Getting an AI-drafted data processing agreement checked

Review of a data processing agreement or data protection schedule drafted with an AI tool, returned as tracked changes with a written explanation, for a fixed fee of £495 in three working days.

Share

Getting an AI-drafted data processing agreement checked

A solicitor's review of a data processing agreement produced with an AI drafting tool, returned as tracked changes with a clean copy and a written explanation, covering the mandatory processor terms under Article 28 of the UK GDPR, subprocessors, security and breach notification, international transfers, audit and deletion, liability, and the US service-provider drafting the draft carries. £495, in three working days.

Buy now, £495

A data processing agreement produced with an AI drafting tool is often built on the California model: a 'service provider' that will not 'sell' personal information, a reference to 'CCPA' and 'GDPR' in the same sentence, and standard contractual clauses attached that are the EU version rather than the UK one. In England and Wales a processor contract must contain the terms Article 28 of the UK GDPR requires, and a transfer outside the UK needs a mechanism the UK regime recognises. I review the agreement against the UK GDPR and the processing concerned, from whichever side instructs me, and return it marked up with tracked changes, a clean copy and a written explanation of the changes, for a fixed fee of £495 in three working days.

Who this is for

Businesses in England and Wales acting as controller, such as a company engaging a software or outsourcing supplier, and businesses acting as processor, such as a SaaS provider, agency or bureau, using a data processing agreement drafted with an AI tool as their standard document or for a particular customer.

What the review checks in an AI-drafted data processing agreement

The mandatory terms under Article 28

Article 28 of the UK GDPR requires a processor contract to set out the subject matter, duration, nature and purpose of the processing, the types of data and categories of data subject, and to oblige the processor to act only on documented instructions, keep personnel bound by confidentiality, take security measures, engage subprocessors only with authorisation, assist the controller with data subject rights and compliance, delete or return data at the end, and make information available for audits. The review checks each requirement is present and drafted to work, and completes the processing schedule the AI draft leaves as a placeholder.

Subprocessors, instructions and the processor's own purposes

The review checks the subprocessor mechanism (general authorisation with a list and a right to object, or specific consent), that the processor flows the Article 28 terms down and remains liable for its subprocessors, that instructions are documented, and that the processor may not use the data for its own purposes, including training models, unless the agreement says so and the controller has a lawful basis. A US draft's 'service provider' language does not deal with any of this.

Security, breach notification and assistance

Article 32 of the UK GDPR requires security appropriate to the risk, and the review checks that the measures are described or scheduled rather than asserted, that the processor notifies the controller of a personal data breach without undue delay so that the controller can meet its own deadline under Article 33, and that assistance with data protection impact assessments and data subject requests is provided at stated cost. A notification period longer than the controller can live with is the commonest defect.

International transfers

Where data leaves the UK, the transfer needs a mechanism under Article 46 of the UK GDPR: the UK international data transfer agreement, the UK addendum to the EU standard contractual clauses, or adequacy regulations, and the review checks which applies, that the right document is attached and completed, and that a transfer risk assessment has been considered. An AI draft attaching the EU clauses alone does not satisfy the UK regime, and the review corrects it.

Audit, deletion and the end of the processing

The review checks the controller's audit right and its practical limits (notice, frequency, cost, reliance on third-party certifications), the obligation to delete or return data at the end of the services with certification, retention required by law, and how the data protection terms survive termination of the main agreement, because an AI draft frequently ends the DPA with the services and leaves the data where it was.

Liability, precedence and the boilerplate

The review checks how liability for data protection claims sits with the main agreement's cap, whether regulatory fines and compensation claims under the Data Protection Act 2018 are within it, and which document prevails on conflict, and replaces a US state's law and courts with English law and jurisdiction. Where the parties are joint controllers rather than controller and processor, the review says so and drafts the arrangement Article 26 of the UK GDPR requires instead.

What it costs

Review of an AI-drafted contract, £495. One contract, returned as a marked-up Word document with my amendments as tracked changes, a clean version with the changes accepted, and a written explanation of the changes. Three working days from payment.

Buying online forms the engagement on payment. The scope is what the review of an ai-drafted contract page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • Your own Word document returned with every amendment I consider necessary shown as a tracked change, so you can see exactly what I changed and accept or reject each one
  • A clean version with every change accepted, ready to send
  • Corrections to anything that is wrong as a matter of English law, unenforceable as drafted, or internally inconsistent
  • Missing provisions added where the document has left a gap that matters: usually liability, termination, payment, intellectual property or data
  • Comments in the margin where a clause is a commercial choice rather than a legal one, so the decision stays yours
  • A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, with anything you should think about before sending it out
  • Follow-up questions on the mark-up answered by email, included

What is not included

  • A full rewrite. This is a review and amendment of your document, not a replacement for it. If the draft is structurally unsuitable for the deal, I will say so and quote separately for drafting it properly
  • A second round of amendments after you have changed the document again, which I can quote for
  • Negotiating with the other side
  • Advice on the law of any jurisdiction other than England and Wales
  • Tax, accounting or regulatory advice
  • Reviewing a document the other side drafted, which is the contract review service, at the same price

Questions I am often asked

Our AI draft refers to CCPA and GDPR. Does one document cover both?

Not as drafted. The UK GDPR sets specific requirements for processor contracts and transfers that a US-style service provider agreement does not meet. The review produces a UK-compliant agreement and says what would be needed for other regimes.

The draft attaches the EU standard contractual clauses for transfers. Is that enough for a UK transfer?

Not on its own. A transfer from the UK needs the UK international data transfer agreement or the UK addendum to the EU clauses, with a transfer risk assessment. The review attaches and completes the right document.

The processor's liability for data breaches is capped at one month's fees. Can we accept that?

You can, but a cap that low leaves the controller carrying the cost of a breach it did not cause. The review proposes a separate, higher cap for data protection claims and says what is realistic for the services concerned.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.