LegalAI Space

Every plan, including Free · v1.0.0

Privacy & Data Protection

Your whole UK GDPR practice in one agent: DSARs, DPAs, DPIAs and triage

Protocols
5
Skills
4
Public sources
7
Workflows
1
Employment Contract Compliance Review · Action items · 6
Six action items waiting for confirmation, each with the clause it came from and the change proposed.

Six action items waiting for confirmation, each with the clause it came from and the change proposed.

What it does

Assesses data protection questions and breach responses against UK and EU GDPR.

The Privacy & Data Protection Agent assesses questions against the UK GDPR, the Data Protection Act 2018 and EU GDPR, and can run a breach-notification assessment, working out whether a notification to the ICO or affected individuals is required and to what timeline.

Typical tasks

  1. 01Assess a personal data breach for notification duties
  2. 02Review a privacy notice against UK GDPR requirements
  3. 03Answer a data-sharing question with the applicable lawful basis

Best for

  • DPOs and privacy teams who want one agent for the whole UK GDPR workflow.
  • Anyone running a DSAR against the one-month statutory clock.
  • Teams triaging a new processing activity before it needs a full DPIA.

How it works

From task to memo, in 5 steps.

Every step is recorded under How this was made on the finished run, with a pass, a needs a look, or a failure against each check. Nothing here is a description of intent. It is what the software does.

  1. 01

    Describe the task

    Describe the task: a DSAR, a DPA to review, a new processing activity, or a triage question.

  2. 02

    Load the matching skill

    The agent loads the matching skill and runs the workflow: computing deadlines, screening, or redlining.

  3. 03

    Screen and verify

    PII Redaction and Privilege Review run automatically, and citations are verified on demand.

  4. 04

    Receive the draft

    Receive a draft: an acknowledgement, a response pack, a redline list, a DPIA, or a triage decision.

  5. 05

    The DPO reviews and sends

    The DPO reviews, decides and sends; every output is a draft, not a final position.

Governed by

5 protocols.

Protocols run before and during the work: they plan, confirm the jurisdiction, screen personal data, check privilege. Gates run after, on the output, and they are code rather than a model's opinion. A failed gate is shown, never hidden.

Protocols

  1. 01Planning ProtocolMaps out the plan before any work starts: which sources answer which part of the task, in what order.
  2. 02Legal Citation VerifierIndependently re-fetches every cited authority and confirms it exists and reads as quoted before the memo reaches you.
  3. 03Privilege ReviewAssesses the output for privileged or confidential material and flags disclosure risk before it is circulated.
  4. 04PII RedactionScreens the task for personal and client data and redacts it before dispatch, with an allow-list so the firm's own name is not stripped from its own memo.
  5. 05Jurisdiction GatekeeperConfirms the task sits inside a jurisdiction the firm has enabled, and flags anything that strays outside it.

Skills

  • Privilege & Confidentiality
  • Data Protection (UK GDPR & Privacy)
  • DSAR Handling (UK GDPR)
  • DPIA Methodology (UK GDPR Art 35)

What comes back

A document with its working attached.

A memo with the assessment, the notification duties and deadlines identified, authorities with verdicts, and open questions.
  1. 01Summary
  2. 02Files
  3. 03Action items
  4. 04Authorities
  5. 05Open questions
  6. 06How this was made

Sources it may cite

Connectors in the catalogue

Catalogue tiles, not live integrations today. Documents are uploaded to the matter.

  • Definely
  • Microsoft 365
  • Google Drive
  • OpenLaw

Try it

Three tasks to start with.

These are the prompts the agent suggests inside the product. Paste your own document under any of them.

  • Respond to a DSAR

    Log this subject access request, compute the statutory deadline, apply the relevant DPA 2018 exemptions, and draft a redaction log and response pack:

  • Review a DPA under Article 28

    Review this data processing agreement against Article 28 UK GDPR from the controller's side. Check every mandatory term and the transfer mechanism, and propose redlines:

  • Run a DPIA or triage

    Screen this new processing activity: proceed, PIA or DPIA. If a DPIA is needed, build the risk register and the Article 36 consultation decision:

What it does not do yet

  • The DPO reviews, decides and sends every output: nothing is submitted to the ICO or a data subject automatically.