As of 13 August 2026, AI can only partly draft a data processing agreement.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsNo comparable human-service price is supplied in the available tool data.
If this goes wrong, the agreement can miss a processing activity or impose obligations that do not match the parties' actual arrangements, leaving your business with legal and compliance exposure.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open your main services agreement, supplier security information and procurement records, then gather the controller and processor legal names, addresses, service description and governing-law terms.
- Ask the supplier or technical owner for the processing register details, including the data subjects, personal data types, processing purposes, duration, hosting locations, sub-processors and security measures.
- Paste those details into the prompt, keeping unknown items marked as [MISSING INFORMATION] rather than asking the model to infer them.
- Generate the draft and copy its completion checklist, assumptions and unresolved questions into a working document for the supplier and internal data protection owner.
- Compare every named party, service, processing purpose, data category, hosting location, sub-processor and security measure against the source records and the current ICO guidance on processor contracts.
- Send the checked draft and the main services agreement to a UK solicitor or suitably qualified data protection adviser, resolve their comments, then obtain approval from the people authorised to sign for both parties.
Prompt
Draft a UK data processing agreement between [CONTROLLER LEGAL NAME AND ADDRESS] and [PROCESSOR LEGAL NAME AND ADDRESS]. The processor provides [SERVICE DESCRIPTION]. Use the information below and invent nothing. If information is missing, write [MISSING INFORMATION] beside the relevant point and list the question needed to complete it. Controller details: [DETAILS] Processor details: [DETAILS] Processing activities and purpose: [DETAILS] Categories of data subjects: [DETAILS] Types of personal data: [DETAILS] Duration of processing: [DETAILS] Controller instructions: [DETAILS] Processor staff access and confidentiality: [DETAILS] Technical and organisational security measures: [DETAILS] Sub-processors and approval process: [DETAILS] International transfers and locations: [DETAILS] Support with data subject rights: [DETAILS] Support with breach, DPIA and regulator obligations: [DETAILS] Deletion or return of data at the end of the service: [DETAILS] Audit and information rights: [DETAILS] Liability, insurance and commercial terms already agreed: [DETAILS] Governing law and jurisdiction: England and Wales, unless the supplied facts say otherwise. Draft in plain UK English. Structure it as a usable contract with definitions, instructions, confidentiality, security, sub-processing, international transfers, data subject rights, breach assistance, audits, deletion or return, and precedence against the main services agreement. Distinguish controller obligations from processor obligations. Do not claim that a certification, security measure, transfer mechanism or approval exists unless supplied. Flag conflicts between the supplied facts and UK GDPR requirements. After the draft, provide a short completion checklist and a table of assumptions and unresolved legal questions. State that this is not professional advice and that a UK solicitor should review it before signature.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot know whether the supplier's description of its processing, security controls or sub-processors is complete.
- AI cannot resolve ambiguous responsibility between your business, the supplier and any sub-processors without informed commercial and legal judgement.
- AI cannot confirm that international transfer arrangements, liability wording and audit rights work for your particular relationship.
- AI does not carry the consequences of signing an inadequate agreement; your business does.
- AI cannot replace a solicitor's review where the agreement is material, unusual, disputed or linked to sensitive personal data.
What caps this at PARTLY: legal accountability, judgement under ambiguity and verification cost.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 1 |
| Total | 5 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT write a data processing agreement?
- Yes, it can produce a useful first draft from your business, supplier and processing details. It cannot confirm that the clauses match the real processing or that the finished agreement protects your business, so a UK solicitor should review it before signature.
- Do I need a data processing agreement under UK GDPR?
- A written contract is generally required when a processor handles personal data on a controller's behalf, with terms covering the processor's duties and the processing arrangements. Whether a particular supplier is a processor, joint controller or independent controller needs a fact-specific assessment.
- What should a UK data processing agreement include?
- It should set out the processing subject matter, duration, nature, purpose, personal data and data subjects, along with processor instructions, confidentiality, security, sub-processors, assistance, audits and deletion or return of data. It should also address international transfers and the relationship with the main services agreement where relevant.
- Should a solicitor review my data processing agreement?
- Yes, especially where the supplier handles sensitive data, uses overseas sub-processors, has unusual liability terms or will not accept your standard wording. This is not professional advice, and a serious or material arrangement needs review by a UK solicitor or qualified data protection adviser.
Nearby answers
- Can AI check whether my privacy policy complies with UK rules?NO
- Can AI check whether my privacy notice complies with UK GDPR?NO
- Can AI create a privacy policy for my UK business?NO
- Can AI draft a freelancer agreement for my UK business?PARTLY
- Can AI draft a cookie policy for my UK website?PARTLY
- Can AI draft terms and conditions for my UK online shop?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.