A six-partner practice had been using ChatGPT to draft client correspondence and summarise financial documents for months. No Data Processing Agreement. No lawful basis documented. Staff sharing client details freely with no guidance on what was and wasn't acceptable. We mapped every AI tool in use, built their UK GDPR compliance framework, produced a DPIA for the highest-risk processing, and delivered an ICO-ready policy document within two weeks.
"We'd been using AI tools daily and assumed it was fine — everyone else was doing it. Turns out we had real exposure we weren't even aware of. We're sorted now and I'd recommend this to any practice."