AI Data
Privacy Review
Company data can reach AI through approved platforms, personal accounts, meeting tools and custom integrations. We map the real flows, provider terms, retention and access so the privacy and technology teams can agree what changes.
List the AI tools
Check where data goes
Agree what must change
You get data-use findings and conditions for approval.
Board report
FINDINGS, OWNERS AND PRIORITIES
UK GDPR
ICO GUIDANCE + EU AI ACT
DPIA-ready
EVIDENCE PACK YOU CAN FILE
Your AI tools can move data outside the systems you approved
Company data may appear in AI chat histories, meeting transcripts, extensions and retrieval indexes as well as its original system. Each copy can have different access and retention settings.
We compare those flows with the data map, contracts and existing assessments. Provider terms and live account settings both need checking.
The report records the technical facts and the decisions your privacy, security and legal owners need to make.
EXISTING CONTROLS
- An AI policy in the staff handbook
- "We're on the enterprise tier, so it's fine"
- A DPIA from 2021 that doesn't mention LLMs
- Copilot rolled out by IT, scoped by nobody
- A vague sense that "training is off"
EXPOSURES TO CHECK
- Staff using free ChatGPT on personal accounts
- Browser extensions that POST page contents to who-knows-where
- Copilot answering questions from HR letters and M&A docs
- A RAG bot whose index includes old API keys
- Logs that prove none of the above
How company data reaches AI tools
These routes can introduce data-protection issues. The review checks which apply to your accounts, settings and actual use.
Paste-it-in shadow AI
Staff may use personal accounts to summarise client emails, contracts or customer lists. We check what information leaves company controls and which terms apply.
Copilot oversharing
Copilot can make information easier to find within a user's existing Microsoft 365 permissions. Broad sharing therefore needs review before sensitive documents are available through search or answers.
Unclear training and retention settings
Training, retention and human-review terms vary by provider, product and account. We record the applicable settings and contract, including what remains stored when training is disabled.
RAG indexes with secrets
A retrieval index may contain old credentials, HR records or legal advice that should have been excluded. We check ingestion scope, access filtering and deletion of derived data.
Prompt injection
Instructions embedded in retrieved content may redirect an assistant or influence its output. The review checks the data it can access and the controls around any outbound action.
What the review covers
The report is written for the board, DPO, security team and customers asking about AI on procurement forms. It covers data flows, findings, owners and the evidence required for remediation.
An AI data map
AI tools found within the agreed technical and organisational scope, including sanctioned and shadow use. We record who uses them, what data is involved, which account pays and which vendor terms apply.
Vendor configuration audit
OpenAI, Anthropic, Google, Microsoft, Mistral. Training opt-outs, retention windows, regional processing, sub-processors, data processing addenda. Pulled from your actual tenants, not the marketing page.
Copilot oversharing scan
If you're running M365 Copilot, we check what it can see. Open links, inherited permissions, sensitivity labels, the documents that shouldn't be in scope but are.
Custom AI workflow review
The internal chatbot, the agent that emails customers, the RAG over your wiki. We trace the data flow end-to-end, look at the prompts, the tools the model can call, the logs, the guardrails.
Shadow AI sweep
Browser extensions, transcription tools, custom GPTs, personal accounts logged in on work machines. We surface what your team is using that you didn't approve. No naming and shaming.
Regulatory mapping
Findings reference relevant data-protection duties, ICO guidance and applicable AI controls. The report separates technical evidence from matters requiring legal interpretation.
Articles 22A to 22D triage
Where AI supports decisions about people, such as hiring, credit, pricing or flagging, we record whether the decision is solely automated and whether it has legal or similarly serious effects. That determines which current UK safeguards need review.
A prioritised fix list
Findings are ranked by risk, with an owner and effort estimate. The response may involve account settings, contracts, policy, training or engineering, depending on where the exposure sits.
A fixed-scope review
The review follows a defined evidence set across accounts, contracts, data flows, permissions and live workflows. The scope still changes with the systems, territories and data involved.
You give us read-only access. You get a board-ready report, a ranked fix list, and a DPIA-ready evidence pack you can file.
BOOK A REVIEW CALLKickoff and access
We meet the relevant technology, privacy and business owners, then agree read-only access to the accounts and systems needed for the review.
Discovery
We inspect provider settings, permissions and custom workflows, with a staff survey or interviews where useful. Collection methods and employee privacy boundaries are agreed in advance.
Mapping and findings
Each exposure gets tied to a specific UK GDPR article, ICO guidance section, EU AI Act obligation or ISO/IEC 42001 control. Each fix gets an owner, an effort estimate and a priority. We share a draft so nothing in the final report is a surprise.
Readout
A walkthrough for the responsible owners, supported by a management brief, detailed findings and evidence for further privacy assessment.
Optional remediation
Remediation is optional and scoped separately. Your own teams can take the policy and account changes, while Vu can handle engineering work where an AI workflow or integration needs changing.
Current AI privacy requirements
The applicable date depends on the system, territory and whether your organisation is a provider or deployer. These are the main dates to check:
EU prohibitions and AI literacy
Unacceptable-risk AI banned. AI literacy duties apply to providers and deployers.
EU general-purpose AI model rules
General-purpose AI model obligations and governance rules in force.
EU AI Act general application
The Act became generally applicable, but individual transparency and high-risk duties still follow their own dates.
EU high-risk system requirements
Following Regulation (EU) 2026/1744, Annex III high-risk rules apply on the first date and product-related high-risk rules on the second.
UK GDPR + ICO expectations
The ICO's AI and data protection guidance already applies. The Data (Use and Access) Act 2025 replaced the old Article 22 approach with Articles 22A to 22D and specific safeguards.
We deal with these data flows in our own AI products
Raq.com and 102.ai use several model providers and business data sources. Provider terms, retention, account access and the boundary between free tools and controlled workflows are operating decisions for us as well.
When this is worth discussing
We work best when there is a real operating problem, enough volume to measure and people from the affected teams who can make decisions.
Usually a good fit
- An established UK business, usually with annual revenue above £10m
- A repeated process with a known cost, delay, error rate or capacity problem
- A senior sponsor and a day-to-day owner who understand the work
- Access to the relevant staff, systems, sample records and security requirements
We may point you elsewhere
- A standard product already covers the process well
- The requirement is a one-off small build with no wider operating case
- There is no owner or access to the people and data needed to test the result
- The plan relies on AI making high-impact decisions with nobody responsible for review
Questions from IT, legal and compliance
We're on the enterprise tier. Doesn't that cover it?
It may provide better training, retention, access and contract controls, depending on the provider, product and settings. It does not cover personal accounts, unapproved extensions or permissions that expose more company data than intended. We check the live tenant and the use outside it.
Does the EU AI Act apply to us?
It can. A UK organisation may be in scope when it places an AI system on the EU market or its output is used in the EU. The Act became generally applicable on 2 August 2026. Following Regulation (EU) 2026/1744, Annex III high-risk rules apply from 2 December 2027 and product-related high-risk rules from 2 August 2028. We map the system, territory and your role before stating what applies.
Is this a security audit?
No. We're not testing your firewall or scanning for CVEs. We're looking specifically at how AI tools and AI workflows handle data, and whether your use of them holds up under UK GDPR, ICO guidance, the EU AI Act and ISO/IEC 42001. If you also need a general security review, we'll tell you and recommend who's good.
We don't have a DPO. Is that a problem?
No. The report is written for the operational owner, technology lead and data-protection adviser. We document the technical facts and recommended controls, while legal advice remains with your DPO or solicitor.
What do you need from us?
Read-only access to the agreed provider accounts and custom workflows, plus input from their owners. The proposal sets out meetings, staff involvement and any limits on evidence collection.
How much does it cost?
We define the systems, providers, teams and data classes in scope before issuing a commercial proposal. Any engineering work arising from the review is scoped separately so the findings remain independent.
What if we already know we've leaked something?
Tell us on the first call. The review takes a back seat to incident response: scope the exposure, rotate keys and assess whether the breach is notifiable. Where notification is required, the ICO deadline is without undue delay and, where feasible, within 72 hours of awareness. Then we fix the cause.
Will the report help with a customer or insurer questionnaire?
The report provides documented data flows, settings and findings that can support those responses. It cannot guarantee an insurer or customer will accept the controls, and questions outside the review scope need separate evidence.
Book an AI data privacy review
Tell us which AI platforms are approved, which data is sensitive and what prompted the review. We will identify the systems, contracts and user practices that need evidence before scoping the work.