GDPR for AI consultancy services
- Six workstreams: inventory, lawful basis analysis, DPIA, safeguard design, transparency and rights, and ongoing review.
- The lawful basis analysis is the workstream with the most value per hour, because everything else follows from it.
- Some of this is legal work. A good firm is clear about where advice becomes a legal opinion.
- Fees commonly run £12,000 to £40,000 for a first programme, with per-system DPIAs priced separately.
- Ask who writes the DPIA and who writes the legitimate interests assessment.
The six workstreams
GDPR for AI consultancy services cover the work of establishing that your AI systems process personal data lawfully, and holding the documentation to show it. The work divides into six workstreams.
One feature distinguishes this from framework compliance: parts of it are legal analysis. A lawful basis determination is a legal judgement, and a good firm is explicit about where its work sits and when a legal opinion is the right instrument.
Inventory. Every AI system touching personal data, what data, from where, whose, and whether any is special category. Includes AI features inside purchased software.
Lawful basis analysis. Separating the purposes, identifying a basis for each, and writing the legitimate interests assessment where that basis is used. This carries the most value per hour, because a wrong basis makes everything built on it wrong.
DPIA. Assessment before processing begins, covering necessity, proportionality, risks to people and the measures addressing them. Priced per system. Covered in GDPR for AI - DPIA Consultants.
Safeguard design. De-identification, training data filtering, output filtering, retention limits, access controls, human review in the decision path, and the objection route. This is where the DPIA turns into something real, and it usually needs engineering involvement.
Transparency and rights. Privacy information that describes the AI processing accurately, and working processes for access, objection, erasure and rectification against AI systems.
Ongoing review. Revisiting the DPIA when processing changes, the basis when purposes change, and adding a data protection gate to procurement and AI launch. Covered by our continuous governance and assurance service.
Where consultancy ends and legal advice begins
Worth being direct about, because the line is blurred in this market.
Determining whether a lawful basis is available for a novel processing operation, interpreting whether Article 22 applies to a borderline decision, or advising on exposure in a regulatory investigation are legal questions. Where a position is genuinely uncertain, a written opinion from a law firm is the right instrument, and a good consultancy will say so rather than absorb the risk quietly.
What consultancy does well is the operational work: building the inventory, structuring the assessments, writing the documentation, designing the safeguards, and running the programme. That is the bulk of the effort and it is not legal work.
What a consultancy cannot do
Certify you. There is no GDPR certification for AI. Article 42 certification schemes exist in limited form and do not cover AI generally.
Make an unlawful processing operation lawful. Where no basis is available, the answer is to change the processing.
Remove a person's influence from a trained model. The technical position is what it is; what a consultancy can do is document the measures taken and the reasoning honestly.
Guarantee a supervisory authority's view. Nobody can.
Typical fees
| Service | Typical fee |
|---|---|
| Inventory and purpose mapping | £4,000 to £12,000 |
| Lawful basis and legitimate interests assessments | £3,000 to £10,000 |
| DPIA, per system | £4,000 to £15,000 |
| Safeguard design | £5,000 to £20,000 |
| Transparency and rights process | £3,000 to £8,000 |
| Full first programme | £12,000 to £40,000 |
| Outsourced DPO | Retainer, scope dependent |
| Independent practitioner day rate | £700 to £1,600 |
Ask for DPIAs priced per system, since that is how the work scales, and ask whether legal opinions are inside or outside the fee.
Doing it once for several regimes
The same underlying work serves more than one requirement, if it is written with that in view.
The DPIA and the EU AI Act's fundamental rights impact assessment share a great deal of content. The AI Act's risk management and technical documentation draw on the same analysis. ISO/IEC 42001's AI system impact assessment covers adjacent ground. And the NIST AI RMF's MAP function asks many of the same questions.
Deciding at the start which regimes you need to satisfy is what makes one body of work serve all of them. Retrofitting is more expensive. See our EU AI Act and ISO/IEC 42001 service pages.
What to do next
Build a first-pass inventory of AI systems touching personal data. It is the input every proposal needs and cost scales with it.
Our free AI impact assessment gives an immediate first view, and the GDPR for AI service page sets out how we run each workstream.
References
FAQ
What do GDPR for AI consultancy services include?
Inventory, lawful basis analysis, DPIAs, safeguard design, transparency and rights processes, and ongoing review.
How much do they cost?
Commonly £12,000 to £40,000 for a first programme, with DPIAs at £4,000 to £15,000 per system.
Do we need a law firm as well?
For genuinely uncertain positions, a novel processing operation, or a regulatory investigation, yes. For the operational work, no.
Can a consultancy certify our GDPR compliance for AI?
No. There is no such certification. Compliance is self-assessed and demonstrated through documentation.
Can one piece of work serve the AI Act too?
Largely, if written with both in view. The DPIA and the fundamental rights impact assessment share substantial content.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the operational work, hold the deadline and stand behind the evidence, and we say plainly when a legal opinion is the right instrument rather than absorbing the question. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.