Every plan, including Free · v1.0.0
Privacy & Data Protection
Your whole UK GDPR practice in one agent: DSARs, DPAs, DPIAs and triage
- Protocols
- 5
- Skills
- 4
- Public sources
- 7
- Workflows
- 1



Six action items waiting for confirmation, each with the clause it came from and the change proposed.
What it does
Assesses data protection questions and breach responses against UK and EU GDPR.
Typical tasks
- 01Assess a personal data breach for notification duties
- 02Review a privacy notice against UK GDPR requirements
- 03Answer a data-sharing question with the applicable lawful basis
Best for
- DPOs and privacy teams who want one agent for the whole UK GDPR workflow.
- Anyone running a DSAR against the one-month statutory clock.
- Teams triaging a new processing activity before it needs a full DPIA.
How it works
From task to memo, in 5 steps.
Every step is recorded under How this was made on the finished run, with a pass, a needs a look, or a failure against each check. Nothing here is a description of intent. It is what the software does.
01
Describe the task
Describe the task: a DSAR, a DPA to review, a new processing activity, or a triage question.
02
Load the matching skill
The agent loads the matching skill and runs the workflow: computing deadlines, screening, or redlining.
03
Screen and verify
PII Redaction and Privilege Review run automatically, and citations are verified on demand.
04
Receive the draft
Receive a draft: an acknowledgement, a response pack, a redline list, a DPIA, or a triage decision.
05
The DPO reviews and sends
The DPO reviews, decides and sends; every output is a draft, not a final position.
Governed by
5 protocols.
Protocols run before and during the work: they plan, confirm the jurisdiction, screen personal data, check privilege. Gates run after, on the output, and they are code rather than a model's opinion. A failed gate is shown, never hidden.
Protocols
- 01Planning ProtocolMaps out the plan before any work starts: which sources answer which part of the task, in what order.
- 02Legal Citation VerifierIndependently re-fetches every cited authority and confirms it exists and reads as quoted before the memo reaches you.
- 03Privilege ReviewAssesses the output for privileged or confidential material and flags disclosure risk before it is circulated.
- 04PII RedactionScreens the task for personal and client data and redacts it before dispatch, with an allow-list so the firm's own name is not stripped from its own memo.
- 05Jurisdiction GatekeeperConfirms the task sits inside a jurisdiction the firm has enabled, and flags anything that strays outside it.
Skills
- Privilege & Confidentiality
- Data Protection (UK GDPR & Privacy)
- DSAR Handling (UK GDPR)
- DPIA Methodology (UK GDPR Art 35)
What comes back
A document with its working attached.
Try it
Three tasks to start with.
These are the prompts the agent suggests inside the product. Paste your own document under any of them.
Respond to a DSAR
Log this subject access request, compute the statutory deadline, apply the relevant DPA 2018 exemptions, and draft a redaction log and response pack:
Review a DPA under Article 28
Review this data processing agreement against Article 28 UK GDPR from the controller's side. Check every mandatory term and the transfer mechanism, and propose redlines:
Run a DPIA or triage
Screen this new processing activity: proceed, PIA or DPIA. If a DPIA is needed, build the risk register and the Article 36 consultation decision:
What it does not do yet
- The DPO reviews, decides and sends every output: nothing is submitted to the ICO or a data subject automatically.
Workflows