Benchmark · UK · v1.0.0-draft

DPA-Bench

The standard for evaluating AI reasoning on UK data protection law.

UK GDPR, Data Protection Act 2018, PECR, ICO guidancedraft — under legal review

Construction

How this benchmark is built

Every item pairs a realistic prompt with a gold-standard answer grounded in primary authority — statute, regulation, or regulator guidance — plus the failure modes the item is designed to surface (fabricated authority, wrong-jurisdiction transplants, omitted elements, unsound reasoning).

Items are drafted under a documented authoring workflow, authority-checked, and gated behind review by a practising lawyer before any paid use. Versions are immutable; the version you were measured against is named in your report, so results stay comparable over time.

22 of 25 items are held out and never published. The released sample below shows the format and difficulty, not the test.

Registry datav1.0.0-draft

25
Items
22
Held out
6
Practice areas

Difficulty distribution

Foundational4
Applied14
Adversarial7

Released sample · 3 of 25 items

Sample items

dpa-001 · lawful_basisdifficulty 1/3

A UK SaaS company says it relies on 'legitimate interests' to process customer data. What must it actually establish?

Gold standard: The three-part test: (1) a legitimate interest is pursued (purpose test), (2) the processing is necessary for that interest (necessity test — no less intrusive way), and (3) the interest is not overridden by the data subject's interests, rights and freedoms (balancing test), documented in a legitimate interests assessment. Naming the basis without the test is incomplete.

Authority: UK GDPR, Art. 6(1)(f) · ICO legitimate interests guidance — probes: omission, bad reasoning

dpa-006 · marketingdifficulty 2/3

May a UK online retailer email marketing to past customers without fresh consent?

Gold standard: Yes, within the PECR 'soft opt-in': the details were collected in the course of a sale or negotiations for one, the marketing is for the sender's own similar products, and the customer was given a simple free opt-out at collection and in every message. Outside those conditions, consent is required. Answering under UK GDPR alone and skipping PECR is the wrong-framework failure this item probes.

Authority: PECR, Reg. 22 · ICO direct marketing guidance — probes: wrong jurisdiction, omission

dpa-023 · lawful_basisdifficulty 3/3

A UK legal-tech vendor fine-tunes an LLM on client matter files. Frame the core data-protection analysis.

Gold standard: Identify roles first (the vendor is a controller for its own training purpose), then: lawful basis for repurposing (legitimate interests demands the three-part test with a hard look at client and data-subject expectations and privilege/confidentiality overlays), purpose-limitation compatibility under Article 6(4), data-minimisation and anonymisation/pseudonymisation options, DPIA (innovative technology, likely high risk), and the difficulty of honouring rights (erasure from trained weights). ICO guidance on generative AI expects exactly this structure; skipping roles or the repurposing test is the failure mode.

Authority: UK GDPR, Arts. 5(1)(b), 6(1)(f), 6(4), 35 · ICO guidance on AI and data protection / generative AI — probes: omission, bad reasoning

Measure your system against DPA-Bench.

Request an auditMethodology

Citing this benchmark: “DPA-Bench v1.0.0-draft, Bench by BizLegal AI (2026-08-16), bench.bizlegal-ai.com/benchmarks/dpa-bench”.