Abstract ai security graphic for data protection services in woking.
Home / Services / Compliance & Governance / AI Governance Policy


We help organisations design practical AI governance frameworks and policies that establish how AI can be used, who is responsible for overseeing it and what safeguards need to be in place.


AI Governance and Data Protection for UK Organisations

Is your organisation ready for AI?
Download our one-page AI governance readiness guide.
Download the AI governance guide →

Professional portrait of a woman with curly hair in a striped shirt, standing outdoors in natural light, used to represent a data protection expert at wdps.


Clara Westbrook
25+ Years PQE

Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016

Trustpilot logo: a green star icon to the left of the word 'trustpilot' in black text on a white background?


A common issue we find is that employees are already using tools such as ChatGPT, Copilot and other AI systems before the organisation has established any formal rules around their use.


This can mean personal data, confidential information or commercially sensitive material is being entered into AI systems without a clear understanding of where that information is going, whether the tool has been approved or what contractual and data protection safeguards are in place.


Putting governance in place gives the organisation greater visibility over how AI is being used and creates a consistent process for assessing new tools before they are introduced.

What we see in practice

AI use often starts as an operational shortcut, not a formal project. We usually begin by recording the tools in use, their business purpose, the data entered, the owner and approval status. That inventory exposes unmanaged use and gives the organisation a proportionate basis for deciding what can continue, what needs safeguards and what should stop.

We start by understanding how AI is already being used within your organisation and what you want to achieve. The level of governance required will depend on the systems involved, the information being processed and the risks created by each use case.

1

Review of existing AI use

2

AI risks and data use

3

Roles and responsibilities

4

AI governance policy

5

Approval and assessment process

6

Training and ongoing review

Some organisations simply need an acceptable-use policy for staff. Others need a wider governance framework covering multiple systems, business functions, approval processes and higher-risk uses of AI. We tailor the scope to what your organisation actually needs.

1. Understand how AI is being used

We discuss which AI systems are already in use, how employees are using them, what information is being entered and whether there are any proposed new AI projects. We also review any existing policies, procurement processes and governance arrangements.


2. Identify the risks and design the framework

We identify areas where AI use creates data protection, confidentiality, contractual or governance risk and agree the controls that should be put in place. This may include approval routes, restricted uses, responsibility for oversight and circumstances in which a DPIA or further assessment is required.

The ICO states that AI involving processing likely to create a high risk to individuals may require a DPIA, and its governance guidance recommends integrating DPIAs into AI governance processes.

3. Put the governance into practice

We prepare the agreed framework and policy documentation and explain how it should operate in practice. Where required, we can also support implementation, staff training and the ongoing review of new AI use cases.


What are the benefits of AI governance?

A practical governance framework makes AI use visible, assigns responsibility and helps the organisation assess risk before new tools are adopted.


Clear rules for employees

Staff understand which AI tools can be used, what they can be used for and what information should not be entered into them.


Better control of risk

New AI tools and use cases can be assessed before they are adopted, reducing the risk of personal, confidential or commercially sensitive information being used inappropriately.


Stronger accountability
Defined responsibilities, approval processes and records make it easier to demonstrate how AI-related decisions are being managed.

AI governance pricing

The cost will depend on whether you require a standalone AI policy or a wider governance framework and on the number and complexity of AI systems already being used.

Fixed Fee
From £750 – £2,500 + VAT
Fixed
Hourly Rate
£375 + VAT
Ongoing
Daily Rate
From £1,000 + VAT
Better for long-term projects which may take a few days to a few weeks
Retainer
Ongoing
Ongoing legal support


We confirm the scope and fee before work begins, whether you need a standalone staff policy, a review of existing AI use or a wider governance framework with approval processes and training.

WDPS is a solicitor-led data protection organisation with more than 25 years’ experience in privacy, data protection and commercial law.


We approach AI governance from a practical perspective. Rather than producing a generic AI policy, we look at how AI is actually being used, the information involved and the risks the organisation needs to control.

Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across technology, media, retail, travel, financial services and other commercial environments.


Request AI governance support

Speak directly with a data protection specialist about how AI is being used within your organisation. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4pm).

If you would like us to review existing AI use, prepare an AI policy or design a wider governance framework, send us a short description of the tools involved and how they are being used. We will confirm the information required, the appropriate scope and the fee before work begins.

Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ

Our team has a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights

Frequently asked questions

Does every organisation need a separate AI policy?

There is no single UK rule requiring every organisation to use the same standalone policy. However, organisations using AI should have governance and documentation proportionate to the risks, including clear approval routes, assigned responsibilities and controls for personal data.

When is a DPIA needed for an AI system?

A DPIA is required where the proposed use of AI is likely to result in a high risk to individuals. This may include significant automated decision-making, systematic monitoring or large-scale use of sensitive information. The assessment should begin before the system is deployed.

Can staff enter personal data into public generative AI tools?

Only where the tool and the intended use have been approved following appropriate privacy, security and contractual checks. Staff should not enter personal or confidential information into unapproved tools, and the organisation should provide clear rules and training.

Who is responsible for personal data when an AI supplier is used?

Responsibility depends on who decides the purposes and essential means of the processing. The parties may be controller and processor, separate controllers or joint controllers. The roles should be assessed and documented rather than assumed from the supplier’s standard terms.