Hael
Book a meeting
GDPR for AI · Readiness

GDPR for AI Readiness and Compliance Services

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 8 min read
Key takeaways
  • Readiness establishes which AI systems touch personal data, for what purposes, on what basis, and where the gaps are.
  • The deliverable is a per-system position and a prioritised plan, not an opinion that you are compliant.
  • Run it before deployment where possible, because a DPIA is required before processing begins.
  • Readiness typically costs £4,000 to £14,000 and takes two to four weeks.
  • The most common finding is a production lawful basis that was reasoned and a training basis that never was.

What a readiness assessment should contain

GDPR for AI readiness services establish where you stand. The output is an inventory of AI systems touching personal data, a purpose and lawful basis position for each, an assessment of whether a DPIA is required and whether an adequate one exists, and a prioritised plan.

Compliance services then cover the work: writing the assessments, designing and implementing safeguards, building transparency and rights processes, and establishing the ongoing review.

Timing matters more here than in other frameworks. A DPIA is required before processing begins. Running readiness after deployment means some findings arrive later than the law expected them.

ElementWhat good looks like
AI system inventoryEvery system touching personal data, built or bought, including AI features inside purchased tools
Data provenanceWhere training data came from, whose it is, and whether any is special category
Purpose separationCollection, training, evaluation and production treated as distinct purposes
Lawful basis positionA basis identified per purpose, with a judgement on whether the reasoning is adequate
Article 9 positionWhere special category data is involved, whether a condition is available
DPIA statusWhether one is required per system, whether one exists, and whether it is sufficient
Article 22 positionWhether any decision is solely automated with legal or similarly significant effect
Rights and transparency gapsWhether privacy information describes the AI processing, and whether an objection route exists
Prioritised planWhat closes each gap, who does it, ordered by risk to people rather than by convenience

Findings should be stated as findings. "This basis is reasoned, this one is not, this DPIA is missing" is defensible. "You are GDPR compliant" is a statement no adviser is in a position to make.

When to run readiness

Before deployment, ideally. The DPIA obligation attaches before processing begins, and safeguards are far cheaper to design into a system than to retrofit.

In practice most organisations run it after deployment, because AI arrived faster than the governance did. That is workable. It just means the plan has to prioritise by risk to people, and some findings will need to be addressed while the system is live.

Run it now regardless if any of the following apply: you train on personal data, you use AI in decisions about people, you bought an AI tool that processes personal data, or a customer has started asking data protection questions about your AI.

What readiness commonly finds

A production basis reasoned, a training basis never articulated. The single most common finding. The organisation can explain why it processes customer data to deliver the service and has never written down why it was lawful to train on it.

No provenance for training data. Particularly where a model was built quickly, inherited, or fine-tuned on data assembled by someone who has left.

DPIA missing or written after deployment. Or written before the system changed materially and never revisited.

No objection route. Where legitimate interests is relied on, this is the safeguard regulators have treated as central.

Vendor AI unassessed. Personal data flowing to a supplier's model with no processor terms addressing it and no assessment.

Special category data treated as ordinary. Health, biometric or similar data in training sets with no Article 9 condition identified.

Human review that would not survive scrutiny. Someone approving outputs at volume without the time or authority to disagree.

Privacy information that does not mention AI. Accurate about everything except the processing the reader would most want to know about.

Cost and timing

ServiceTypical costTypical duration
Inventory and purpose mapping£4,000 to £12,0002 to 3 weeks
Full readiness including basis and DPIA review£4,000 to £14,0002 to 4 weeks
Compliance build£12,000 to £40,0006 to 12 weeks
DPIA, per system£4,000 to £15,0002 to 4 weeks each

Cost scales with the number of AI systems, how much personal data is in training sets, and whether special category data is involved.

What compliance services cover after readiness

Writing the legitimate interests assessments. Producing the DPIAs. Designing and implementing safeguards including de-identification, filtering, retention limits and the objection route. Building human review that is real. Updating privacy information. Establishing rights processes that work against AI systems. Putting processor terms in place with AI vendors. And establishing the review cycle.

That is our implementation service.

What to do next

List the AI systems that touch personal data. It costs nothing, it is the input every proposal needs, and it usually surfaces vendor AI nobody had assessed.

Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.

References

FAQ

What is a GDPR for AI readiness assessment?

An inventory of AI systems touching personal data, with a purpose and lawful basis position for each, a DPIA status, and a prioritised plan.

Should readiness happen before deployment?

Ideally yes, because the DPIA obligation attaches before processing begins. After deployment it is still worth doing and the plan prioritises by risk.

How long does it take?

Two to four weeks for most organisations, including the delivery call.

What does it cost?

Typically £4,000 to £14,000, scaling with system count and how much personal data is in training sets.

What is the most common finding?

A well-reasoned lawful basis for running the model in production and no reasoning at all for training it.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings per system rather than issuing an opinion. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on GDPR for AI, free.

Answer a short set of questions and see what GDPR for AI expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether GDPR for AI applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to GDPR for AI.

Or speak to us about your deadline. Book a meeting.