BridgeLayer Back to the site
← Back to the site

Illustrative example. Fictional organisation.

The full illustrative GDPR and AI action plan

XYZ Recruitment Ltd, a fictional 14 person agency. Version 1.0, 30 July 2026.

Real plans are built from your operations, so no two are alike. The shape is always this: findings in plain English, why each one matters, a priority, a named owner and a target date. Nothing below describes a real business.

1. Business profile

A 14-person recruitment agency placing permanent candidates with UK employers. Holds candidate CVs, client contacts and employee records across a cloud applicant tracking system, shared drives and email. Runs its own email marketing to a list built over six years. Consultants use AI tools informally to speed up shortlisting and drafting.

2. Overall risk position

Moderate operational risk. XYZ Recruitment Ltd is a well-run agency with careful people in it. The findings below are typical of a business that has grown faster than the documents written for it. Three would become difficult quickly under scrutiny from a candidate, a client procurement team or the regulator. None require a large project to address.

3. Key findings

All findings, ordered by priority.
Finding Why it matters Priority Owner Target
Marketing list is not categorised by recipient typeDifferent direct-marketing rules apply to corporate subscribers and to individual subscribers such as sole traders and unincorporated partnerships. Without categorisation the team cannot demonstrate which approach applies to which contacts, or evidence it if asked.HighMarketing leadWeek 2
Candidate CVs pasted into consumer AI toolsPersonal data leaves controlled systems with no record of where it went, what the tool retains, or whether the candidate would expect it.HighDirectorsWeek 1
Privacy notice describes an earlier version of the businessThe notice omits tools and activities now in daily use, so it no longer describes what actually happens to candidate data.HighOperations leadWeek 3
No named owner for the 72-hour breach decisionA decision with a statutory deadline needs an owner appointed before the day it is needed.MediumDirectorsWeek 2
Processing record incomplete for higher-risk activityDocumentation expectations scale with the nature of the processing. Candidate screening sits at the end where records matter most.MediumOperations leadWeek 3
Subject access requests handled ad hocRequests are answered by whoever sees them first, with no log and no record that the deadline was met.MediumOperations leadWeek 4
Vendor terms not reviewed for processor obligationsClient procurement reviews routinely ask for this, and the answer is currently an assumption rather than a document.MediumOperations leadWeek 4
ICO data protection fee position not documentedThe registration position has never been assessed or recorded, so nobody can confirm it if a client asks.MediumDirectorsWeek 2
Candidate data retained without a stated periodOld records accumulate in shared drives, increasing what would be exposed by any single incident.LowOperations leadMonth 2
No AI-risk screening before adopting a new toolNew tools arrive through individual consultants rather than a decision, so nobody assesses them before candidate data reaches them.LowDirectorsMonth 2
Staff have had no data-protection refresherProcesses only work if the people running them know they exist.LowOperations leadMonth 3

4. Thirty-day action sequence

  1. Week 1: circulate the one-page workplace AI rules. Approved tools, what may be entered, what never may, and who to ask when it is not obvious.
  2. Week 2: categorise the marketing list by recipient type and source, document the position for each group, and suppress or remove contacts that cannot lawfully be used.
  3. Week 2: name the owner for breach decisions and put the escalation route on one page. Document the ICO fee position.
  4. Week 3: run a single working session to build the processing record, focused on regular and higher-risk activity.
  5. Week 3: update the privacy notice so it describes the business as it operates today.
  6. Week 4: walk one subject access request and one breach scenario through as a dry run, and fix whatever the dry run exposes.

5. One-page workplace AI policy (preview)

6. Where specialist legal advice is recommended

Two items sit at the boundary of legal interpretation rather than operational implementation: the retention position for candidate records tied to an existing client contract, and one clause in a client's data-processing agreement. We have organised the facts for both and recommend that XYZ Recruitment Ltd obtains advice from an appropriately qualified solicitor. We are happy to prepare the brief.

XYZ Recruitment Ltd is a fictional organisation created solely to demonstrate the format of a BridgeLayer action plan. It is not a client, has never been a client, and any resemblance to a real business is coincidental. Findings, owners, dates and the legal-boundary examples above are illustrative. Real plans are built from your operations after a review and remain operational documents. They are not legal advice and not a compliance determination.

← Back to the site