← Back to recipes

Evaluate AI tools for data protection compliance

complianceintermediateproven

The problem

A team member wants to use a new AI tool, or you're evaluating platforms for a project, but you're not sure if it meets your GDPR obligations. Where does the data go? Does the provider train on your inputs? What happens if there's a breach? Your DPO (if you have one) is already stretched. You need a repeatable way to assess AI tools before adopting them, without needing a law degree.

The solution

Create a structured evaluation checklist and use AI to help you work through it. Feed the tool's privacy policy and terms of service into Claude, then systematically assess data processing location, training data policies, sub-processors, breach notification, and international transfer mechanisms. Build a one-page assessment you can file for accountability and share with your DPO or trustees.

What you get

A completed AI tool assessment form covering: what data the tool processes, where it's stored and processed, whether inputs are used for training, what data processing agreement is available, international transfer safeguards, sub-processors involved, breach notification commitments, and your recommendation (approve, approve with conditions, or reject). Reusable template for future assessments.

Before you start

  • The AI tool's privacy policy and terms of service (usually on their website)
  • Your charity's data protection policy or GDPR documentation
  • Understanding of what data you plan to use with the tool
  • Basic knowledge of GDPR concepts (data controller, processor, lawful basis)

When to use this

  • Before adopting any new AI tool that will process personal data
  • When staff request to use a new AI service
  • During your annual review of existing AI tools
  • When a tool you use updates its terms of service
  • Before a pilot project involving new AI technology

When not to use this

  • The tool will only process fully anonymised or public data (low risk, but still worth a quick check)
  • You already have a thorough procurement process that covers AI-specific concerns
  • You need formal legal advice on a specific data protection question (this helps you prepare, not replace legal counsel)

Steps

  1. 1

    Gather the tool's documentation

    Find and save the tool's privacy policy, terms of service, and data processing agreement (DPA) if available. Most AI providers publish these on their website. Also check their help centre for specifics on data handling, model training, and data retention. If you can't find a DPA, that's already a red flag.

  2. 2

    Assess data processing location

    Paste the privacy policy into Claude and ask: 'Where does this company process and store user data? Identify all countries mentioned. Are there any international data transfers outside the UK/EEA? What transfer mechanisms do they use (Standard Contractual Clauses, adequacy decisions, etc.)?' For US-based providers (most AI companies), check whether they rely on the EU-US Data Privacy Framework.

  3. 3

    Check training data policies

    This is the big one for AI tools. Ask Claude: 'Does this tool use customer inputs to train or improve its AI models? Can this be opted out of? Is there a difference between free and paid tiers? What does the DPA say about this?' Many providers train on free-tier data but not paid. Know exactly where you stand.

  4. 4

    Review sub-processors and data sharing

    Ask: 'Who are this company\'s sub-processors? What third parties receive user data? Is there a published list of sub-processors?' AI tools often use cloud providers (AWS, Google Cloud), analytics services, and other AI models. Each sub-processor is another entity handling your data.

  5. 5

    Check breach notification and data retention

    Ask: 'What are this company\'s obligations on data breach notification? How quickly must they notify customers? What is their data retention policy - how long do they keep inputs and outputs? Can data be deleted on request?' Under GDPR, you need to notify the ICO within 72 hours of becoming aware of a breach, so your processor needs to tell you fast.

  6. 6

    Complete your assessment form

    Compile your findings into a one-page assessment. Include: tool name, intended use, data types involved, your assessment of each area, any conditions for approval (e.g., 'paid tier only', 'no personal data'), and your recommendation. File this for accountability - you may need to show the ICO your due diligence.

Example code

AI tool assessment template

A reusable template for evaluating AI tools against data protection requirements.

# AI Tool Data Protection Assessment

**Tool name:** [e.g., Claude / ChatGPT / Midjourney]
**Assessed by:** [Name]
**Date:** [Date]
**Intended use:** [What will we use it for?]
**Data types involved:** [What personal data, if any, will be processed?]

## Assessment

| Area | Finding | Status |
|------|---------|--------|
| Data processing location | [Where is data processed?] | [OK / Concern / Blocker] |
| Training on inputs | [Does the tool train on our data?] | [OK / Concern / Blocker] |
| DPA available | [Is a Data Processing Agreement available?] | [OK / Concern / Blocker] |
| International transfers | [Transfer mechanisms in place?] | [OK / Concern / Blocker] |
| Sub-processors | [Who else handles the data?] | [OK / Concern / Blocker] |
| Breach notification | [How quickly are we notified?] | [OK / Concern / Blocker] |
| Data retention | [How long is data kept?] | [OK / Concern / Blocker] |
| Deletion rights | [Can we request data deletion?] | [OK / Concern / Blocker] |

## Conditions
- [e.g., Paid tier only - free tier trains on data]
- [e.g., No identified beneficiary data]
- [e.g., DPA must be signed before use]

## Recommendation
[ ] Approved
[ ] Approved with conditions (see above)
[ ] Not approved - [reason]

## Review date
[Date + 12 months, or when terms change]

Tools

Claudeservice · freemium
Visit →

Resources

At a glance

Time to implement
hours
Setup cost
free
Ongoing cost
free
Cost trend
stable
Organisation size
small, medium, large
Target audience
operations-manager, it-technical, ceo-trustees

Free tier AI is fine for this - you're analysing publicly available policies, not sensitive data.

Written by AI Recipes for Charities

Last updated: 2026-04-04