Compliance
NVIDIA TensorRT-LLM in United Kingdom
Structured issue-spotting for deploying NVIDIA TensorRT-LLM in United Kingdom, read against the rules for that jurisdiction.
- Source
- Rules engine over a generic brief — no anchored quote on this page
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01What this reading assumes
- Jurisdiction
- United Kingdom
- Principal framework
- UK GDPR, as retained and amended, together with the Data Protection Act 2018. The core duties are unchanged in shape — lawful basis, transparency, purpose limitation, security, processor contracts, international transfers — but the automated decision-making regime now sits in Articles 22A to 22D rather than Article 22. Article 22A defines a decision as based solely on automated processing where there is no meaningful human involvement, and a significant decision as one producing a legal or similarly significant effect. Whether human involvement is meaningful must be considered in light of the extent to which the decision is reached by profiling.
- Delivery assessed
- Self-hosted
- Data leaves the network
- no
- Vendor home jurisdiction
- United States
- Verified vendor positions
- none — every vendor position below is a question, not an assurance
- Rules evaluated
- 31
- Rules fired
- 11
Assumptions about use
- An internal deployment used by employees, not a public-facing product.
- A person reads the output before acting on it — but that is not recorded, so the engine reports it as a gap rather than assuming it.
- No significant automated decision is taken about a person by the system alone.
02Issues to work through
Cross Cutting
Self-hosting moves the security obligation to you
Keeping data on your own hardware answers the transfer question and creates an operations question. Patching, backups, key management, monitoring and incident response are now yours, and an unpatched inference server on the office network is a worse outcome than a well-run vendor.
- Required checks
- Name the person responsible for patching each component, and the cadence.
- Confirm backups exist, are encrypted, and have been restored at least once.
- Confirm there is an incident response path that includes this system.
- Technical controls
- Encrypt at rest and in transit, including between the application and the inference server.
- Centralise authentication through the existing identity provider rather than local accounts.
- Keep an audit log of who queried what, and protect it from the people it records.
- Subscribe to security advisories for each component and track upgrade lag.
Being able to reconstruct a decision months later
The question that arrives after a complaint is what the system was shown and what it produced on a particular day. Models change, prompts change, and indexes are rebuilt, so the answer has to be recorded at the time. Without it, the only available response is that the output cannot be reproduced.
- Required checks
- Decide what is recorded per interaction: model and version, prompt template version, retrieved document ids, output, reviewer and outcome.
- Set how long those records are kept, balanced against the retention duties that also apply to them.
- Vendor questions
- Does the vendor pin model versions, and how much notice is given before a model is retired or changed?
- Technical controls
- Version prompt templates in source control and log the version used.
- Log the model identifier and version returned by the provider, not the one you requested.
Confidentiality duties bind independently of data protection law
Material can be entirely free of personal data and still be the material a contract stops you disclosing. Client retainers, non-disclosure agreements, supplier contracts and common-law duties are the usual sources, and several of them require consent before a third party processes the material at all — which a model API call is.
- Required checks
- Review the confidentiality clauses in the contracts covering the material going into the system.
- Identify any contract requiring notice or consent before a subcontractor processes the material.
- Decide whether the deployment needs a confidentiality carve-out negotiated into new contracts.
- Vendor questions
- Will the vendor accept a confidentiality undertaking beyond its standard terms?
- Which staff at the vendor can access customer content, under what controls?
- Technical controls
- Segregate the most sensitive corpora into an index that the general assistant cannot reach.
Human review required — take this to your counsel
We were not told whether a person reviews the output
Where output influences a decision about a person, the reviewer has to be able to disagree with it. That needs three things a rubber-stamp review lacks: enough information to judge, enough time to judge, and an override that is used often enough to be real. Design it before the volume makes it impossible.
- Required checks
- Name the role that reviews the output and what they see when they do.
- Decide what evidence is retained about each review, so the practice can be shown to exist.
- Set a threshold below which the system must not act without review.
- Vendor questions
- Does the product expose the retrieved context and the confidence behind a suggestion, or only the answer?
- Technical controls
- Show the reviewer the retrieved sources next to the suggestion, not the suggestion alone.
- Record the reviewer’s decision, including overrides, as part of the audit trail.
Human review required — take this to your counsel
An AI deployment creates new copies of the data
Vector indexes, prompt logs, completion caches, evaluation datasets, fine-tuning checkpoints and backups are all copies of the source material in places the existing retention schedule does not mention. Deletion requests are the moment this is discovered, because deleting the source document does not delete its embedding.
- Required checks
- List every store the deployment creates and add each to the retention schedule.
- Establish how a deletion request propagates to the index, the caches and the logs.
- Establish how long backups keep material that has been deleted from the live system.
- Vendor questions
- What does the vendor retain, where, and for how long after we delete our copy?
- Technical controls
- Store the source document id with every embedding so deletion can cascade.
- Set time-to-live on prompt and completion logs rather than relying on manual cleanup.
Who can reach the model, the index and the weights
A self-hosted stack has three access surfaces that are easy to leave open: the inference endpoint, the vector index, and the weights on disk. Retrieval also carries an authorisation problem an ordinary application does not have — the index must not return a document to someone who could not open it in the source system.
- Required checks
- Confirm the inference endpoint is not reachable from outside the network and requires authentication.
- Confirm retrieval filters by the requesting user’s permissions, not only by relevance.
- Confirm who can read the model files and the index volume at the operating-system level.
- Technical controls
- Bind the inference server to a private interface and put an authenticating proxy in front of it.
- Carry document-level access control into the index and enforce it at query time.
- Encrypt the volume holding the weights and the index, and restrict it to the service account.
- Rotate API keys and keep them out of client-side code and container images.
What ends up in a prompt, and where it goes next
Even with inference inside the network, prompts and retrieved context accumulate in logs, traces and caches, and system prompts can often be extracted from the output. The leak path is internal rather than external, but it is still a copy of the source material in a new place.
- Required checks
- Write down which categories of information may be entered into a prompt, and tell people.
- Establish what the system prompt contains and whether disclosing it would matter.
- Establish which shadow tools staff are already using; the policy has to name the permitted ones.
- Vendor questions
- Are prompts and completions retained, for how long, and can retention be set to zero?
- Are prompts used for abuse monitoring, and if so who can read them and for how long?
- Technical controls
- Redact or block high-risk patterns before the prompt leaves the application.
- Keep prompt and completion logs out of general-purpose observability tools.
- Set an explicit retention period on prompt logs and enforce it.
United Kingdom
Articles 22A to 22D replaced Article 22 on 5 February 2026
Article 22A defines a decision as based solely on automated processing where there is no meaningful human involvement, and a significant decision as one producing a legal effect or a similarly significant effect for the data subject; whether human involvement is meaningful must be considered in light of how far the decision is reached by profiling. Articles 22B and 22C then set the restrictions and the safeguards. Anything keyed to Article 22 is citing a provision that no longer exists.
- Required checks
- Re-test the deployment against the Article 22A definitions rather than the old Article 22 wording.
- Be honest about whether the human step is meaningful involvement or a formality.
- Update policies, DPIAs and vendor questionnaires that still reference Article 22.
- Vendor questions
- Does the product support a human review step that gives the reviewer the basis for the output?
- Technical controls
- Record the reviewer, what they saw and what they decided, so meaningful involvement can be evidenced.
Human review required — take this to your counsel
ICO AI guidance: sound on principles, stale on mechanics
The Data (Use and Access) Act 2025 (Commencement No. 4) Regulations 2026 require the Information Commissioner to prepare a code of practice on good practice in processing personal data for developing and using artificial intelligence and for automated decision-making. The ICO’s existing Guidance on AI and Data Protection covers accountability and governance, transparency, lawfulness, accuracy, and fairness across the AI lifecycle; it was updated on 15 March 2023 and predates the Act, so use it for the reasoning rather than for the current wording of the automated decision-making rules.
- Required checks
- Work through the ICO risk toolkit and keep the output as part of the accountability record.
- Note the pending statutory code as a watch item.
A lawful basis for the AI processing, under the amended UK regime
The UK GDPR and the Data Protection Act 2018 still require a lawful basis and purpose limitation, but both were substantially amended by the Data (Use and Access) Act 2025, whose main data protection tranche commenced on 5 February 2026. Guidance and internal policies written before then need re-reading rather than re-using.
- Required checks
- Identify the basis for the AI processing specifically, and record it.
- Check any policy or DPIA template you are reusing against the amended text.
No UK AI statute, which is not the same as no obligations
A title search of UK Public General Acts returns no result for artificial intelligence, and government policy remains the pro-innovation approach in which existing regulators apply cross-sectoral principles within their remits. The duties on a UK deployment therefore come from data protection law, sector regulation, equality law and employment law — and from the statutory ICO code once it is made.
- Required checks
- List the regulators that already supervise your sector and check what each has said about AI.
- Do not treat the absence of an AI Act as an absence of a compliance workstream.
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
03What this reading does not know
- Whether any of the data falls into a special or sensitive category.
- Whether any material is covered by legal professional privilege.
- Whether a person reviews the output before it is acted on.
04Instruments these issues point at
- guidanceUK AI White PaperThe government policy paper setting out a framework in which existing regulators apply cross-sectoral principles within their remits, rather than a new statute or AI regulator. It remains the stated approach: no UK Public General Act carries artificial intelligence in its title.
- statuteDPA 2018The domestic statute sitting alongside the UK GDPR. Carries the general processing regime, exemptions, law enforcement and intelligence services parts, and the Information Commissioner’s functions and enforcement powers. Provisions replacing the Commissioner with an Information Commission are on the statute book but not commenced.
- statuteDUAA 2025The Act that reshaped UK data protection. Part 5 covers data protection and privacy; section 80 substituted Articles 22A to 22D of the UK GDPR for Article 22. Commencement is staged and incomplete — a number of sections, including those abolishing the office of Information Commissioner, are not in force.
- guidanceICO AI GuidanceThe ICO’s principal AI guidance, covering accountability and governance, lawfulness, fairness across the AI lifecycle, transparency, security, and individual rights, with an AI and data protection risk toolkit. The page carries a notice that the guidance is under review because of changes made by the Data (Use and Access) Act.
- regulationICO AI Code Regulations 2026Statutory instrument requiring the Information Commissioner to prepare a code of practice on artificial intelligence and automated decision-making, using powers inserted into the Data Protection Act 2018 by the Data (Use and Access) Act 2025. It creates no AI regulator and imposes no direct duty on a deployer; the duties will come from the code.
- statuteUK GDPRThe retained EU regulation as amended for the UK. Automated decision-making now sits in Chapter III Section 4A: Article 22A defines a decision based solely on automated processing as one taken without meaningful human involvement, and a significant decision as one with a legal or similarly significant effect, with profiling expressly relevant to the assessment.
05Vendor documents being watched
- Data processing agreementhttps://www.nvidia.com/en-us/agreements/data-processing-addendum/nvidia-cloud-services-data-processing-addendum/not yet fetched
- Privacy policyhttps://www.nvidia.com/en-us/about-nvidia/privacy-policy/not yet fetched
- Security pagehttps://www.nvidia.com/privacy-center/not yet fetched
- Terms of servicehttps://developer.nvidia.com/legal/termsnot yet fetched
06Ask about your own deployment
This page reads the rules against a generic organisation. Your size, industry, data and existing contracts change which of these issues matter and which fall away.