
AI Governance and Policy Support
Put clear rules, responsibilities and controls around how AI is selected, approved and used across your organisation.
We help organisations design practical AI governance frameworks and policies that establish how AI can be used, who is responsible for overseeing it and what safeguards need to be in place.
AI Governance and Data Protection for UK Organisations
Is AI already being used across your organisation?
AI tools are often adopted by individual teams before an organisation has decided which systems are approved, what information can be entered into them or who is responsible for overseeing their use. Good AI governance puts those controls in place before inconsistent practices become established.
Read the ICO guidance on AI and data protection →
Is your organisation ready for AI?
Download our one-page AI governance readiness guide.
Download the AI governance guide →

Clara Westbrook
25+ Years PQE
Founder | Qualified Solicitor | Data Protection Specialist
07976 939 016
A common issue we find is that employees are already using tools such as ChatGPT, Copilot and other AI systems before the organisation has established any formal rules around their use.
This can mean personal data, confidential information or commercially sensitive material is being entered into AI systems without a clear understanding of where that information is going, whether the tool has been approved or what contractual and data protection safeguards are in place.
Putting governance in place gives the organisation greater visibility over how AI is being used and creates a consistent process for assessing new tools before they are introduced.
Why does AI governance matter?
Uncontrolled use of AI can create risks that are difficult to identify once a tool has already become embedded within the organisation. Employees may enter personal or confidential information into unapproved systems, rely on inaccurate outputs or use AI in ways that have not been assessed for data protection, contractual or security risks.
A clear governance framework gives your organisation a consistent way to approve AI tools, define acceptable use and identify higher-risk applications before they create a problem.
What we see in practice
AI use often starts as an operational shortcut, not a formal project. We usually begin by recording the tools in use, their business purpose, the data entered, the owner and approval status. That inventory exposes unmanaged use and gives the organisation a proportionate basis for deciding what can continue, what needs safeguards and what should stop.
What to expect from our AI governance service
We start by understanding how AI is already being used within your organisation and what you want to achieve. The level of governance required will depend on the systems involved, the information being processed and the risks created by each use case.
1
Review of existing AI use
2
AI risks and data use
3
Roles and responsibilities
4
AI governance policy
5
Approval and assessment process
6
Training and ongoing review
Some organisations simply need an acceptable-use policy for staff. Others need a wider governance framework covering multiple systems, business functions, approval processes and higher-risk uses of AI. We tailor the scope to what your organisation actually needs.
How our AI governance service works
1. Understand how AI is being used
We discuss which AI systems are already in use, how employees are using them, what information is being entered and whether there are any proposed new AI projects. We also review any existing policies, procurement processes and governance arrangements.
2. Identify the risks and design the framework
We identify areas where AI use creates data protection, confidentiality, contractual or governance risk and agree the controls that should be put in place. This may include approval routes, restricted uses, responsibility for oversight and circumstances in which a DPIA or further assessment is required.
The ICO states that AI involving processing likely to create a high risk to individuals may require a DPIA, and its governance guidance recommends integrating DPIAs into AI governance processes.
3. Put the governance into practice
We prepare the agreed framework and policy documentation and explain how it should operate in practice. Where required, we can also support implementation, staff training and the ongoing review of new AI use cases.
What are the benefits of AI governance?
A practical governance framework makes AI use visible, assigns responsibility and helps the organisation assess risk before new tools are adopted.
Clear rules for employees
Staff understand which AI tools can be used, what they can be used for and what information should not be entered into them.
Better control of risk
New AI tools and use cases can be assessed before they are adopted, reducing the risk of personal, confidential or commercially sensitive information being used inappropriately.
Stronger accountability
Defined responsibilities, approval processes and records make it easier to demonstrate how AI-related decisions are being managed.
AI governance pricing
The cost will depend on whether you require a standalone AI policy or a wider governance framework and on the number and complexity of AI systems already being used.
Fixed Fee | From £750 – £2,500 + VAT | Fixed |
Hourly Rate | £375 + VAT | Ongoing |
Daily Rate | From £1,000 + VAT | Better for long-term projects which may take a few days to a few weeks |
Retainer | Ongoing | Ongoing legal support |
We confirm the scope and fee before work begins, whether you need a standalone staff policy, a review of existing AI use or a wider governance framework with approval processes and training.
Why organisations choose WDPS
WDPS is a solicitor-led data protection organisation with more than 25 years’ experience in privacy, data protection and commercial law.
We approach AI governance from a practical perspective. Rather than producing a generic AI policy, we look at how AI is actually being used, the information involved and the risks the organisation needs to control.
Our team’s previous experience includes work involving organisations such as WarnerMedia, Yum! Brands, Burberry, Expedia and Société Générale across technology, media, retail, travel, financial services and other commercial environments.
Request AI governance support
Speak directly with a data protection specialist about how AI is being used within your organisation. +44 (0)7976 939 016 (Mon – Fri: 9:00 am – 6:00 pm Sat: 10 – 4pm).
If you would like us to review existing AI use, prepare an AI policy or design a wider governance framework, send us a short description of the tools involved and how they are being used. We will confirm the information required, the appropriate scope and the fee before work begins.
Westbrook Data Protection Services Limited, 2nd Floor, Midas House, 62 Goldsworth Road Woking, Surrey, GU21 6LQ
View our Privacy Policy here
Explore More Data Protection & Privacy Services
Our team has a deep understanding of the following areas of law and continue to add value to our clients’ businesses.
Latest Insights
- The GDPR Accountability Principle: From Paper to PracticeAccountability principle As a new consultant at Westbrook Data Protection Services, one of the first […]
- Changes to employment law and the rise in Data Subject Access RequestsChanges to employment law and the rise in Data Subject Access Requests Employment Rights Act […]
Stay ahead with expert data protection tips
Get practical advice, legal updates, and exclusive insights.
Frequently asked questions
Does every organisation need a separate AI policy?
There is no single UK rule requiring every organisation to use the same standalone policy. However, organisations using AI should have governance and documentation proportionate to the risks, including clear approval routes, assigned responsibilities and controls for personal data.
When is a DPIA needed for an AI system?
A DPIA is required where the proposed use of AI is likely to result in a high risk to individuals. This may include significant automated decision-making, systematic monitoring or large-scale use of sensitive information. The assessment should begin before the system is deployed.
Can staff enter personal data into public generative AI tools?
Only where the tool and the intended use have been approved following appropriate privacy, security and contractual checks. Staff should not enter personal or confidential information into unapproved tools, and the organisation should provide clear rules and training.
Who is responsible for personal data when an AI supplier is used?
Responsibility depends on who decides the purposes and essential means of the processing. The parties may be controller and processor, separate controllers or joint controllers. The roles should be assessed and documented rather than assumed from the supplier’s standard terms.



