Home · Business · Legal & Compliance · Terms & policies

PARTLY

As of 13 August 2026, AI can only partly draft a data retention policy for your UK business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsThe supplied tool information gives no price for a solicitor or other alternative; iubenda is described as generating and maintaining privacy and cookie compliance documents.

If this goes wrong, your business may keep personal data longer than necessary or delete records needed for legal, contractual or operational reasons.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open the ICO guidance on storage limitation and your current privacy notice, then create a list of every personal data category your business holds.
    2. Export or write down the systems, paper files, email accounts, backups and suppliers where each data category is stored.
    3. Gather current retention practices, contractual requirements, insurance requirements, legal claims, investigations and sector-specific rules for each category.
    4. Paste that information into the prompt, replacing every bracketed slot and marking unknown facts as unknown rather than guessing.
    5. Ask the chatbot to produce the policy, retention schedule, assumptions and checking list specified in the prompt.
    6. Compare every proposed period and exception with the relevant ICO or GOV.UK source, then send unresolved legal or sector-specific points to a UK solicitor or data protection specialist before approval.
    7. Have the responsible business owners confirm that the systems, deletion methods, backups and assigned responsibilities are accurate, then publish the approved policy and set a review reminder.

    Prompt

    Draft a UK data retention policy for [BUSINESS NAME], a [BUSINESS TYPE] with [NUMBER OR DESCRIPTION OF STAFF] operating in [LOCATIONS]. This is a working draft, not professional advice. Do not invent facts, legal duties, retention periods or regulatory requirements. Where information is missing or uncertain, write [NEEDS CONFIRMATION] and explain what must be confirmed.
    
    Use the business information below:
    - Personal data categories: [LIST]
    - Data subjects: [CUSTOMERS, STAFF, SUPPLIERS, CHILDREN OR OTHERS]
    - Systems and storage locations: [LIST]
    - Current retention periods: [LIST OR UNKNOWN]
    - Reasons for retaining each category: [LIST]
    - Relevant contracts, insurance requirements, litigation holds or investigations: [LIST OR NONE KNOWN]
    - Relevant sector rules or regulators: [LIST OR UNKNOWN]
    - Deletion, anonymisation and backup processes: [DESCRIPTION]
    - Roles responsible for retention and deletion: [ROLES]
    - International transfers or overseas storage: [DETAILS OR UNKNOWN]
    - Existing privacy notice or data protection policy: [PASTE OR SUMMARISE]
    
    Produce:
    1. A clear policy suitable for internal approval, with purpose, scope, principles, responsibilities, retention schedule, deletion and anonymisation procedures, backups, legal holds, exceptions, monitoring and review.
    2. A retention schedule table with data category, purpose, system, proposed retention period, justification, deletion method, owner and unresolved question.
    3. A separate list of assumptions and questions for the business.
    4. A separate list of points that need checking against current ICO guidance, GOV.UK guidance, contracts, sector rules or advice from a UK solicitor or data protection specialist.
    
    Do not claim that one fixed period applies merely because it is common practice. Distinguish legal requirements from business choices, and explain when a retention period depends on the facts. Use plain British English and do not include personal data in the draft.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot discover every personal data store, backup, supplier process or informal practice in your business.
  • It cannot decide whether a proposed retention period is justified by your particular legal, contractual and operational facts.
  • It cannot reliably identify every sector-specific rule or conflict between a retention policy and a legal hold.
  • It cannot take responsibility for unlawful retention, premature deletion or a failed response to a data subject request.
  • It cannot confirm that your technical deletion and backup processes actually carry out what the policy promises.

What caps this at PARTLY: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta2
Total6 / 10

FAQ

Can ChatGPT write a data retention policy?
Yes, it can produce a useful first draft and a retention schedule from accurate information about your business. This is not professional advice, and a UK solicitor or data protection specialist should check periods and exceptions before you approve it.
What information does AI need to draft a data retention policy?
Give it your data categories, purposes, systems, storage locations, current practices, contracts, sector rules, legal holds, deletion methods and responsible roles. If you do not know an answer, mark it as unknown because a guessed detail can make the policy misleading.
Is an AI-generated data retention policy legally valid in the UK?
A policy is not made legally compliant merely because AI drafted it. Your business must be able to justify its retention periods and follow the policy in practice under applicable UK data protection requirements.
Should a solicitor check my data retention policy?
Yes, especially if you handle sensitive data, operate in a regulated sector, have complex contracts, face litigation or retain records for statutory reasons. A UK solicitor or data protection specialist can check the legal basis, retention periods, exceptions and accountability that a chatbot cannot take responsibility for.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.