DPIA & AI policy pack
Everything a firm needs to show it has assessed and governed the AI tools already in use — including the ones fee-earners adopted without telling anyone. Assessed against UK GDPR article 35, written for lawyers rather than technologists, delivered in five to seven days.
Why this is where most firms should start
It is a fixed fee, it takes a week, and it produces the document set that enterprise clients, insurers and the ICO all ask for first. In practice it also surfaces the AML problems, because the discovery conversation is about what people actually do rather than what the policy says.
- Article 35 requires an assessment, not an intention
- Most firms have no inventory of AI use at all
- A policy read once is worth less than a page people keep
Stated in advance, delivered as described.
Completed DPIA per tool
Purpose, data flows, location of processing, retention, training use, risks and mitigations — written against your firm's facts, not a generic template.
AI acceptable-use policy
Two pages, plain English, aimed at fee-earners. The three prohibitions are unmissable; the permissions are specific enough to be followed.
Vendor assessment questionnaire
The 24 questions to send any new AI supplier, with the answers that should end the conversation marked as such.
Transparency and privacy wording
Client-facing notice language you can publish, covering AI use in service delivery.
Staff one-pager
One page of may and may not, formatted to be printed, laminated and actually consulted.
Board note
A short summary of exposure and what changed, suitable for minuting.
Four steps, no surprises.
Discovery
A 60-minute session with the people who know what is in use, plus a short written questionnaire for the rest of the firm.
Tool inventory
We list every tool in use, declared or otherwise, and confirm the data-flow position for each — from vendor documentation where it exists, from the vendor where it does not.
Assessment and drafting
DPIAs completed per tool; policy and notices drafted around your practice rather than a generic model.
Walkthrough
A 45-minute session with the compliance desk and, if you want, the fee-earners who will have to live with the policy.
Fixed numbers. The invoice matches the proposal.
| Engagement | Cost | Turnaround | What it covers | |
|---|---|---|---|---|
| DPIA & AI policy pack | $1,200 – $1,500fixed | 5–7 days |
Everything needed to show you have assessed and governed the AI tools already in use — including the ones fee-earners adopted without telling you.
|
Contact us → Estimated range $1,200 – $1,500 · how quotes work |
Payment. 50% on booking, 50% on delivery unless the option says otherwise. Card payment through Stripe, or invoice with bank transfer. Card details never touch our servers. Larger deployments are billed to milestones agreed in writing before work starts.
- Any firm where staff use AI and no DPIA exists
- Firms whose enterprise clients have started asking about AI governance
- Firms handling confidential or privileged material in tools nobody assessed
- Firms about to embark on ISO/IEC 42001 or a private AI deployment