Responsible technology. Human accountability.

Artificial Intelligence Policy

How UK Bailiffs uses AI to improve accuracy, consistency and service while keeping lawful enforcement, professional judgment and accountability firmly in human hands.

Version 1.2 Effective 9 August 2026 Owner: Compliance Manager Next review by 9 February 2027

Our position is straightforward: AI may support our people, but it does not acquire legal powers, exercise an enforcement agent's statutory authority, replace professional judgment or remove UK Bailiffs' responsibility for an outcome.

1. Purpose and scope

This policy explains how UK Bailiff Services Ltd, trading as UK Bailiffs ("UK Bailiffs", "we", "us" or "our"), governs artificial intelligence, machine learning, generative AI, automated tools and AI-enabled decision support.

It applies to our directors, employees, enforcement agents, contractors and approved suppliers whenever they design, buy, configure or use AI for UK Bailiffs. It covers internal administration and public-facing services, including enforcement, recovery, possession, investigations, security support, client reporting, communications, payments and complaints.

Important: this policy explains our governance approach. It does not expand any enforcement power, override a court order or warrant, alter a contract, or limit anyone's statutory rights. Where law, a court direction, client requirement or binding standard sets a higher requirement, the higher requirement applies.

2. Our principles

Lawful and accountable

UK Bailiffs remains responsible for its work, including work supported by a third-party AI service.

Human controlled

People with the right competence and authority review matters requiring legal judgment, discretion or a significant decision.

Fair and proportionate

We test for unjustified bias, avoid discriminatory proxies and consider the effect on vulnerable people and protected groups.

Transparent and explainable

We provide clear information about material AI use and an understandable explanation where the law or fairness requires one.

Private and secure

We minimise personal data, approve suppliers, control access and apply appropriate retention and transfer safeguards.

Accurate and challengeable

AI output is treated as assistance, not unquestionable fact. Relevant people can raise errors and request human consideration.

3. How we may use AI

Approved AI may assist with tasks such as:

  • receiving, categorising and checking instructions for missing or inconsistent information;
  • summarising correspondence, calls, documents and case histories for a human user;
  • preparing draft letters, notices, reports, inventories and client updates for appropriate checking;
  • calculations, calendar prompts, document comparisons, knowledge retrieval and quality assurance;
  • supporting payment reconciliation and identifying anomalies, while controlled business systems remain the financial record;
  • suggesting operational allocation using legitimate factors such as location, availability, qualification and workload;
  • identifying words or circumstances that may indicate vulnerability, communication difficulty, dispute or risk so a trained person can review them; and
  • describing photographs or extracting information from documents, subject to verification against the original evidence.

The permitted use, data, approval level and monitoring requirements must be recorded in our AI system register before a material use goes live.

4. Decisions AI will not make on its own

AI must not be the sole or final decision-maker where a decision requires the exercise of legal powers, professional judgment or discretion, or may have a legal or similarly significant effect. In particular, AI will not by itself:

  • authorise entry, the taking control or removal of goods, eviction, repossession, use of force or any other statutory or common-law enforcement step;
  • determine that a person owns goods, is liable, is deliberately avoiding payment, lacks vulnerability, can afford a payment plan, or has lost a dispute or complaint;
  • decide whether enforcement should continue where vulnerability, safeguarding, proportionality, insolvency, ownership, identity or legal validity is in issue;
  • make a final decision on recruitment, disciplinary action, termination, certification suitability or agent misconduct;
  • authorise a payment, refund, fee adjustment or change to a person's account outside an approved workflow and required authority; or
  • create, alter or present fabricated correspondence, photographs, audio, body-worn video, signatures, attendance records or other evidence as genuine.

A human review is meaningful only where the reviewer has sufficient information, training, time and authority to question, change or reject the AI output. A rubber-stamp approval is not meaningful human involvement.

5. Personal data, ChatGPT and other approved AI services

We may use ChatGPT and comparable AI models only through approved business or API deployments that meet the non-persistence requirements below. Before approval, we assess and document the provider, purpose, data flow, security, contractual terms, sub-processors, hosting, international transfers, deletion arrangements and ability to support data-subject rights.

Depending on the approved task, the data processed may include instruction and contact details, identifiers, case status, correspondence, documents, images, payment status, accessibility needs and information indicating possible vulnerability. We use only data relevant and reasonably necessary for the recorded purpose. The applicable privacy information identifies the controller, purposes, lawful bases, recipients, retention position and individual rights in more detail.

Approved AI models are processing tools, not UK Bailiffs' official system of record. They do not create or retain the authoritative record of an instruction, personal transaction, payment, enforcement action or decision. Authoritative records, evidence, approvals and accountable human decisions are held separately in UK Bailiffs' controlled case, finance and document systems for the appropriate lawful retention period.

Where necessary and proportionate for accountability, subject access, complaint handling or audit, UK Bailiffs records the minimum relevant input, output, source references, human checks and decision outcome in its controlled systems. We do not retain unnecessary prompt content or duplicate personal data merely because AI was used.

Our non-persistent AI commitment: UK Bailiffs only approves AI model deployments that are technically verified and, where provided by a third party, contractually confirmed so that the model cannot create persistent memory of case content or retrieve that content after the authorised request has ended. Prompt and response content may be handled transiently in working memory only for the time technically necessary to produce the response. It must not be retained as provider-side conversation history or application state, used to train or fine-tune a provider's models, made available for routine human review, or used to build a profile of the person concerned. This transient handling remains processing for the purposes of data-protection law even though the model does not store the content.

ChatGPT or another external model may therefore be used with live case content only where the particular business or API deployment has been technically verified and contractually confirmed to prevent retention of prompt and response content. Saved-chat, memory, training and equivalent storage features must be disabled. If a provider, model, feature or endpoint cannot satisfy and evidence this requirement, it must not be used with personal or case data. We retain proportionate evidence of the technical configuration, verification and applicable contractual terms for each approved deployment.

Limited operational metadata may be retained where necessary to secure and audit the service, such as the time of a request, approved user, model version, token volume and success or failure status. Such metadata must exclude prompt and response content and case identifiers wherever reasonably practicable, be access-controlled and follow a documented retention period.

Staff and contractors must not place live case data in personal, consumer or unapproved AI accounts. We remove or replace identifiers where reasonably practicable, disclose only the minimum data needed, and do not use case data to train or fine-tune any general-purpose or supplier model.

Where we are the controller, we determine the purpose and lawful basis. Where we act for a client, the allocation of controller and processor responsibilities is documented. Special-category and criminal-offence data receive additional protection and are only processed where the required UK GDPR and Data Protection Act 2018 conditions are met.

6. Your rights to access, explanation and human review

Your data-protection rights apply where AI is used. Their precise scope depends on the circumstances and lawful exemptions, but you may ask us to:

What you may request

  • confirm whether we process your personal data using an AI-enabled system;
  • provide access to personal data we control in relevant prompts, outputs, case records and audit information, subject to the rights of others and lawful exemptions;
  • explain, in clear terms, the purpose of the AI, the information used, its role in the process and the safeguards applied;
  • provide meaningful information about the logic, significance and envisaged consequences of solely automated significant processing where the law requires it;
  • correct inaccurate personal data and have relevant downstream records reconsidered;
  • make representations, contest a significant automated decision and obtain human intervention;
  • object to, restrict or request deletion of processing where the relevant legal conditions apply; and
  • complain to UK Bailiffs and, if unresolved, to the Information Commissioner's Office.

We do not ordinarily use solely automated processing to make significant enforcement decisions. If a proposed use could do so, it must not begin until we have identified a lawful basis, completed the required impact assessment, introduced the statutory safeguards and provided appropriate privacy information.

Access rights do not necessarily require disclosure of source code, security information, another person's data or legally privileged material. We will provide the information the law requires in an intelligible and useful form. Requests can be made through our Data Subject Access page or by emailing legal@ukbailiffs.org.

7. Freedom of Information and public-authority requests

UK Bailiffs is a private limited company and is not generally a public authority for the purposes of the Freedom of Information Act 2000 ("FOIA"). However, information we hold on behalf of a council, government body or other public-authority client may be treated as held by that authority for the purposes of FOIA or the Environmental Information Regulations 2004 ("EIR"). Our contractual duties may also require us to assist the authority with information requests.

Where a request relates to information that may be held on behalf of a public authority, we will:

  • identify and preserve relevant official records already held by UK Bailiffs, including relevant audit information, and prevent inappropriate alteration or deletion while the request is considered;
  • send a request received directly by us to the relevant public authority without undue delay and, where appropriate, tell the requester that we have done so;
  • carry out proportionate searches and provide reasonable assistance so the authority can identify, retrieve and understand relevant information;
  • give the authority relevant factual representations about confidentiality, legal privilege, personal data, security and commercial interests, while recognising that the authority is responsible for deciding whether information must be disclosed or withheld; and
  • comply with lawful preservation, search and disclosure instructions from the responsible authority.

FOIA and EIR apply to recorded information already held; they do not normally require information to be created that is not held. Because approved AI models do not persist prompts or responses, the model cannot later retrieve content that ceased to exist when transient processing ended. This does not affect disclosure of any relevant information that was separately adopted into, or is otherwise held within, UK Bailiffs' official systems.

A request for the requester's own personal data is normally handled as a data-protection subject access request rather than an FOI request. We will identify the appropriate route and will not use an incorrect label to deprive anyone of a legal right.

8. Fairness, equality, vulnerability and accessibility

We will not intentionally design or use AI to discriminate unlawfully on grounds protected by the Equality Act 2010. Protected characteristics, health information, postcode, language, disability indicators and other proxy data must not be used to produce an unjustified adverse outcome.

An AI-generated vulnerability or risk flag is a prompt for trained human consideration, not a diagnosis or final conclusion. Absence of a flag does not mean absence of vulnerability. Staff and agents must consider the person's actual circumstances, make reasonable adjustments where required and follow applicable vulnerability, safeguarding and ability-to-pay procedures.

Where reasonably possible, we provide a non-AI route or direct human contact for anyone who cannot use, does not understand or is materially disadvantaged by an AI-enabled channel.

9. Accuracy, evidence and legal quality

AI can produce incomplete, outdated or incorrect material. We apply risk-based checking proportionate to the impact. Names, addresses, identity matches, sums, payments, fees, dates, legal authorities, statutory wording, ownership assertions, vulnerability indicators and instructions affecting enforcement require verification against reliable source material.

Original evidence must be preserved. AI-generated summaries or image descriptions must be traceable to the source and must not be presented as if they were contemporaneous evidence. Material legal content is checked against legislation, court directions, current official guidance or suitably qualified advice before reliance.

10. Security, suppliers and retention

Controls are selected according to risk and may include:

  • approved-tool lists, role-based access, multi-factor authentication and least-privilege permissions;
  • encryption in transit and at rest, secure integration, monitoring and audit logs;
  • data-processing terms, confidentiality duties, sub-processor review and lawful international-transfer safeguards;
  • testing for prompt injection, data leakage, unauthorised tool use, manipulation and unsafe external actions;
  • retention schedules and deletion controls aligned with the purpose, legal claims, enforcement records and client requirements; and
  • incident management, containment, investigation, notification and learning in line with our data-breach procedure.

A supplier's assurance does not remove our accountability. A material model, provider, integration, retention or hosting change triggers reassessment before continued high-impact use.

11. Legal and regulatory framework

There is no single UK Act that replaces all existing duties whenever AI is used. We apply the law to the particular purpose, data and outcome. As at 9 August 2026, the principal framework considered by this policy includes, as applicable and as amended or replaced:

  • the UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025, including accountability, transparency, data minimisation, security, impact assessment, complaints and automated-decision safeguards;
  • the Freedom of Information Act 2000 and Environmental Information Regulations 2004 where we hold information on behalf of, or provide information services to, a public authority;
  • the Privacy and Electronic Communications Regulations 2003 for relevant electronic communications, tracking and marketing;
  • the Equality Act 2010, including non-discrimination and reasonable-adjustment duties;
  • the Digital Markets, Competition and Consumers Act 2024, Consumer Rights Act 2015 and other applicable consumer and competition requirements;
  • the Human Rights Act 1998 and public-law fairness where applicable to the function or instruction;
  • the Copyright, Designs and Patents Act 1988, database rights, confidentiality, trade-secret and other intellectual-property obligations;
  • the Computer Misuse Act 1990 and other applicable criminal, fraud, harassment, communications and cyber-security law;
  • the Tribunals, Courts and Enforcement Act 2007 (including Schedule 12), Taking Control of Goods Regulations 2013, Taking Control of Goods (Fees) Regulations 2014, Certification of Enforcement Agents Regulations 2014, applicable procedural rules, court orders, warrants and Ministry of Justice National Standards; and
  • the Enforcement Conduct Board Standards applicable to our accreditation. These are standards rather than legislation. We also treat the ECB Vulnerability and Ability to Pay Standards published in March 2026, effective January 2027, as an implementation requirement.

This list identifies the principal framework and is not a claim that every law applies to every use case. Other sector, employment, health and safety, safeguarding, surveillance, insolvency, property, contract or jurisdiction-specific requirements are included in the assessment where relevant. Work outside England and Wales follows the law and authorised professional arrangements of the relevant jurisdiction.

12. Governance and impact assessment

The Compliance Manager owns this policy. Senior management retains overall accountability. Each material AI system has a named business owner responsible for purpose, data, controls, testing, monitoring and withdrawal.

Before a new or materially changed AI use is approved, we assess its necessity, proportionality, lawful basis, data sources, accuracy, explainability, equality and vulnerability impact, security, supplier risk, retention, human oversight and means of challenge. A Data Protection Impact Assessment is completed where processing is likely to create high risk, including relevant innovative technology, large-scale sensitive data, systematic monitoring, profiling or significant automated decisions. Other assessments, including legitimate-interest, equality, security and legal assessments, are completed where applicable.

13. How we will keep this policy current

A statement that a policy will "automatically adapt" cannot by itself change systems, contracts or working practices. We use the following controlled update process:

  1. Maintain an AI register. Record each approved system, owner, provider, purpose, data categories, risk level, retention position, integrations and required human control.
  2. Monitor developments. At least quarterly, review legislation, commencement regulations, material judgments and guidance from the ICO, Government, CMA, Ministry of Justice, NCSC and ECB.
  3. Apply immediate triggers. Reassess sooner when there is new law or guidance, a new model or supplier, a material system change, a new use of data, an incident, complaint, audit finding, unexplained performance change or evidence of unfair outcomes.
  4. Assess the gap. Identify affected systems, people, contracts and records; obtain legal or specialist advice where needed; and update DPIAs, legitimate-interest assessments, equality assessments and security reviews.
  5. Control risk while reviewing. Pause, restrict or add human approval to a use where continued operation could be unlawful, unsafe or unfair. Urgent controls do not wait for the next published policy version.
  6. Test before release. Test accuracy, bias, accessibility, security, explainability, record keeping, human intervention and routes to challenge using representative and adverse scenarios.
  7. Approve and implement. Obtain approval from the Compliance Manager and senior management, amend contracts and procedures, configure systems, brief suppliers and train relevant staff and agents.
  8. Publish and evidence. Update the version number, effective date, change record and linked privacy information; retain the superseded version and evidence of approval and testing.
  9. Review performance. Monitor errors, overrides, complaints, incidents, equality and vulnerability outcomes and supplier changes. Conduct a scheduled policy review at least every six months.
Known review triggers already scheduled: publication of the ICO's final post-DUAA automated-decision guidance, currently expected in winter 2026, and implementation of the ECB Vulnerability and Ability to Pay Standards from January 2027.

14. Questions, challenges and complaints

You may ask whether AI materially supported a process concerning you, report an inaccurate output, request a human review or raise a data-protection or service complaint. Raising a concern will not by itself cause adverse treatment.

We investigate in accordance with our Complaints Policy, Privacy Notice and applicable statutory timescales. Data-protection complaints are acknowledged within the period required by law, and we keep complainants appropriately informed.

15. Policy status and version control

This policy takes effect on 9 August 2026 and applies until replaced. References to legislation and standards include amendments, re-enactments and replacements to the extent applicable; however, operational change is implemented through the controlled review process above.

Version: 1.2  |  Owner: Compliance Manager  |  Approved by: Senior Management  |  Scheduled review: by 9 February 2027.

Version 1.2 change record: strengthened the technical verification, contractual confirmation and evidence requirements for non-persistent AI; clarified proportionate internal recording for accountability while avoiding unnecessary prompt duplication; and retained the FOIA/EIR contractor procedure introduced in version 1.1.

Official reference points

Reference links are provided for transparency. Guidance and standards may change and do not replace the legislation itself or case-specific legal advice.

Contact UK Bailiffs

For an AI-related question, access request, correction or human review, contact our Compliance Manager or use the relevant form below.

Email: legal@ukbailiffs.org
Telephone: 0330 133 1818
Post: Compliance Manager, UK Bailiff Services Ltd, 223 Bacup Road, Rossendale, BB4 7PA

UK Bailiff Services Ltd, company number 11337729, trading as UK Bailiffs.