Getting an AI-drafted privacy policy checked
Review of a privacy policy drafted with an AI tool, checked against the UK GDPR and the Data Protection Act 2018, returned as tracked changes with a written explanation, for a fixed fee of £495 in three working days.
Getting an AI-drafted privacy policy checked
Buy now, £495A privacy notice produced with an AI drafting tool is organised under the right headings and, in most tools, written to a US or EU template: references to 'GDPR' without the UK version, to the Data Protection Act 1998, to Privacy Shield, to California residents' rights, and to lawful bases claimed for every purpose at once. A UK notice has to state what the UK GDPR requires, for the processing the business in fact carries out. I review the notice against the UK GDPR and the Data Protection Act 2018 and the business's actual processing, and return it marked up with tracked changes, a clean copy and a written explanation of the changes, for a fixed fee of £495 in three working days.
Who this is for
Businesses in England and Wales that have drafted a privacy policy or privacy notice for their website, app, customers, staff or contacts using an AI tool, and want it checked and corrected before it is published. The review is of the client's own document; it covers the notice, and identifies where the processing it describes needs a record, a policy or a contract the notice does not supply.
What the review checks in an AI-drafted privacy policy
The information the notice must contain
Article 13 of the UK GDPR, applied with the Data Protection Act 2018, requires a notice given at the point of collection to state the identity and contact details of the controller, the purposes and lawful basis of the processing, the legitimate interests relied on, the recipients, any international transfer and its safeguards, the retention period or criteria, the individual's rights including the right to complain to the ICO, whether the provision of data is a statutory or contractual requirement, and any automated decision-making. Article 14 sets the equivalent for data obtained from elsewhere. The review checks the draft against each item and completes it for the business's processing.
The lawful bases the draft claims
An AI draft may state that the business processes data on the basis of consent, contract, legal obligation and legitimate interests without saying which applies to what, or may claim consent for processing where consent is not the right basis and cannot be withdrawn without breaking the service. Article 6 of the UK GDPR requires a lawful basis for each purpose, and special category data such as health information needs an additional condition under Article 9 and the Data Protection Act 2018. The review maps each purpose to its basis and rewrites the notice so that the basis stated is the one the business relies on.
References to the wrong law
AI drafts cite the Data Protection Act 1998, which was repealed, the EU GDPR rather than the UK GDPR, the Privacy Shield, which no longer exists, and US state privacy laws with a 'Do Not Sell My Personal Information' link that has no meaning in the UK. The review corrects every citation to the UK GDPR and the Data Protection Act 2018, notes where the Data (Use and Access) Act 2025 amends the position, and removes provisions that apply only to jurisdictions where the business does not operate, while keeping the EU GDPR references where the business in fact offers services to people in the EU.
Retention periods, recipients and processors
An AI draft may say that data is kept for 'as long as necessary', which is not the retention period or criteria the notice must state, and may describe recipients as 'trusted third parties'. The review asks for the categories of recipient, the processors the business uses (hosting, email, payments, analytics, CRM), and the retention periods or criteria for each category of data, and writes them in, since a notice that cannot be completed on those points shows the business has not decided them.
International transfers
Data sent to processors outside the UK, which includes most US-based platforms, needs a transfer mechanism under Article 46 of the UK GDPR, or adequacy regulations for the destination, and the notice must say that transfers take place and what safeguards apply. An AI draft may state that data may be transferred 'worldwide' or rely on a mechanism that does not exist. The review identifies the actual transfers, the mechanism for each, whether the UK extension to the EU-US Data Privacy Framework, the International Data Transfer Agreement or the Addendum, and states them accurately.
Rights, complaints, cookies and marketing
The notice must set out the rights of access, rectification, erasure, restriction, portability and objection and the right to complain to the Information Commissioner's Office, with the business's contact details for exercising them, and Article 12 requires requests to be answered within one month. Cookies are governed by regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 and belong in a cookie policy the notice refers to, and marketing by email or text needs consent or the soft opt-in under regulation 22. The review completes the rights section, separates the cookie policy, and checks the marketing paragraph against the business's actual consents, and notes that most controllers must register with the ICO and pay a fee under the Data Protection (Charges and Information) Regulations 2018.
What it costs
Review of an AI-drafted contract, £495. One contract, returned as a marked-up Word document with my amendments as tracked changes, a clean version with the changes accepted, and a written explanation of the changes. Three working days from payment.
Buying online forms the engagement on payment. The scope is what the review of an ai-drafted contract page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- Your own Word document returned with every amendment I consider necessary shown as a tracked change, so you can see exactly what I changed and accept or reject each one
- A clean version with every change accepted, ready to send
- Corrections to anything that is wrong as a matter of English law, unenforceable as drafted, or internally inconsistent
- Missing provisions added where the document has left a gap that matters: usually liability, termination, payment, intellectual property or data
- Comments in the margin where a clause is a commercial choice rather than a legal one, so the decision stays yours
- A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, with anything you should think about before sending it out
- Follow-up questions on the mark-up answered by email, included
What is not included
- A full rewrite. This is a review and amendment of your document, not a replacement for it. If the draft is structurally unsuitable for the deal, I will say so and quote separately for drafting it properly
- A second round of amendments after you have changed the document again, which I can quote for
- Negotiating with the other side
- Advice on the law of any jurisdiction other than England and Wales
- Tax, accounting or regulatory advice
- Reviewing a document the other side drafted, which is the contract review service, at the same price
Questions I am often asked
Our AI-drafted policy refers to GDPR and the Data Protection Act 1998. Is that a problem?
The 1998 Act was repealed and the law that applies in the UK is the UK GDPR with the Data Protection Act 2018, so the notice misstates the law. The review corrects every citation and removes the provisions that apply only to other jurisdictions.
The draft says we keep data for as long as necessary. Is that enough?
The notice must state the retention period or the criteria used to determine it, for each category of data. The review asks for your retention decisions and writes them in, which also shows where a retention decision has not yet been made.
We use US-based email and analytics tools. Does the notice need to say so?
It does: the notice must state that data is transferred outside the UK and what safeguards apply. The review identifies the actual transfers and the mechanism for each, and states them accurately rather than as a general statement that data may be transferred worldwide.
Related guidance and services
- Review of an AI-drafted contract, £495, the service this page describes
- Data protection agreements and privacy terms, £795
- Getting AI-drafted website terms checked
- Getting AI-drafted terms and conditions checked
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.