CAIS Background Watermark
SOVEREIGN AI · UK GDPR EXPOSURE

UK GDPR GenAI Exposure Check:
Personal Data, Processors, and Shadow AI

Every UK business using GenAI around emails, documents, HR files, client records, or support chats may already be handling personal data in AI workflows. A data-protection policy on its own does not show whether those workflows are tested, monitored, and proved.

This free UK GDPR GenAI exposure check maps where ChatGPT, Claude, Gemini, Copilot, and similar tools can create personal-data leakage, weak processor visibility, and gaps in evidence when a complaint or rights request lands.

Twelve questions · Yes / Partial / No / Unknown · about 3–4 minutes.

You receive an exposure band and a six-axis control-strength profile — a plain-English snapshot for DPOs, privacy leads, COOs, and GCs. It scores exposure only.

Compliance AI Shield
UK GDPR-aligned · any UK organisation
Compliance AI Shield
Compliance AI Shield
complianceaishield.co.uk
Self-auditSovereign AI12 questions~3–4 minutes

Start the self-audit

Twelve questions. Answer Yes / Partial / No / Unknown. Then unlock your exposure band and six-axis control-strength profile.

This scores exposure, not eligibility for any government funding scheme. It does not intercept a live prompt, block a model call, or produce a cryptographic audit receipt. Paper policies catalogue risk — they do not eliminate runtime leakage.
Educational self-assessment only. Not legal advice or compliance certification.
Also available: SRA audit · FCA audit · EU AI Act check

Scores exposure only. Not ICO certification, not legal advice, and not a funding eligibility check. Does not intercept a live prompt.

Also available: SRA GenAI Exposure Self-Audit · FCA GenAI Exposure Self-Audit · EU AI Act Exposure Check

What to do next

Your exposure band is a starting point. Keep the snapshot, share it with your DPO / privacy lead / board, then close gaps on paper — or move to a board-ready review and, where needed, runtime proof that GenAI use involving personal data is tested, monitored, and proved.

UK GDPR, personal data, and Shadow AI

This pillar section gives search engines and human readers the plain-English context behind the audit above. It explains how GenAI affects personal-data workflows, why processor visibility and evidence matter, and why a policy pack alone is not proof.

Why UK GDPR and GenAI is an exposure problem for every sector

UK GDPR did not pause when ChatGPT arrived. If personal data enters a prompt — names, emails, HR files, support tickets, or customer records — data-protection duties follow the workflow, not the brand of the AI tool.

Many organisations treat AI governance as a future project and UK GDPR as a finished policy pack. The practical question is whether you can show that GenAI use involving personal data is tested, monitored, and proved — or only that a privacy notice and AI policy exist.

This page starts with a free exposure check, then explains the personal-data risks that sit behind the score. Educational only. Not legal advice. Not ICO certification.

Shadow AI and personal data

Shadow AI means staff using public GenAI tools where personal data may be involved, often without an approved-tools list or named owner.

Common examples include pasting a customer email thread into ChatGPT to draft a reply, summarising HR notes in a consumer LLM, or feeding support tickets containing personal data into a browser assistant.

If you cannot see which tools people use with personal data, you cannot evidence lawful handling, processor relationships, or incident readiness.

What must never be pasted into public AI tools

Organisations need red lines in plain English, with examples — not only abstract principles.

High-risk categories usually include personal data that identifies a living individual, special-category data, confidential HR material, and customer identifiers combined with sensitive context.

Processors, subprocessors, and international transfers

GenAI vendor chains often hide processors, subprocessors, and cross-border transfers. Teams assume the model provider handles compliance. That assumption is frequently wrong for the organisation's own obligations.

Before scaling GenAI use, map which vendors process personal data in prompts or outputs, where data may be stored or transferred, and what contractual terms actually say about training, retention, and subprocessors.

Lawful basis, DPIA-style discipline, and records

UK GDPR expects organisations to understand purpose, lawful basis, and risk for processing. GenAI use cases change purpose and risk quickly.

You do not need a theatre of paperwork. You do need enough discipline to answer why personal data is entering an AI workflow, what lawful basis applies, and whether higher-risk uses have been assessed before scale.

Rights requests, complaints, and evidence

When a data subject access request, complaint, or incident lands, "we have a GDPR policy" is weak evidence.

Organisations struggle when they cannot show which AI tools touched a workflow involving that person, what safeguards were meant to apply, and whether a control would have stopped an unsafe prompt.

Why IT dashboards fail GenAI personal-data risk

DLP and email controls matter. They still often miss browser GenAI pastes and do not prove a risky prompt was blocked before the model ran.

The missing layer is often execution: what actually crossed the perimeter, whether policy survived run-time, and whether you can prove it afterwards.

What tested, monitored, and proved means for personal-data AI use

For most organisations, it means a controlled bad-prompt exercise with privacy and IT present, ongoing visibility of tools and material personal-data AI use, and evidence of allow, block, or escalate decisions.

A free exposure check is step zero: honesty about gaps. A board pack turns that into an accountable plan. Runtime controls are where proof becomes technical rather than aspirational.

How to use this free UK GDPR GenAI exposure check

Complete the 12-question self-audit above, unlock your exposure band and six-axis profile, and share the snapshot with your DPO, privacy lead, or IT team.

If Evidence or Assurance scores weakly, treat that as a priority. If you need something board-ready, the next step is a facilitated review, board pack, and one-hour consultation. If you need run-time proof, discuss an inline intercept and ledger path.

Frequently asked questions

Is this an official ICO assessment?

No. It is an educational exposure check. Not ICO certification or legal advice.

Does a good score mean we are GDPR compliant?

No. It maps exposure. Compliance is a wider programme of law, process, and proof.

Do only regulated firms need this?

No. Any organisation using personal data with GenAI may have exposure, including HR, SaaS, healthcare-adjacent, and professional services.