UK GDPR

GDPR Compliant AI Starts With Where the Data Goes

No product can make your business UK GDPR-compliant on its own, and we will not pretend otherwise. What an on-premises AI machine does is remove the hardest question from the assessment. With Local AI, the personal data does not go anywhere.

£500 per month for the software and the hardware rental. You rent the machine — you don’t buy it.

GDPR compliant AI means AI used in a way that meets the UK GDPR and Data Protection Act 2018. The hardest part is usually where personal data is processed. Local AI runs on a machine in your own office, so there is no third-party AI processor and no restricted transfer to justify; lawful basis and retention remain yours.

Bring your DPO to the call

These are the questions we would rather answer early. Bring your DPO or your advisers; we will walk through the data flow line by line.

The Data Flow
An on-premises AI machine keeping personal data inside a UK office

Model, documents and chat history on one machine inside your building. The only outside connection is to your own Microsoft or Google account for sign-in.

AI and GDPR compliance for UK solicitors, clinics, accountants and HR teams

ICO as regulator, UK GDPR and the Data Protection Act 2018 as the rules. Here is what changes when the data stays put.

Also From Us · Cloud AI Agents

The Phone and the Inbox Can Stay in the Cloud

Local AI is for the confidential, document-heavy work. For answering calls, managing the inbox and chasing leads, our hosted agents are up and running in days with no hardware at all — and plenty of clients run both.

See the Local AI product page →
The Assessment

The Questions Your DPO Asks About GDPR and AI

Most of the hard work in an AI GDPR assessment is about the processor and the transfer. Here is what each looks like for a cloud service and for a machine in your own office.

The questionCloud AI serviceLocal AI (on-premises)
Who is the processor for the AI step?The AI provider — appoint, assess, contract, reviewNobody — the model runs on your own machine
Is there a restricted transfer?Often — IDTA or UK Addendum, plus a transfer risk assessmentNo — the data never leaves your building
Is our data used to train models?Depends on the plan, the settings and the small printNever
What goes in the Article 30 record?A new processor and, often, a new transferOne fewer of each
Article 32 security of processingTheir controls, assessed by youYour network, your access controls, hardware you physically hold
Erasure requestsYour copy and theirsYour copy only
Lawful basis, purpose, retentionYoursStill yours
What Changes

What Local AI Settles, and What It Leaves With You

The ICO’s guidance on AI and data protection does not ask whether a tool is “compliant”. It asks the usual questions — purpose, lawful basis, minimisation, security, rights, accountability — and then asks them again for each processor and each transfer you have introduced. That last part is where cloud AI gets expensive to sign off: a new Article 28 contract, a transfer mechanism, a transfer risk assessment, and all of it kept under review.

Local AI removes those items rather than answering them. The model runs on a dedicated machine on your network. Documents, prompts and chat history are stored on it. There is no AI provider processing personal data on your behalf, so there is no processor to appoint for that step. There is no transfer, because nothing leaves the UK or, for that matter, the room. Your record of processing gains one fewer processor and one fewer transfer to describe and keep current.

Security of processing under Article 32 becomes a question about your own network and your own access controls, which is a question you already answer for everything else you hold. Staff sign in with the Microsoft 365 or Google Workspace accounts you already administer, so who can see what is decided with the tools you have.

What stays with you is everything that was always yours. You remain the data controller. Purpose and lawful basis are your call. Your retention policy keeps applying, and because the files never left, a deletion is a deletion. Staff conduct is still your responsibility — the difference is that the private assistant is the easy option, so the habit of pasting client material into a public chatbot ends on its own. We act as a processor only for the support access you grant us, and we will sign a data processing agreement covering exactly that.

We say this plainly because the GDPR compliance AI vendors advertise usually means a tick-box that promises not to train on your data. That is worth having. It is not the same as the data never leaving your building.

What You Get

What Is Installed, and What the Paperwork Looks Like

The machine, the software on it, the sign-in, the training and the support — and the two documents your advisers will ask for.

🏠

No third-party AI processor

The model runs on your own machine, so your documents are never sent to an AI provider. Nothing to appoint, assess or keep under review for the AI step.

🇬🇧

No restricted transfers

Your data never leaves the UK. The IDTA, the UK Addendum and a transfer risk assessment simply do not arise for the processing Local AI does.

📋

A shorter Article 30 record

One fewer processor and one fewer transfer to describe, review and keep current — and one less thing to explain if the ICO ever asks.

IncludedNot included
A dedicated machine, sized for your team, rented to you (not sold) and installed by usA cloud subscription — nothing runs on our servers
£500 per month for the software and the hardware rentalBuying the hardware — the machine is rented, not sold
Private chat, document spaces and custom assistants on that machineClinical, legal or financial advice — it drafts, you decide
Single sign-on with your Microsoft 365 or Google WorkspaceA replacement for your practice, case or CRM system
Import of your existing documents, and training for the people using itPhone answering — see AI Receptionist
Software updates, model upgrades and support from the people who installed itInbox automation — see Email Manager
A data processing agreement covering the support access you grant usA certificate that says your business is “GDPR compliant” — no such thing exists
How It Works

From Sign-Off Blocker to Working Machine

Weeks, not months. Bring the questions early; they are easier to answer before hardware is ordered.

1

Walk the data flow

A call with you and, ideally, your DPO. We go through where data sits, who signs in, what is backed up and where, and the support access you will grant.

2

Install inside your network

The machine goes on your premises, single sign-on connects to your Microsoft 365 or Google Workspace, and your documents are imported into spaces — none of it touching an outside service.

3

Sign the DPA, train the team

The data processing agreement covers our support access. We train the people using it and keep the software and models current.

Straight Answers

Where Local AI Is the Wrong Answer

We would rather lose the enquiry than the trust. Three things we tell every prospect before they sign anything.

It is not a compliance certificate

No product can make a business UK GDPR-compliant on its own. Local AI removes the processor and transfer questions for the AI step. Purpose, lawful basis, retention and staff conduct remain yours, and we will not tell you otherwise.

It is slower than the big cloud models

Open-weight models on a single machine are capable for summarising, drafting and answering questions about your own documents. For frontier reasoning on hard, novel problems, the largest cloud models are still ahead. That is the trade.

It is a weeks-long install, not a sign-up

A cloud agent is live in days. Local AI needs the machine specified, delivered, installed on your network and your documents imported. Weeks, not months — but not tomorrow.

Why Business AI Agents

Built With the Regulator in Mind

Data never leaves the building

Model, documents and chat history on one machine in your office. The only outside connection is your own sign-in.

Never used for training

Your content is not used to train or improve any model. The models arrive trained and stay that way unless you ask.

One DPA, for one thing

We are a processor only for the support access you grant, and the agreement says so in plain terms.

Honest about the trade

Local models are capable and somewhat slower than the largest cloud services. We say so before you sign anything.

Which Page Answers Your Question

If your question is…The short answerRead more
What exactly is installed?One machine: chat, spaces, assistants, supportOn-premises AI solution
Is this what people mean by private AI?Yes — private by constructionPrivate AI
Which model runs on it?An open-weight local LLM, matched to the jobLocal LLM
We are solicitorsClient files and privilege stay in the officeLocal AI for solicitors
We are a GP practicePractice documents stay inside the surgeryLocal AI for GP practices
We are a dental practicePatient records stay in the practiceLocal AI for dental practices
Why on-premises at all?The case for Local AI, in fullLocal AI product page

GDPR Compliant AI by City and Sector

GDPR Compliant AI London GDPR Compliant AI Manchester GDPR Compliant AI for dental practices GDPR Compliant AI for solicitors GDPR Compliant AI for estate agents GDPR Compliant AI for gp practices

AI and GDPR Compliance: Common Questions

Is there such a thing as GDPR compliant AI?

Not as a product label. Compliance is a property of how your business uses a tool, not of the tool. What a product can do is make the assessment easier. Local AI keeps personal data on a machine in your office, which removes the processor and transfer questions for the AI step entirely.

Do we need a data processing agreement for AI?

If a provider processes personal data on your behalf, yes — that is an Article 28 contract. With Local AI the model runs on your own machine, so there is no AI processor to contract with. We act as a processor only for the support access you choose to grant us, and we sign a data processing agreement covering it.

Does using AI count as an international transfer?

Cloud AI often does, if the provider processes data outside the UK, which brings in the IDTA or the UK Addendum and a transfer risk assessment. With Local AI your data never leaves the UK — it never leaves your building — so the restricted-transfer questions do not arise for the processing it does.

Do we need a DPIA for AI?

Often, yes, and we would rather you did one. Local AI makes it shorter: the questions about the processor, the transfer mechanism and the training use of your data have plain answers. The questions about purpose, lawful basis, retention and who has access are still yours to answer.

Is our data used to train the model?

No. Your documents and conversations are not used to train or improve any model, ours or anyone else’s. The models arrive trained and stay that way unless you ask us to change them.

What happens when someone asks us to erase their data?

Retention and deletion follow the policy you already have, because the files never left your systems. When you action a deletion, there is no third-party copy of the data to chase.

How much does Local AI cost?

£500 per month for the software and the hardware rental. The dedicated machine is rented to your business, not sold: you never buy the hardware. It is installed in your building and runs the private chat, document spaces and assistants. Local AI is for business customers only.

Bring the Hard Questions Early

Tell us what is blocking AI sign-off in your business. We will walk through the data flow with you and your advisers, and say plainly what Local AI settles and what it does not.

Book a Consultation

Prefer email? sghaith@businessaiagents.co.uk