Get to Know Amber
Amber Sivill is a Junior Data Protection Consultant at Data Protection People with a background in law and a strong start in data protection consultancy. Before joining Data Protection People, she spent a year and a half at an outsourced data protection consultancy, progressing from Trainee Data Protection Officer to Data Protection Manager. Her interest in data protection began while studying law, when reading The People vs Tech: How the Internet is Killing Democracy led her to explore how personal data, democracy and technology intersect.
That interest shaped her undergraduate dissertation on the processing of special category data in democratic processes and how effectively UK GDPR is enforced, one of her highest marks and a key part of her First Class Law degree. Amber also holds both the CIPP/E and CIPM qualifications, and has experience across UK, EU and international privacy work, including AI, PECR, security, cookies, international transfers, and frameworks such as HIPAA and the CCPA/CPRA.
Experience
Amber is currently a Junior Data Protection Consultant at Data Protection People, where she supports clients across a wide range of privacy and information governance matters. Before joining Data Protection People, she spent a year and a half at The DPO Centre, where she progressed from Trainee Data Protection Officer to Data Protection Manager. That progression reflects both the quality of her work and the trust she built early in her career.
Her experience covers much of what clients would expect from DPO support in practice, including compliance audits, DPIAs, DSARs, policy and privacy notice drafting, training, advice line support and wider privacy governance work. She also has experience with cookie compliance, international transfers and cross-border privacy issues, alongside knowledge of frameworks such as HIPAA and the CCPA/CPRA.
Amber’s legal background still shapes the way she works. She graduated from the University of Cumbria with First Class Honours in Law, and her dissertation on special category data in democratic processes remains one of the strongest examples of the curiosity and critical thinking she brings to privacy work. Clients value her for being thoughtful, approachable and able to turn complex issues into clear, practical advice.
“I enjoy the side of data protection that helps clients make sense of difficult issues and turn them into something clear, practical and workable.”
Amber Sivill
Junior Data Protection Consultant
Amber's Posts
S2 Ep29: How AI Is Reshaping the DPO Role in 2026
S2 Ep29: How AI Is Reshaping the DPO Role in 2026
Data Protection Made Easy podcast with Caine Glancy and Amber Sivill
Artificial intelligence is changing how Data Protection Officers work.
AI tools can help with research, training, risk assessments and routine administration. However, they can also produce inaccurate advice, encourage confirmation bias and create new governance risks.
In this episode of the Data Protection Made Easy podcast, Caine Glancy and Amber Sivill discuss how AI is affecting DPO workloads and why professional knowledge and meaningful human oversight remain essential.
What Does This Episode Cover?
During the episode, Caine and Amber discuss:
- The increase in AI-generated Subject Access Requests
- How AI is affecting DPO workloads
- The risks of using AI for data protection advice
- How AI could support RoPAs, DPIAs and LIAs
- The importance of checking AI-generated policies
- Confirmation bias in AI responses
- Why human oversight and professional knowledge still matter
How Is AI Affecting Subject Access Requests?
The discussion explored the growing number of Subject Access Requests, or SARs, that appear to have been generated using AI.
These requests can look formal and detailed. However, they may ask for information that does not fall within the normal scope of a SAR.
Amber explained:
“It also fuels a lot of misunderstanding. A lot of the time, you see a request and most of it does not even fall under the scope of what a SAR generally covers.”
Caine also shared that SAR-related cases handled through the DPP Support Desk have increased significantly.
AI may make it easier for people to create requests, complaints and follow-up correspondence. This can place additional pressure on data protection teams, particularly where requests are vague or based on incorrect information.
Can DPOs Rely on AI for Data Protection Advice?
AI can provide a useful starting point. However, it should not replace professional knowledge.
Amber explained:
“You need to have the base knowledge in order to be able to use these systems.”
An experienced practitioner may recognise when an AI response refers to the wrong legislation, misses important context or provides an answer that is too confident.
Someone with less experience may not spot those problems.
Data protection decisions are rarely black and white. The correct answer often depends on the organisation, the processing activity and the people who may be affected.
Could AI Support RoPAs, DPIAs and LIAs?
AI may help DPOs complete some routine or administrative tasks.
For example, it could help pre-populate a Record of Processing Activities, or RoPA, using information about an organisation’s activities and data sharing.
It may also provide a starting point for a Data Protection Impact Assessment, or DPIA, and a Legitimate Interests Assessment, or LIA.
However, organisations must consider what information they enter into an AI system. DPIAs and other assessments may contain sensitive or confidential information.
Amber said:
“There is a limit as to what you can provide the model with in terms of confidentiality and not oversharing any information.”
Any AI-generated assessment must be checked against the organisation’s actual processing, systems and risks.
Why Does Human Oversight Matter?
AI can produce clear and convincing answers even when those answers are incomplete or incorrect.
It may also agree with the direction of a prompt instead of challenging the user’s assumptions. This is known as confirmation bias, which means favouring information that supports an existing view.
Caine explained:
“It is a fantastic tool that will hopefully be able to help in the role as a DPO. But what matters is that you can supplement it with your pre-existing knowledge.”
Amber added:
“The human element needs to be someone overlooking it who actually knows what they are talking about.”
Human oversight must be meaningful. The person reviewing an AI output needs the knowledge and authority to identify problems, challenge the result and make the final decision.
Is an AI-Generated Policy Better Than No Policy?
An AI-generated policy is not useful simply because it exists.
A policy must reflect how the organisation actually works. It must be practical, accurate and followed by staff.
Amber explained:
“If you have a policy in place and it does not align with your business, it is not workable and people are not following it, then there is ultimately not really anything there in place anyway.”
AI may help structure a first draft. However, the final policy should be reviewed by someone who understands the organisation, its legal duties and its operational risks.
What Should DPOs Take Away?
AI can support DPOs, but it should not replace them.
Organisations should:
- Use AI to support work rather than make final decisions
- Check AI outputs against current law and ICO guidance
- Avoid entering unnecessary personal or confidential information
- Keep meaningful human oversight in place
- Document how AI tools are approved, monitored and reviewed
- Make sure policies and assessments reflect real business practices
The DPO role is becoming broader and more connected to technology, governance and organisational risk.
AI creates opportunities to work more efficiently. It also makes professional judgement, scepticism and accountability more important.
Meet Your Hosts
Caine Glancy
Caine is the Data Protection Support Desk Manager at Data Protection People. He works with organisations every day to help them understand and respond to practical data protection challenges.
Amber Sivill
Amber is a Data Protection Consultant at Data Protection People. She supports organisations with data protection compliance, governance and emerging technology risks.
Watch or Listen to the Episode
Watch the full episode on YouTube or listen on Spotify.
Need Support With AI Governance?
If your organisation is adopting AI, Data Protection Made Easy can help you understand the risks, strengthen governance and meet your data protection responsibilities.
How AI Is Reshaping the DPO Role in 2026
By Amber Sivill, Data Protection Consultant and AI Specialist at Data Protection People
Artificial intelligence is not only changing the way organisations handle information, it is changing the way individuals understand, exercise and challenge their individual rights. That shift is now landing firmly on the DPO’s desk. Ahead of this Friday’s podcast episode on how AI is reshaping the DPO role, I wanted to share what I am seeing in practice, and why I think the roles and responsibilities of a DPO are becoming more strategic, visible, and more closely connected to AI governance than ever before.
Subject access requests are changing shape, not just volume
Most DPOs I speak to will recognise the same trend: subject access requests are coming in fast and strong, and the requests themselves are becoming more broad complex. Some of that is the result of greater public awareness of data rights. But it is increasingly clear that data subjects are using AI tools to assist them with drafting more detailed and legally focused requests.
A request that once said, “please send me my data”, may now arrive with references to specific processing activities, legislation, ICO guidance and carefully worded follow-up questions. That does not mean the individual is being difficult. In many cases, they have simply had support from an AI tool to articulate what they are asking for. For organisations, the practical effect is clear: SARs can take longer to assess, scope and respond to, even where the underlying request is perfectly legitimate.
The regulatory position has also moved on. Since February of this year, the Data (Use and Access Act) 2025 has given organisations more room to take a reasonable and proportionate approach to searches, rather than treating every request as requiring an exhaustive search of every system and record. It also allows organisations to “stop-the-clock” whilst waiting for identity verification or clarification where a request is unclear. Whilst those changes provide more flexibility to organisations, they do not remove the need for a robust process or adequate resources to address a request. In my experience, many complaints arise not because an organisation neglected their responsibilities under data protection law, but because expectations were not managed, communication was unclear, or the SAR process did not hold up under pressure.
The workplace risk nobody’s policy covers yet
The SAR challenge is only part of the picture. The other, and often less visible, issue is what is happening inside organisations. Staff are increasingly experimenting with consumer AI tools to save time, summarise information, draft communications and sense-check their work. That behaviour is understandable, particularly where approved tools are not available, but it creates real data protection risk when there are no clear rules around what can and cannot be shared.
In practical terms, this might mean someone pasting a client email thread into a personal AI account to help draft a reply. It might mean uploading a contract, pricing document or HR note to create a quick summary. In the moment, that may feel like a harmless productivity shortcut. From a data protection perspective, however, personal data and confidential business information may have left the organisation’s control, with little or no record of what was shared, where it went, or how it may be used afterwards.
This is where policy, training and governance need to catch up with day-to-day behaviour. If an organisation has no approved AI tools, no written position on staff use, and no practical examples of what is and is not acceptable, employees will make their own judgement calls. That is not just a training gap. It is a governance gap, and it is exactly the kind of issue a DPO should be helping the organisation to identify and close.
Where AI is actually helping, not just complicating things
It would be too simplistic to present AI only as a risk. Used properly, it can also support better data protection practice. The organisations making the strongest progress are not necessarily the ones banning AI outright. They are the ones setting sensible boundaries, choosing appropriate tools, and making sure human oversight remains built into the process.
For example, AI-assisted triage can be genuinely useful in SAR handling. It can help identify likely duplicate documents, flag material that may contain third-party data, and support the first review of large data sets. It can also help organisations spot patterns across complaints, requests and internal queries that may point to a wider process issue. Used carefully, those capabilities can give DPOs more time to focus on judgement, accountability and risk, rather than manual administration.
The key point is that AI should not be treated as a shortcut around governance. It should be assessed in the same practical way as any other tool or processor: what data does it use, where does that data go, what controls are in place, and what role does human review play in the final decision?
What this means for your organisation
None of this is a reason to panic. It is a reason to take stock. If SARs are becoming harder to scope, if staff are using AI tools without clear guidance, or if your organisation does not have the internal capacity to keep pace with the rate of change, it may be time to look at whether your current data protection arrangements are still fit for purpose. An experienced outsourced DPO can bring both the day-to-day capacity and the AI-specific knowledge needed to turn uncertainty into a practical, proportionate plan.
We will be exploring this in more detail on this Friday’s episode of the Data Protection Made Easy podcast, including what we are seeing across client organisations and what a sensible, usable AI policy looks like in practice.
What BMW’s ChatGPT Configurator Tells Us About Data Protection Risk
AI in the Showroom: What BMW’s ChatGPT Configurator Tells Us About Data Protection Risk
A Data Protection Officer’s perspective on AI, automotive retail and accountable risk management
BMW’s decision to make its vehicle configurator available through ChatGPT shows how quickly generative AI is moving from experimentation into customer-facing services.
A customer can describe the vehicle they need in ordinary language. The AI-assisted tool can then interpret those requirements and direct the customer towards suitable models, specifications or available stock.
That may improve the customer journey. It may also create material data protection risk if the system is deployed without proper governance.
The question is not whether AI should be used. It is whether the organisation can show that it understands the processing, has assessed the risks to individuals and has put proportionate controls in place.
Conversational AI Is Entering the Vehicle Market
BMW is not operating in isolation. Mercedes-Benz has trialled ChatGPT functionality within its MBUX voice assistant using Azure OpenAI Service. The stated aim was to support more natural dialogue, follow-up questions and broader information retrieval.
Volkswagen has also integrated ChatGPT into its IDA voice assistant through Cerence Chat Pro. Volkswagen has stated that ChatGPT does not gain access to vehicle information and that relevant queries are handled through an automotive-grade integration layer.
The use cases are not identical. BMW’s example centres on retail configuration and product recommendation. Mercedes-Benz and Volkswagen have focused more on in-car assistance, voice-enabled controls and information retrieval.
However, the underlying data protection issues are closely aligned. They include natural language input, personalisation, inferred preferences, third-party AI infrastructure, transparency, security, accuracy and accountability.
Why Does This Matter Under UK Data Protection Law?
The UK GDPR and the Data Protection Act 2018 do not prohibit the use of AI. They do require personal data to be processed lawfully, fairly and transparently. Organisations must also follow the principles of collecting only necessary data, keeping information accurate, protecting it securely and being able to demonstrate compliance.
The ICO’s guidance on AI and data protection applies established data protection principles to AI systems. It places strong emphasis on governance, fairness, transparency and Data Protection Impact Assessments.
A Data Protection Impact Assessment, or DPIA, is a structured process for identifying and reducing risks to people’s rights before high-risk processing begins.
The ICO’s AI and data protection risk toolkit also gives organisations a practical structure for identifying and reducing risks created by their own AI systems.
The European Data Protection Board’s opinion on AI models is relevant too. It considers legitimate interests, anonymisation and the use of personal data during the development and deployment of AI models.
For an AI car configurator, the critical issue is not simply the presence of a chatbot. It is the processing context.
- What information is collected?
- How are customer prompts interpreted?
- Is the information combined with account, location, finance, dealership or stock data?
- Could the output influence a customer’s purchasing decision?
- Has the customer received a meaningful explanation of what is happening?
What Are the Core Data Protection Risks?
1. Lawfulness, Fairness and Reasonable Expectations
A customer may think they are only asking for a practical recommendation.
“I need an SUV with room for three children, low running costs and enough boot space for a wheelchair.”
That prompt may reveal family composition, mobility needs, financial priorities and lifestyle information. Some of that information may be sensitive in context, even if the organisation did not ask for it directly.
Fairness requires more than identifying a lawful basis. Organisations should assess whether the processing is within the customer’s reasonable expectations. They should also consider whether the system could influence customers in unexpected ways or have a disproportionate effect on vulnerable people.
2. Transparency and Explainability
Conversational tools can feel informal, but they may sit on top of complex processing chains.
Customers should receive clear information about:
- Whether they are interacting with an AI system
- What personal data is being used
- Whether their prompts are retained
- Whether the information is used to improve the service
- Which third parties are involved
- How recommendations are produced at a meaningful level
The ICO’s work on transparency and explaining AI-assisted decisions is especially relevant where an output may affect a person’s choices.
3. Accuracy and Inappropriate Reliance
Generative AI can produce confident but inaccurate outputs. This is often called an AI hallucination.
In a car configurator, the system could misstate a model’s availability, running costs, environmental performance, finance options, safety features or suitability for a particular use.
The accuracy principle still applies. Grounding the system in a controlled and verified product knowledge base can reduce the risk. If it relies on broader or uncontrolled content, the risk changes.
Organisations should not present generative outputs as authoritative unless they have been appropriately limited, tested and monitored.
4. Collecting Only Necessary Data
Natural language systems can encourage people to disclose more information than is needed.
A well-designed configurator should not invite customers to provide unnecessary personal data. Clear prompt design, input filters, warnings shown at the right time and carefully chosen examples can help reduce that risk.
Organisations must also be able to justify how long conversational logs are kept. They should understand whether those logs are linked to customer accounts, used for analytics, used to improve the service or used during model development.
5. Supplier and Data-Flow Accountability
Automotive AI systems may involve a vehicle manufacturer, dealership network, cloud provider, AI model provider, voice technology provider, analytics supplier and finance or insurance partners.
A controller decides why and how personal data is used. A processor handles personal data on the controller’s behalf. These roles should be clearly analysed, documented and reflected in contracts and governance records.
The organisation deploying the service must understand:
- Where personal data flows
- Which additional suppliers are involved
- Whether international transfers take place
- What security measures apply
- Whether customer data may be used to train or improve AI models
A supplier’s reputation or a high-level assurance statement is not enough.
6. Profiling, Automated Decisions and Consumer Vulnerability
Profiling means using personal data to evaluate or predict aspects of a person, such as their preferences, behaviour or financial position.
A configurator may not make a decision with a legal or similarly significant effect on its own. The risk increases if it profiles customers, ranks products by inferred affordability, directs people towards finance options or personalises offers in a way that materially influences their choices.
Organisations should assess what the system actually does rather than relying on the marketing label attached to it. If the system evaluates personal aspects of an individual and produces recommendations that significantly affect them, further safeguards and an assessment of automated decision-making rules may be required.
What Does Good AI Governance Look Like?
A conversational AI configurator should be treated as an AI-enabled processing activity that requires structured governance.
Before launch, I would expect to see controls such as:
- A Data Protection Impact Assessment: Cover the AI lifecycle, user prompts, model outputs, third-party processing, international transfers, retention, people’s rights and risks to vulnerable customers.
- A documented lawful basis: Complete a legitimate interests assessment where the organisation relies on legitimate interests. This assessment checks whether the processing is necessary and balanced against people’s rights.
- Clear customer information: Explain the AI interaction, how information is used, how long it is kept and how a person can ask for help.
- Prompt and output controls: Reduce unnecessary collection of personal data and limit inaccurate or unsupported answers.
- Human oversight: Provide escalation where recommendations relate to finance, safety, accessibility needs or other higher-risk matters.
- Verified knowledge sources: Base recommendations on controlled manufacturer data rather than uncontrolled online content.
- Testing and monitoring: Check accuracy, bias, security, inappropriate personalisation and model drift, which means the system’s performance changing over time.
- Supplier checks: Review contracts, security assurances, additional suppliers, audit rights and international data transfers.
- Retention and deletion controls: Set clear rules for prompts, logs, analytics information and any data used to improve the system.
- Incident response plans: Prepare for data leakage, misuse, inaccurate recommendations and security incidents.
These are not tick-box activities. They provide the evidence needed to demonstrate accountability.
Innovation Is Not the Risk. Unmanaged Deployment Is.
There is nothing inherently unlawful about using generative AI to support vehicle configuration, product discovery or in-car assistance.
Used well, conversational AI can improve accessibility, reduce friction and help customers navigate complex choices.
The answer is not to resist innovation. It is to support innovation with governance that is practical, evidenced and capable of being tested.
Organisations should maintain a live risk assessment, test the system with realistic prompts, scrutinise supplier claims, monitor outputs and give customers clear information and meaningful control.
BMW’s ChatGPT configurator is more than a digital sales channel. It is a reminder that AI risk management sits at the intersection of data protection, consumer trust, product governance and operational resilience.
For Data Protection Officers, or DPOs, the objective is not to block AI. It is to make sure AI is explainable, fair, proportionate and accountable.
Frequently Asked Questions
What Is BMW’s ChatGPT Vehicle Configurator?
BMW has made its vehicle configurator available through a plugin in ChatGPT. Customers can describe their requirements using text or voice and receive suggestions for suitable models and configurations based on BMW’s configurator data.
Why Could an AI Car Configurator Create Data Protection Risk?
A customer’s prompts may reveal personal details about their family, accessibility needs, budget or lifestyle. The service may also involve several suppliers, complex data flows and recommendations that influence purchasing decisions.
Does UK Data Protection Law Prevent Organisations From Using AI?
No. Organisations can use AI, but any use of personal data must be lawful, fair, transparent, accurate, secure and accountable.
What Should an Organisation Do Before Launching Customer-Facing AI?
It should understand what data the system uses, document its lawful basis, assess the risks, give people clear information, review suppliers, test outputs and provide appropriate human oversight. A Data Protection Impact Assessment may be required where the processing is likely to create a high risk to people.
How Data Protection Made Easy Can Help
Data Protection People supports organisations that want to use data, technology and AI responsibly while meeting their duties under UK GDPR and related law.
Through Data Protection Made Easy, organisations can access practical data protection advice, support for ad-hoc queries, policy and governance work, training, supplier assurance and risk-based reviews.
Where work crosses into wider security assurance, organisations may also need support with information security management, ISO 27001 readiness, PCI DSS considerations or Cyber Essentials certification. Not every framework will be relevant to every AI project.
The principle remains the same. Effective AI governance depends on understanding the data, the technology, the suppliers and the risks, then putting controls in place that can be demonstrated.
Sources
- BMW Group: BMW launches vehicle configurator as a dialogue-based plugin in OpenAI’s ChatGPT
- ICO: Guidance on AI and data protection
- ICO: AI and data protection risk toolkit
- European Data Protection Board: Opinion on AI models