights, processors, international transfers, security, retention, breaches, impact assessments, marketing, cookies and relevant records. Which items apply depends on your systems, data and business activities.
- Is an AI GDPR checklist legally compliant?
- No checklist produced by a chatbot is proof that your business is compliant. This is not professional advice, and a serious or uncertain case needs a solicitor or data protection specialist to assess the facts and accept responsibility for their advice.
- Can AI tell me if my small business complies with UK GDPR?
- It can compare information you provide with published guidance and flag apparent gaps. It cannot reliably find undisclosed processing, resolve every legal judgement or transfer responsibility for the result from your business.
Nearby answers
- Can AI act as my business's data protection officer?NO
- Can AI audit my website cookies for PECR compliance?PARTLY
- Can AI build a data protection policy for my UK business?PARTLY
- Can AI check whether an AI tool creates UK GDPR risks for my business?NO
- Can AI check whether my international data transfers comply with UK GDPR?NO
- Can AI check my email marketing consent process under UK PECR?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.