Home · Business · Legal & Compliance · Terms & policies
As of 13 August 2026, AI can only partly draft a data retention policy for your UK business.
This still needs a person who signs their name to it.
Can you do it?
15 minutesto a draft.
1 hourto something you’d act on.
Cost, all in£0
Skill neededchat-fluent
Who has to check ita professional
What the alternative costsThe supplied tool information gives no price for a solicitor or other alternative; iubenda is described as generating and maintaining privacy and cookie compliance documents.
If this goes wrong, your business may keep personal data longer than necessary or delete records needed for legal, contractual or operational reasons.
What to actually do
Hand it to a person
The route this page recommends
Someone with a licence or accountable authority has to sign this before it counts.
Use a tool built for this
Second choiceDo it yourself
The distant thirdA chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.
How to actually do it
- Open the ICO guidance on storage limitation and your current privacy notice, then create a list of every personal data category your business holds.
- Export or write down the systems, paper files, email accounts, backups and suppliers where each data category is stored.
- Gather current retention practices, contractual requirements, insurance requirements, legal claims, investigations and sector-specific rules for each category.
- Paste that information into the prompt, replacing every bracketed slot and marking unknown facts as unknown rather than guessing.
- Ask the chatbot to produce the policy, retention schedule, assumptions and checking list specified in the prompt.
- Compare every proposed period and exception with the relevant ICO or GOV.UK source, then send unresolved legal or sector-specific points to a UK solicitor or data protection specialist before approval.
- Have the responsible business owners confirm that the systems, deletion methods, backups and assigned responsibilities are accurate, then publish the approved policy and set a review reminder.
Prompt
Draft a UK data retention policy for [BUSINESS NAME], a [BUSINESS TYPE] with [NUMBER OR DESCRIPTION OF STAFF] operating in [LOCATIONS]. This is a working draft, not professional advice. Do not invent facts, legal duties, retention periods or regulatory requirements. Where information is missing or uncertain, write [NEEDS CONFIRMATION] and explain what must be confirmed. Use the business information below: - Personal data categories: [LIST] - Data subjects: [CUSTOMERS, STAFF, SUPPLIERS, CHILDREN OR OTHERS] - Systems and storage locations: [LIST] - Current retention periods: [LIST OR UNKNOWN] - Reasons for retaining each category: [LIST] - Relevant contracts, insurance requirements, litigation holds or investigations: [LIST OR NONE KNOWN] - Relevant sector rules or regulators: [LIST OR UNKNOWN] - Deletion, anonymisation and backup processes: [DESCRIPTION] - Roles responsible for retention and deletion: [ROLES] - International transfers or overseas storage: [DETAILS OR UNKNOWN] - Existing privacy notice or data protection policy: [PASTE OR SUMMARISE] Produce: 1. A clear policy suitable for internal approval, with purpose, scope, principles, responsibilities, retention schedule, deletion and anonymisation procedures, backups, legal holds, exceptions, monitoring and review. 2. A retention schedule table with data category, purpose, system, proposed retention period, justification, deletion method, owner and unresolved question. 3. A separate list of assumptions and questions for the business. 4. A separate list of points that need checking against current ICO guidance, GOV.UK guidance, contracts, sector rules or advice from a UK solicitor or data protection specialist. Do not claim that one fixed period applies merely because it is common practice. Distinguish legal requirements from business choices, and explain when a retention period depends on the facts. Use plain British English and do not include personal data in the draft.
Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.
What it gets wrong
- AI cannot discover every personal data store, backup, supplier process or informal practice in your business.
- It cannot decide whether a proposed retention period is justified by your particular legal, contractual and operational facts.
- It cannot reliably identify every sector-specific rule or conflict between a retention policy and a legal hold.
- It cannot take responsibility for unlawful retention, premature deletion or a failed response to a data subject request.
- It cannot confirm that your technical deletion and backup processes actually carry out what the policy promises.
What caps this at PARTLY: legal accountability, verification cost and context depth.
How we scored this
Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.
| Axis | Score (0–2) |
|---|---|
| Output | 2 |
| Inputs | 1 |
| Verification | 1 |
| Liability | 0 |
| Effort delta | 2 |
| Total | 6 / 10 |
The methodology and its thresholds are published in full.
FAQ
- Can ChatGPT write a data retention policy?
- Yes, it can produce a useful first draft and a retention schedule from accurate information about your business. This is not professional advice, and a UK solicitor or data protection specialist should check periods and exceptions before you approve it.
- What information does AI need to draft a data retention policy?
- Give it your data categories, purposes, systems, storage locations, current practices, contracts, sector rules, legal holds, deletion methods and responsible roles. If you do not know an answer, mark it as unknown because a guessed detail can make the policy misleading.
- Is an AI-generated data retention policy legally valid in the UK?
- A policy is not made legally compliant merely because AI drafted it. Your business must be able to justify its retention periods and follow the policy in practice under applicable UK data protection requirements.
- Should a solicitor check my data retention policy?
- Yes, especially if you handle sensitive data, operate in a regulated sector, have complex contracts, face litigation or retain records for statutory reasons. A UK solicitor or data protection specialist can check the legal basis, retention periods, exceptions and accountability that a chatbot cannot take responsibility for.
Nearby answers
- Can AI draft a modern slavery statement for my UK business?PARTLY
- Can AI draft terms and conditions for my UK service business?PARTLY
- Can AI rewrite my UK business terms in plain English?YES
- Can AI audit my UK website cookies for compliance?NO
- Can AI draft booking terms for my UK business?PARTLY
- Can AI draft a data processing agreement for my UK business?PARTLY
Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.
The newsletter
AI news, new answers and product picks, straight to your inbox.