UK GDPR and LLMs: a checklist for hosting open models

· 2 min read · kvrun team

If prompts sent to your model can contain personal data, and they almost always can, running an LLM is processing under UK GDPR and the Data Protection Act 2018. This checklist covers what to settle before you put an open model into production in the UK.

The checklist

  1. Decide the roles. You are normally the controller. Your inference provider is normally a processor and needs an Article 28 contract that limits it to your instructions.
  2. Pick a lawful basis for each purpose: answering users, logging, evaluation and fine-tuning may need different ones.
  3. Run a DPIA. The ICO expects a data protection impact assessment for most AI processing that is likely to be high risk. Do it before launch, not after.
  4. Map the data flows, including the ones people forget: KV cache offload, request logs, evaluation sets, fine-tuning datasets and model artifacts.
  5. Keep it in the UK or cover the transfer. Processing abroad is a restricted transfer that needs adequacy or safeguards such as the IDTA. UK-based inference avoids the question.
  6. Secure it (Article 32). Encryption, tenant isolation, access control and logging, applied to cached context as well as storage.
  7. Set retention. Define how long prompts, logs and caches live, and make the system enforce it.
  8. Make erasure real (Article 17). You need to remove a person's data from logs, caches and datasets, and show that you did.
  9. Mind fine-tuning. Data used to train a model can influence its outputs. Minimise, pseudonymise, and keep the dataset tied to one model.
  10. Keep records (Article 30) of processing, and evidence that the controls above operate.

Where inference infrastructure helps or hurts

RequirementTypical shared APIGoverned, UK-based inference
ResidencyOften global by defaultUK compute and storage
IsolationShared hardware and cachesDedicated GPU, per-tenant keys
ErasureProvider retention policyKey destruction with a certificate
EvidenceQuestionnaire answersExportable audit log mapped to controls
Training on your dataContract termsYour data trains only your model

A note on the EU AI Act

UK organisations that place AI systems on the EU market, or whose outputs are used in the EU, may also fall under the EU AI Act. It adds documentation, evaluation and oversight duties on top of data protection. kvrun records an evaluation for every fine-tune, mapped to the relevant articles, so that evidence exists from the start.

Related: UK-based AI inference and KV cache security.

This article is general information, not legal advice. Take advice on your own obligations.