- Does AI compliance actually apply to individuals and very small organisations?
- Data protection law applies regardless of size, so if you process personal data with an AI tool you carry the same duties as a large organisation — lawful basis, transparency, security and a DPIA for higher-risk uses. What scales with size is the paperwork, not the duty. A two-page policy, a tool list and an incident log are usually proportionate for a sole trader or a small charity.
- What is the smallest set of documents I should have?
- An AI use policy, a list of approved tools with the data each may touch, and an incident log. Add a DPIA for any use involving personal data, and a risk-register entry if you have a board or trustees. All of those are downloadable from this page.
- Do I need a DPIA before using an AI assistant?
- You need one where the processing is likely to result in a high risk to people — which includes large-scale or systematic use of personal data, decisions with real effects on individuals, and processing data about children or vulnerable people. For general drafting with no personal data, a note in your policy explaining why no DPIA was needed is usually enough. Record the reasoning either way.
- Are free AI tools acceptable for charity work?
- They can be, provided the policy says what may and may not be entered into them and somebody checks the output. The risk is rarely the price — it is the volunteer who pastes a beneficiary's details into a consumer tool because nobody told them not to.
- Do these templates make us compliant?
- No template can. They give you the structure and the evidence trail; the compliance comes from the decisions you record in them and from actually following the policy. If your circumstances are complex, take professional advice — these are practical starting points, not legal advice.
Written by Andy Wake, Founder and Managing Director of Automated Governance Systems Ltd. Practical guidance, not legal advice — take professional advice where your circumstances are complex.