GDPR for AI Readiness and Compliance Services
- Readiness establishes which AI systems touch personal data, for what purposes, on what basis, and where the gaps are.
- The deliverable is a per-system position and a prioritised plan, not an opinion that you are compliant.
- Run it before deployment where possible, because a DPIA is required before processing begins.
- Readiness typically costs £4,000 to £14,000 and takes two to four weeks.
- The most common finding is a production lawful basis that was reasoned and a training basis that never was.
What a readiness assessment should contain
GDPR for AI readiness services establish where you stand. The output is an inventory of AI systems touching personal data, a purpose and lawful basis position for each, an assessment of whether a DPIA is required and whether an adequate one exists, and a prioritised plan.
Compliance services then cover the work: writing the assessments, designing and implementing safeguards, building transparency and rights processes, and establishing the ongoing review.
Timing matters more here than in other frameworks. A DPIA is required before processing begins. Running readiness after deployment means some findings arrive later than the law expected them.
| Element | What good looks like |
|---|---|
| AI system inventory | Every system touching personal data, built or bought, including AI features inside purchased tools |
| Data provenance | Where training data came from, whose it is, and whether any is special category |
| Purpose separation | Collection, training, evaluation and production treated as distinct purposes |
| Lawful basis position | A basis identified per purpose, with a judgement on whether the reasoning is adequate |
| Article 9 position | Where special category data is involved, whether a condition is available |
| DPIA status | Whether one is required per system, whether one exists, and whether it is sufficient |
| Article 22 position | Whether any decision is solely automated with legal or similarly significant effect |
| Rights and transparency gaps | Whether privacy information describes the AI processing, and whether an objection route exists |
| Prioritised plan | What closes each gap, who does it, ordered by risk to people rather than by convenience |
Findings should be stated as findings. "This basis is reasoned, this one is not, this DPIA is missing" is defensible. "You are GDPR compliant" is a statement no adviser is in a position to make.
When to run readiness
Before deployment, ideally. The DPIA obligation attaches before processing begins, and safeguards are far cheaper to design into a system than to retrofit.
In practice most organisations run it after deployment, because AI arrived faster than the governance did. That is workable. It just means the plan has to prioritise by risk to people, and some findings will need to be addressed while the system is live.
Run it now regardless if any of the following apply: you train on personal data, you use AI in decisions about people, you bought an AI tool that processes personal data, or a customer has started asking data protection questions about your AI.
What readiness commonly finds
A production basis reasoned, a training basis never articulated. The single most common finding. The organisation can explain why it processes customer data to deliver the service and has never written down why it was lawful to train on it.
No provenance for training data. Particularly where a model was built quickly, inherited, or fine-tuned on data assembled by someone who has left.
DPIA missing or written after deployment. Or written before the system changed materially and never revisited.
No objection route. Where legitimate interests is relied on, this is the safeguard regulators have treated as central.
Vendor AI unassessed. Personal data flowing to a supplier's model with no processor terms addressing it and no assessment.
Special category data treated as ordinary. Health, biometric or similar data in training sets with no Article 9 condition identified.
Human review that would not survive scrutiny. Someone approving outputs at volume without the time or authority to disagree.
Privacy information that does not mention AI. Accurate about everything except the processing the reader would most want to know about.
Cost and timing
| Service | Typical cost | Typical duration |
|---|---|---|
| Inventory and purpose mapping | £4,000 to £12,000 | 2 to 3 weeks |
| Full readiness including basis and DPIA review | £4,000 to £14,000 | 2 to 4 weeks |
| Compliance build | £12,000 to £40,000 | 6 to 12 weeks |
| DPIA, per system | £4,000 to £15,000 | 2 to 4 weeks each |
Cost scales with the number of AI systems, how much personal data is in training sets, and whether special category data is involved.
What compliance services cover after readiness
Writing the legitimate interests assessments. Producing the DPIAs. Designing and implementing safeguards including de-identification, filtering, retention limits and the objection route. Building human review that is real. Updating privacy information. Establishing rights processes that work against AI systems. Putting processor terms in place with AI vendors. And establishing the review cycle.
That is our implementation service.
What to do next
List the AI systems that touch personal data. It costs nothing, it is the input every proposal needs, and it usually surfaces vendor AI nobody had assessed.
Our free AI impact assessment gives an immediate first view, and our readiness and gap assessment produces the full position for a fixed fee.
References
FAQ
What is a GDPR for AI readiness assessment?
An inventory of AI systems touching personal data, with a purpose and lawful basis position for each, a DPIA status, and a prioritised plan.
Should readiness happen before deployment?
Ideally yes, because the DPIA obligation attaches before processing begins. After deployment it is still worth doing and the plan prioritises by risk.
How long does it take?
Two to four weeks for most organisations, including the delivery call.
What does it cost?
Typically £4,000 to £14,000, scaling with system count and how much personal data is in training sets.
What is the most common finding?
A well-reasoned lawful basis for running the model in production and no reasoning at all for training it.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. Our readiness and gap assessment is delivered as a fixed fee with a delivery call, and states findings per system rather than issuing an opinion. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.