PARTLY

As of 13 August 2026, AI can only partly draft a UK GDPR privacy notice for your business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsiubenda generates and maintains privacy and cookie compliance documents, while a solicitor remains the route for legal responsibility.

If this goes wrong: your notice misstates how you use personal data and leaves your business exposed to complaints, enforcement or loss of trust.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open your current website, app, customer forms, staff processes and supplier list, then record every point at which personal data is collected, used, shared or deleted.
    2. Ask the people responsible for marketing, sales, HR, IT and customer support to provide the purposes, data categories, systems, recipients, retention periods and international transfers for their processes.
    3. Gather your existing privacy notice, cookie notice, consent wording, data processing agreements and any records of processing activities, removing unnecessary personal data before pasting anything into a chatbot.
    4. Paste the gathered business facts into the prompt and ask the chatbot to list missing or uncertain facts before drafting the notice.
    5. Resolve each [CONFIRM] item with the relevant process owner, and replace it in the draft only when your business can support the statement with an actual process or document.
    6. Open the current ICO guidance on privacy information and compare its required information with every section of the draft, then ask a solicitor or qualified data protection adviser to check the final wording before publishing it.
    7. Publish the approved notice where people can see it before or when their data is collected, and set a named owner and review trigger for changes to your processing.

    Prompt

    Draft a UK GDPR privacy notice for the business described below. Treat the UK GDPR and Data Protection Act 2018 as the legal context, and use current ICO guidance as the checking reference where it is available. Do not give legal advice, invent facts, assume a lawful basis, or fill gaps with standard wording that is not supported by the information provided.
    
    Business name: [BUSINESS NAME]
    Business type and location: [BUSINESS TYPE AND UK LOCATION]
    Contact details for privacy enquiries: [CONTACT DETAILS]
    Data protection officer or privacy contact, if any: [DETAILS OR NONE]
    What personal data we collect: [LIST EACH CATEGORY]
    Who provides it and how we collect it: [SOURCES AND METHODS]
    Why we use it: [PURPOSES]
    Lawful basis we currently rely on for each purpose: [BASIS OR UNKNOWN]
    Special category or criminal offence data: [DETAILS OR NONE]
    Who receives or can access it: [RECIPIENTS, SUPPLIERS AND GROUP COMPANIES]
    International transfers: [DETAILS OR NONE OR UNKNOWN]
    How long we keep each category: [RETENTION PERIODS OR UNKNOWN]
    Cookies and similar technologies: [DETAILS OR LINK TO COOKIE NOTICE]
    Individual rights and how to exercise them: [PROCESS AND CONTACT]
    Automated decision-making or profiling: [DETAILS OR NONE OR UNKNOWN]
    Children's data: [DETAILS OR NONE OR UNKNOWN]
    How we secure the data: [HIGH-LEVEL CONTROLS]
    How people can complain: [INTERNAL PROCESS AND ICO INFORMATION]
    
    First, list every missing or uncertain fact that must be confirmed by the business. Then produce a plain-English privacy notice with headings. Mark any unresolved statement as [CONFIRM]. For each purpose, show the personal data used, the stated lawful basis, recipients, retention period and any relevant rights. If the information supplied does not support a lawful basis or retention period, say so instead of choosing one. Keep the notice separate from any cookie notice unless the supplied information supports combining them. Finish with a short checklist of factual and legal points a solicitor or qualified data protection adviser should check before publication.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: legal accountability, verification cost and context depth.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability0
Effort delta2
Total6 / 10

FAQ

Can ChatGPT write a GDPR privacy notice?
It can produce a useful first draft from accurate details about your business and its data processing. It cannot establish whether those details are complete or whether the lawful bases and retention periods are defensible, so a solicitor or qualified data protection adviser should check the final notice.
Is an AI-generated privacy policy legally valid in the UK?
There is no special legal status that makes an AI-generated notice valid. It must accurately explain your actual processing and meet UK GDPR transparency requirements, and your business remains responsible for errors.
What information does AI need to write a UK GDPR privacy notice?
Give it your data categories, collection methods, purposes, lawful bases, recipients, international transfers, retention periods, rights process, cookies, automated decision-making and contact details. You also need to identify missing facts rather than allowing the model to supply standard wording by assumption.
Do I need a solicitor to check my privacy notice?
Not every simple notice needs a solicitor, but a serious or complex case should be checked by a solicitor or qualified data protection adviser. This is not professional advice, and your business keeps the liability if the notice is incomplete or misleading.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.