Abstract ai security graphic for data protection services in woking.


AI Policies for the Workplace

Home / Services / Compliance & Governance / AI Governance Policy


We help organisations write and implement AI policies that govern how AI can be used in the workplace. Reducing your organisation’s risk of a breach and employee misuse.


We write AI governance policies that control how data should be used across your organisation.

Is your organisation ready for AI?
If you’re considering AI or already have it in place but don’t have a policy set up. Download our one-page AI governance readiness guide.
Download the AI governance guide →

Professional portrait of a woman with curly hair in a striped shirt, standing outdoors in natural light, used to represent a data protection expert at wdps.


Clara Westbrook
25+ Years PQE

Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016

Trustpilot logo: a green star icon to the left of the word 'trustpilot' in black text on a white background?


A common issue we find is that employees are already using tools such as ChatGPT, Copilot and other AI systems before the organisation has established any formal rules around their use.


This can mean personal data, confidential information or commercially sensitive material is being entered into AI systems without a clear understanding of where that information is going, whether the tool has been approved or what contractual and data protection safeguards are in place. Many organisations we’ve seen don’t realise this is even happening.


Putting a clear policy in place when establishing these tools gives your organisation greater visibility over how AI is being used and creates a consistent process for assessing new tools before they are introduced.

We start by understanding how AI is already being used within your organisation and what you want to achieve by having it in place. Some organisations simply need an acceptable-use policy for staff. Others need a wider governance framework covering multiple systems, business functions, approval processes and higher-risk uses of AI. We tailor the scope to what your organisation actually needs.

Our process:

1

Understand how
AI is being used

2

Identify the risks
and design the framework

3

Put the governance
into practice

1. We discuss which AI systems are already in use, how employees are using them, what information is being entered and whether there are any proposed new AI projects. We also review any existing policies, procurement processes and governance arrangements.


2. We identify areas where AI use creates data protection, confidentiality, contractual or governance risk and agree the controls that should be put in place. This may include approval routes, restricted uses, responsibility for oversight and circumstances in which a DPIA or further assessment is required.

The ICO states that AI involving processing likely to create a high risk to individuals may require a DPIA, and its governance guidance recommends integrating DPIAs into AI governance processes.

3. We prepare the agreed framework and policy documentation and explain how it should operate in practice. Where required, we can also support implementation, staff training and the ongoing review of new AI use cases.

AI governance pricing

The cost will depend on whether you require a standalone AI policy or a wider governance framework and on the number and complexity of AI systems already being used.

Fixed Fee
From £750 – £2,500 + VAT
Fixed
Hourly Rate
£375 + VAT
Ongoing
Daily Rate
From £1,000 + VAT
Better for long-term projects which may take a few days to a few weeks
Retainer
Ongoing
Ongoing legal support


We confirm the scope and fee before work begins, whether you need a standalone staff policy, a review of existing AI use or a wider governance framework with approval processes and training.

WDPS is a solicitor-led data protection organisation with more than 25 years’ experience in privacy, data protection and commercial law.


We approach AI governance from a practical perspective. Rather than producing a generic AI policy, we look at how AI is actually being used, the information involved and the risks the organisation needs to control.

Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across technology, media, retail, travel, financial services and other commercial environments.


Request AI governance support

Speak directly with a data protection specialist about how AI is being used within your organisation. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4pm).

If you would like us to review existing AI use, prepare an AI policy or design a wider governance framework, send us a short description of the tools involved and how they are being used. We will confirm the information required, the appropriate scope and the fee before work begins.

Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ

Our team has a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights

Frequently asked questions

Does every organisation need a separate AI policy?

There is no single UK rule requiring every organisation to use the same standalone policy. However, organisations using AI should have governance and documentation proportionate to the risks, including clear approval routes, assigned responsibilities and controls for personal data.

When is a DPIA needed for an AI system?

A DPIA is required where the proposed use of AI is likely to result in a high risk to individuals. This may include significant automated decision-making, systematic monitoring or large-scale use of sensitive information. The assessment should begin before the system is deployed.

Can staff enter personal data into public generative AI tools?

Only where the tool and the intended use have been approved following appropriate privacy, security and contractual checks. Staff should not enter personal or confidential information into unapproved tools, and the organisation should provide clear rules and training.

Who is responsible for personal data when an AI supplier is used?

Responsibility depends on who decides the purposes and essential means of the processing. The parties may be controller and processor, separate controllers or joint controllers. The roles should be assessed and documented rather than assumed from the supplier’s standard terms.