
AI Policies for the Workplace
We’ll help you put clear rules in place to control how AI is governed and used across your organisation.
We help organisations write and implement AI policies that govern how AI can be used in the workplace. Reducing your organisation’s risk of a breach and employee misuse.
We write AI governance policies that control how data should be used across your organisation.
Is AI already being used across your organisation?
We regularly see AI tools being used before an organisation has decided which systems are approved, what information can be entered into them or who is responsible for overseeing their use. This had lead to serious incidences where company confidential information has been disclosed. Good AI governance puts those controls in place before inconsistent practices become established.
Read the ICO guidance on AI and data protection →
Is your organisation ready for AI?
If you’re considering AI or already have it in place but don’t have a policy set up. Download our one-page AI governance readiness guide.
Download the AI governance guide →

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
A common issue we find is that employees are already using tools such as ChatGPT, Copilot and other AI systems before the organisation has established any formal rules around their use.
This can mean personal data, confidential information or commercially sensitive material is being entered into AI systems without a clear understanding of where that information is going, whether the tool has been approved or what contractual and data protection safeguards are in place. Many organisations we’ve seen don’t realise this is even happening.
Putting a clear policy in place when establishing these tools gives your organisation greater visibility over how AI is being used and creates a consistent process for assessing new tools before they are introduced.
Why does an AI policy matter?
We have dealt with situations where unregulated use of AI has created risks for organisations that they weren’t even aware of. In one instance, employees were entering personal and client information into an open source AI chat bot as it reduced time reading and responding to requests. This exposed the organisation to serious risks, as the information inputted was being used to train other open source chat bots and give responses to other users based on the information it was being fed.
A clear AI policy stops this and puts your organisation a stronger position if a breach were to happen.
What to expect from our AI governance service
We start by understanding how AI is already being used within your organisation and what you want to achieve by having it in place. Some organisations simply need an acceptable-use policy for staff. Others need a wider governance framework covering multiple systems, business functions, approval processes and higher-risk uses of AI. We tailor the scope to what your organisation actually needs.
Our process:
1
Understand how
AI is being used
2
Identify the risks
and design the framework
3
Put the governance
into practice
How our AI governance service works
1. We discuss which AI systems are already in use, how employees are using them, what information is being entered and whether there are any proposed new AI projects. We also review any existing policies, procurement processes and governance arrangements.
2. We identify areas where AI use creates data protection, confidentiality, contractual or governance risk and agree the controls that should be put in place. This may include approval routes, restricted uses, responsibility for oversight and circumstances in which a DPIA or further assessment is required.
The ICO states that AI involving processing likely to create a high risk to individuals may require a DPIA, and its governance guidance recommends integrating DPIAs into AI governance processes.
3. We prepare the agreed framework and policy documentation and explain how it should operate in practice. Where required, we can also support implementation, staff training and the ongoing review of new AI use cases.
AI governance pricing
The cost will depend on whether you require a standalone AI policy or a wider governance framework and on the number and complexity of AI systems already being used.
Fixed Fee | From £750 – £2,500 + VAT | Fixed |
Hourly Rate | £375 + VAT | Ongoing |
Daily Rate | From £1,000 + VAT | Better for long-term projects which may take a few days to a few weeks |
Retainer | Ongoing | Ongoing legal support |
We confirm the scope and fee before work begins, whether you need a standalone staff policy, a review of existing AI use or a wider governance framework with approval processes and training.
Why organisations choose to work with us
WDPS is a solicitor-led data protection organisation with more than 25 years’ experience in privacy, data protection and commercial law.
We approach AI governance from a practical perspective. Rather than producing a generic AI policy, we look at how AI is actually being used, the information involved and the risks the organisation needs to control.
Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across technology, media, retail, travel, financial services and other commercial environments.
Request AI governance support
Speak directly with a data protection specialist about how AI is being used within your organisation. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4pm).
If you would like us to review existing AI use, prepare an AI policy or design a wider governance framework, send us a short description of the tools involved and how they are being used. We will confirm the information required, the appropriate scope and the fee before work begins.
Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ
View our Privacy Policy here
Explore More Data Protection & Privacy Services
Our team has a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
Frequently asked questions
Does every organisation need a separate AI policy?
There is no single UK rule requiring every organisation to use the same standalone policy. However, organisations using AI should have governance and documentation proportionate to the risks, including clear approval routes, assigned responsibilities and controls for personal data.
When is a DPIA needed for an AI system?
A DPIA is required where the proposed use of AI is likely to result in a high risk to individuals. This may include significant automated decision-making, systematic monitoring or large-scale use of sensitive information. The assessment should begin before the system is deployed.
Can staff enter personal data into public generative AI tools?
Only where the tool and the intended use have been approved following appropriate privacy, security and contractual checks. Staff should not enter personal or confidential information into unapproved tools, and the organisation should provide clear rules and training.
Who is responsible for personal data when an AI supplier is used?
Responsibility depends on who decides the purposes and essential means of the processing. The parties may be controller and processor, separate controllers or joint controllers. The roles should be assessed and documented rather than assumed from the supplier’s standard terms.



