GDPR Compliant AI Starts With Where the Data Goes
No product can make your business UK GDPR-compliant on its own, and we will not pretend otherwise. What an on-premises AI machine does is remove the hardest question from the assessment. With Local AI, the personal data does not go anywhere.
£500 per month for the software and the hardware rental. You rent the machine — you don’t buy it.
GDPR compliant AI means AI used in a way that meets the UK GDPR and Data Protection Act 2018. The hardest part is usually where personal data is processed. Local AI runs on a machine in your own office, so there is no third-party AI processor and no restricted transfer to justify; lawful basis and retention remain yours.
Bring your DPO to the call
These are the questions we would rather answer early. Bring your DPO or your advisers; we will walk through the data flow line by line.
Model, documents and chat history on one machine inside your building. The only outside connection is to your own Microsoft or Google account for sign-in.
The Phone and the Inbox Can Stay in the Cloud
Local AI is for the confidential, document-heavy work. For answering calls, managing the inbox and chasing leads, our hosted agents are up and running in days with no hardware at all — and plenty of clients run both.
- ☁ Cloud-based AI Receptionist
- ☁ Cloud-based Email Manager
- ☁ Cloud-based Leads Outreach
- 🏢 On-premise Local AI
The Questions Your DPO Asks About GDPR and AI
Most of the hard work in an AI GDPR assessment is about the processor and the transfer. Here is what each looks like for a cloud service and for a machine in your own office.
| The question | Cloud AI service | Local AI (on-premises) |
|---|---|---|
| Who is the processor for the AI step? | The AI provider — appoint, assess, contract, review | Nobody — the model runs on your own machine |
| Is there a restricted transfer? | Often — IDTA or UK Addendum, plus a transfer risk assessment | No — the data never leaves your building |
| Is our data used to train models? | Depends on the plan, the settings and the small print | Never |
| What goes in the Article 30 record? | A new processor and, often, a new transfer | One fewer of each |
| Article 32 security of processing | Their controls, assessed by you | Your network, your access controls, hardware you physically hold |
| Erasure requests | Your copy and theirs | Your copy only |
| Lawful basis, purpose, retention | Yours | Still yours |
What Local AI Settles, and What It Leaves With You
The ICO’s guidance on AI and data protection does not ask whether a tool is “compliant”. It asks the usual questions — purpose, lawful basis, minimisation, security, rights, accountability — and then asks them again for each processor and each transfer you have introduced. That last part is where cloud AI gets expensive to sign off: a new Article 28 contract, a transfer mechanism, a transfer risk assessment, and all of it kept under review.
Local AI removes those items rather than answering them. The model runs on a dedicated machine on your network. Documents, prompts and chat history are stored on it. There is no AI provider processing personal data on your behalf, so there is no processor to appoint for that step. There is no transfer, because nothing leaves the UK or, for that matter, the room. Your record of processing gains one fewer processor and one fewer transfer to describe and keep current.
Security of processing under Article 32 becomes a question about your own network and your own access controls, which is a question you already answer for everything else you hold. Staff sign in with the Microsoft 365 or Google Workspace accounts you already administer, so who can see what is decided with the tools you have.
What stays with you is everything that was always yours. You remain the data controller. Purpose and lawful basis are your call. Your retention policy keeps applying, and because the files never left, a deletion is a deletion. Staff conduct is still your responsibility — the difference is that the private assistant is the easy option, so the habit of pasting client material into a public chatbot ends on its own. We act as a processor only for the support access you grant us, and we will sign a data processing agreement covering exactly that.
We say this plainly because the GDPR compliance AI vendors advertise usually means a tick-box that promises not to train on your data. That is worth having. It is not the same as the data never leaving your building.
What Is Installed, and What the Paperwork Looks Like
The machine, the software on it, the sign-in, the training and the support — and the two documents your advisers will ask for.
No third-party AI processor
The model runs on your own machine, so your documents are never sent to an AI provider. Nothing to appoint, assess or keep under review for the AI step.
No restricted transfers
Your data never leaves the UK. The IDTA, the UK Addendum and a transfer risk assessment simply do not arise for the processing Local AI does.
A shorter Article 30 record
One fewer processor and one fewer transfer to describe, review and keep current — and one less thing to explain if the ICO ever asks.
| Included | Not included |
|---|---|
| A dedicated machine, sized for your team, rented to you (not sold) and installed by us | A cloud subscription — nothing runs on our servers |
| £500 per month for the software and the hardware rental | Buying the hardware — the machine is rented, not sold |
| Private chat, document spaces and custom assistants on that machine | Clinical, legal or financial advice — it drafts, you decide |
| Single sign-on with your Microsoft 365 or Google Workspace | A replacement for your practice, case or CRM system |
| Import of your existing documents, and training for the people using it | Phone answering — see AI Receptionist |
| Software updates, model upgrades and support from the people who installed it | Inbox automation — see Email Manager |
| A data processing agreement covering the support access you grant us | A certificate that says your business is “GDPR compliant” — no such thing exists |
From Sign-Off Blocker to Working Machine
Weeks, not months. Bring the questions early; they are easier to answer before hardware is ordered.
Walk the data flow
A call with you and, ideally, your DPO. We go through where data sits, who signs in, what is backed up and where, and the support access you will grant.
Install inside your network
The machine goes on your premises, single sign-on connects to your Microsoft 365 or Google Workspace, and your documents are imported into spaces — none of it touching an outside service.
Sign the DPA, train the team
The data processing agreement covers our support access. We train the people using it and keep the software and models current.
Where Local AI Is the Wrong Answer
We would rather lose the enquiry than the trust. Three things we tell every prospect before they sign anything.
It is not a compliance certificate
No product can make a business UK GDPR-compliant on its own. Local AI removes the processor and transfer questions for the AI step. Purpose, lawful basis, retention and staff conduct remain yours, and we will not tell you otherwise.
It is slower than the big cloud models
Open-weight models on a single machine are capable for summarising, drafting and answering questions about your own documents. For frontier reasoning on hard, novel problems, the largest cloud models are still ahead. That is the trade.
It is a weeks-long install, not a sign-up
A cloud agent is live in days. Local AI needs the machine specified, delivered, installed on your network and your documents imported. Weeks, not months — but not tomorrow.
Built With the Regulator in Mind
Data never leaves the building
Model, documents and chat history on one machine in your office. The only outside connection is your own sign-in.
Never used for training
Your content is not used to train or improve any model. The models arrive trained and stay that way unless you ask.
One DPA, for one thing
We are a processor only for the support access you grant, and the agreement says so in plain terms.
Honest about the trade
Local models are capable and somewhat slower than the largest cloud services. We say so before you sign anything.
Which Page Answers Your Question
| If your question is… | The short answer | Read more |
|---|---|---|
| What exactly is installed? | One machine: chat, spaces, assistants, support | On-premises AI solution |
| Is this what people mean by private AI? | Yes — private by construction | Private AI |
| Which model runs on it? | An open-weight local LLM, matched to the job | Local LLM |
| We are solicitors | Client files and privilege stay in the office | Local AI for solicitors |
| We are a GP practice | Practice documents stay inside the surgery | Local AI for GP practices |
| We are a dental practice | Patient records stay in the practice | Local AI for dental practices |
| Why on-premises at all? | The case for Local AI, in full | Local AI product page |
GDPR Compliant AI by City and Sector
AI and GDPR Compliance: Common Questions
Is there such a thing as GDPR compliant AI?
Not as a product label. Compliance is a property of how your business uses a tool, not of the tool. What a product can do is make the assessment easier. Local AI keeps personal data on a machine in your office, which removes the processor and transfer questions for the AI step entirely.
Do we need a data processing agreement for AI?
If a provider processes personal data on your behalf, yes — that is an Article 28 contract. With Local AI the model runs on your own machine, so there is no AI processor to contract with. We act as a processor only for the support access you choose to grant us, and we sign a data processing agreement covering it.
Does using AI count as an international transfer?
Cloud AI often does, if the provider processes data outside the UK, which brings in the IDTA or the UK Addendum and a transfer risk assessment. With Local AI your data never leaves the UK — it never leaves your building — so the restricted-transfer questions do not arise for the processing it does.
Do we need a DPIA for AI?
Often, yes, and we would rather you did one. Local AI makes it shorter: the questions about the processor, the transfer mechanism and the training use of your data have plain answers. The questions about purpose, lawful basis, retention and who has access are still yours to answer.
Is our data used to train the model?
No. Your documents and conversations are not used to train or improve any model, ours or anyone else’s. The models arrive trained and stay that way unless you ask us to change them.
What happens when someone asks us to erase their data?
Retention and deletion follow the policy you already have, because the files never left your systems. When you action a deletion, there is no third-party copy of the data to chase.
How much does Local AI cost?
£500 per month for the software and the hardware rental. The dedicated machine is rented to your business, not sold: you never buy the hardware. It is installed in your building and runs the private chat, document spaces and assistants. Local AI is for business customers only.
Bring the Hard Questions Early
Tell us what is blocking AI sign-off in your business. We will walk through the data flow with you and your advisers, and say plainly what Local AI settles and what it does not.
Prefer email? sghaith@businessaiagents.co.uk
