Illustrative example
What a £500 scoping review actually says
A complete worked example, start to finish, so you can see the output before you buy it. The client is invented. Every legal position, source and date in it is real and was checked in the week this was written.
About this document
This is not a real client's report, redacted or otherwise. It is an illustrative example written to show the shape, the depth and the limits of the review. The company below does not exist. The findings are the ones we see most often, and each is traced to a source you can open yourself.
The client
A UK software company, 18 staff, selling a booking platform to customers in the UK and the EEA. Four months ago they added an AI assistant to the customer portal, built on a commercial LLM API. A prospective enterprise customer sent a security and data protection questionnaire, and the questions about the AI feature could not be answered from anything the company had written down.
What was reviewed
Their provider account settings, the signed agreement and its addendum, the record of processing activities, the public privacy notice, the retention policy, and the live behaviour of the assistant itself.
Not reviewed: infrastructure security, the rest of the product, employment or marketing processing, and anything outside the AI feature. Those were out of scope and are named here so nobody assumes otherwise.
The answer, first
The assistant can be run lawfully and does not need to be switched off. The provider's side of the arrangement is in reasonable order: there is a processor contract, the transfer has a valid safeguard, and the provider does not train on the data.
The gap is that almost none of that is written down correctly, and one entry that is written down is wrong. Two findings should be closed before the enterprise questionnaire is returned. Three more are cheap and should follow within the month. One is a renewal-time change.
On the specific question that prompted the review, the questionnaire can be answered honestly and well once findings 1 and 2 are closed. Returning it as things stand would put a statement in writing that the register contradicts.
Findings
The record of processing names a transfer safeguard that does not exist
BlockerThe record of processing activities states that transfers to OpenAI are covered by the EU-US Data Privacy Framework. Searching the official register by legal entity name returns no record for OpenAI under any status, active or inactive. Microsoft and Google LLC both return active certifications, so the search itself works.
The transfer is running on the Standard Contractual Clauses in OpenAI’s own agreement, which is a valid safeguard. The documentation names a different one. A record that cites a safeguard the register refutes is worse than a record that cites the right one, because it shows the entry was never checked.
Checked against: dataprivacyframework.gov, searched 5 September 2026 by legal entity name under both statuses. OpenAI’s data processing addendum, effective 1 January 2026, which carries the Standard Contractual Clauses and the UK Addendum and mentions the Framework nowhere.
No impact assessment exists for a system that needs one
BlockerThe assistant is customer-facing, runs on every inbound enquiry, and passes free-text customer messages to a third-country model provider. No data protection impact assessment has been carried out.
This is the systematic, large-scale processing Article 35 is aimed at, and the assessment is required before the processing starts rather than after. It is also the document a regulator asks for first, so its absence sets the tone for everything that follows.
Checked against: UK GDPR Article 35(1) and (3). ICO guidance on when a DPIA is required.
The public privacy notice does not mention AI processing at all
HighThe notice lists hosting, email and analytics providers. It does not say that customer messages are sent to a model provider, does not name that provider, and does not describe the transfer.
Every mismatch between the notice and the actual processing is visible to a regulator from their desk, without any investigation. This one is also visible to any customer who asks a direct question.
Checked against: UK GDPR Articles 13(1)(e) and 13(1)(f), read against the client’s live notice and the actual data flow.
Retention is on the vendor default and nobody chose it
HighAPI inputs and outputs are retained for up to 30 days for abuse monitoring, which is the provider default. Zero data retention has not been applied for. Nobody at the client had made a decision about retention either way.
Thirty days is defensible and is not the problem. The problem is that the client’s own retention policy states a different period, so the document promises something the system does not do. Zero data retention is also approval-gated by the provider rather than a self-serve toggle, so it needs a request and a lead time.
Checked against: OpenAI platform documentation on data controls, read 7 September 2026: API data is not used for training unless the customer opts in, and abuse monitoring logs are retained for up to 30 days by default.
The assistant does not tell users it is an assistant
HighThe chat widget opens with a greeting in the company’s name and gives no indication that the responses are machine generated.
The EU AI Act’s transparency duties for systems that interact directly with people have applied since 2 August 2026, and the client sells into the EU. This is a one-line fix in the widget and a paragraph in the notice, so it is a cheap gap to close and an obvious one to be caught on.
Checked against: EU AI Act Article 50(1). Applicability confirmed against the client’s stated EU customer base.
The contracting entity is the wrong one for the customer base
MediumThe account contracts with the provider’s US entity. The provider offers an Irish contracting entity for customers in the EEA, and the client has EEA customers.
This does not make the processing unlawful, and the Standard Contractual Clauses continue to carry the transfer either way. It does mean the arrangement is longer and more fragile to explain than it needs to be, and it is straightforward to change at renewal.
Checked against: OpenAI’s data processing addendum, effective 1 January 2026, on contracting entities for EEA customers.
What to do next
Every action is scoped and fixed-priced before any work starts, and two of them are things the client should simply do themselves. A review that turns every finding into billable work is not a review.
Correct the transfer entry and the processor record
The record of processing is amended to state the Standard Contractual Clauses and the UK Addendum, with the date the register was checked and by whom, so the next reader can repeat the check.
Fixed fee, quoted with the scope. Days, not weeks.
Write the impact assessment
A full DPIA for the assistant: data flows, the roles across client and provider, the risks that follow from the architecture rather than generic ones, the controls, and residual risk with a named sign-off.
Fixed fee, quoted with the scope. The £500 comes off it.
Update the privacy notice
The AI processing paragraph, the provider named, the transfer described, and the retention position stated in terms the client can actually meet.
Fixed fee, quoted with the scope.
Settle retention, then make the documents match
A decision on whether to apply for zero data retention or to operate on the 30-day default, then the retention policy amended to whichever was chosen. The client can do this without us; the decision matters more than who writes it down.
Client action. We confirm the wording if useful.
Add the Article 50 disclosure
One line in the widget and one paragraph in the notice.
Client action, same day. We supply the wording.
What the review does not do
- It is a review, not the documents. It tells you what is missing and what it will take to fix. It does not produce the DPIA, the notice or the record; those are separate, scoped and fixed-priced.
- It works from what you show us and what is publicly verifiable. We read your actual settings, contracts and documents, and we check vendor claims against primary sources. We do not audit your infrastructure or test your security.
- It is a position as at a date. Vendor terms, retention defaults and register entries all move. Every finding carries the date it was checked so you can tell when it needs looking at again.
- It is not legal advice and it is not a certification. Nobody can certify a business as compliant, and anyone offering to is selling you something that does not exist. What it says is which controls were verified in place, on the date they were checked.
Want this done for your setup?
The £500 scoping review is the document above, written about your system, with every finding traced to a source you can open. Written report in one week, no call required. If you already know which documents you need, ask for a scope and a fixed price instead.