AI and GDPR for UK Businesses: 7 Checks Before Your Team Uses AI Tools
Practical guidance for UK SMEs using AI tools
AI tools are already finding their way into everyday business. Employees are using them to summarise documents, draft emails, analyse information, take meeting notes and speed up routine administration.
The productivity benefits can be significant. But there is an important question every organisation should answer first:
What happens to the information entered into the AI tool?
If that information includes customer details, employee records or anything else that identifies a person, UK GDPR may apply. Using a well-known AI platform does not transfer your organisation’s data protection responsibilities to the provider.
The good news is that responsible AI use does not have to begin with a large compliance project. It begins with knowing which tools are in use, understanding what data they handle and setting sensible boundaries.
Here are seven checks every UK business should make before allowing AI tools into everyday workflows.
1. Be clear about what the AI tool is being used for
Before approving an AI product, define the business purpose it will serve.
“We want to use AI” is not a purpose. “We want to create first drafts of marketing copy” or “We want to summarise internal meeting notes using an approved tool within our managed Microsoft 365 environment.” is much clearer.
A defined use case makes it easier to decide:
- what information the tool needs;
- whether personal or sensitive data will be involved;
- who should have access;
- how its output will be checked; and
- whether a less intrusive option could achieve the same result.
Start with a limited, low-risk use case. Review the outcome before expanding access or allowing the tool to process more sensitive information.
2. Control what employees can enter
The most immediate risk comes from the prompt box.
An employee may paste in a customer email, contract, support ticket, spreadsheet or set of meeting notes to save time. That material could contain names, contact details, financial information, health information, commercially sensitive data or login credentials.
Your policy should make clear that staff must not enter confidential or personal information into an AI tool unless the tool and that specific use have been formally approved.
Where possible:
- remove names and other identifying details;
- use fictional or anonymised examples;
- enter only the minimum information required;
- never submit passwords, authentication codes or security credentials; and
- provide a clear route for employees to ask before using uncertain data.
Simply removing a person’s name may not be enough. If the remaining details can still identify them, the information may still be personal data.
3. Check the provider, not just the product features
An attractive demonstration tells you what an AI tool can do. It does not necessarily tell you how your business information will be handled.
Before adoption, check the provider’s current contractual and technical information. Questions should include:
- Will prompts, uploaded files or outputs be retained?
- Can business data be used to train or improve the provider’s models?
- Where will the data be stored and processed?
- Are international data transfers involved?
- Who are the provider’s subprocessors?
- What access controls, encryption and audit records are available?
- Can information be deleted in line with your retention policy?
- What happens to the data when the subscription ends?
- Will the provider notify you of a security incident or material change?
Free consumer accounts and business or enterprise services may offer very different contractual protections and administrative controls. Do not assume that settings or assurances for one version apply to another.
The ICO also stresses the importance of understanding whether each organisation is acting as a controller, processor or joint controller. The wording in a contract is relevant, but the practical decisions each party makes about why and how personal data is processed also matter.
4. Identify your lawful basis and be transparent
If an AI use involves personal data, your organisation needs a lawful basis for processing it. The appropriate basis depends on the purpose and circumstances; it should be identified before processing begins, not added retrospectively.
Additional rules apply to special category data, such as information about health, ethnicity, religion, political opinions or biometric identification. Criminal offence data also receives additional protection.
People should also receive clear and meaningful information about how their data is used. That may require changes to privacy information, employee notices or customer-facing processes.
Avoid vague explanations such as “we may use AI to improve our services.” Explain, in language people can understand, what the system does, what information it uses, why it is used and how the use may affect them.
5. Decide whether a DPIA is required
A Data Protection Impact Assessment, or DPIA, is a structured way to identify and reduce risks to people before processing begins.
The ICO says that, in the vast majority of cases, AI involving personal data is likely to involve high-risk processing and therefore trigger a DPIA requirement. The decision must still be made case by case. If you conclude that a proposed use is not high risk, document how you reached that conclusion.
A DPIA is particularly important where AI is used for:
- profiling or scoring people;
- recruitment, performance or disciplinary decisions;
- decisions about access to services or opportunities;
- large-scale use of sensitive information;
- monitoring people or their behaviour; or
- processing that individuals would not reasonably expect.
Treat the DPIA as a working risk-management document, not a form completed after the system has already been purchased. It should describe the data flow, purpose, risks, safeguards, supplier roles and degree of human involvement. It should also be reviewed if the tool, data or use case changes.
If you are unsure whether a DPIA or a particular lawful basis is required, seek appropriate data protection or legal advice.
6. Keep meaningful human oversight
AI output can sound confident while being incomplete, inaccurate or simply wrong. It may also reproduce bias found in its training data or introduced through the way a task has been framed.
For that reason, an employee should remain responsible for checking important output before it is used. The level of review should reflect the potential harm: a draft social media caption is not the same as a recommendation affecting someone’s job, credit or access to a service.
Human review must be meaningful. The reviewer needs enough knowledge, authority and time to challenge the result and make a different decision. Clicking “approve” without understanding the output is not effective oversight.
Businesses should also consider how they would:
- correct inaccurate personal information;
- respond to a data access or deletion request;
- explain a decision influenced by AI;
- record when AI contributed to an important outcome; and
- manage a complaint or challenge from the affected person.
7. Create a clear AI policy and review it regularly
If staff are not given an approved route for using AI, some will choose their own. This “shadow AI” can leave the business without visibility of where its information is going.
A practical AI policy should state:
- which tools and account types are approved
- which business uses are permitted
- what information must never be entered
- when anonymisation or approval is required
- who checks AI-generated output
- how suspected errors or data incidents are reported
- who can procure or connect new AI services
- how usage will be reviewed
Policy alone is not enough. Support it with short, role-relevant training, secure configuration and an approval process that employees can actually use. Review the policy as providers change their terms, products gain new features and regulatory guidance develops.
A quick AI and GDPR checklist
Before approving an AI tool, can your business answer yes to these questions?
☐ We have defined the specific business purpose.
☐ We know whether personal, sensitive or confidential data will be used.
☐ We have checked the provider’s retention, training, security and data-location terms.
☐ We have identified and documented an appropriate lawful basis where personal data is involved.
☐ We have assessed whether a DPIA is required and recorded the decision.
☐ A suitably qualified person will review important outputs and can overturn them.
☐ Employees have clear rules, training and an escalation route.
If one or more answers are “no”, pause before introducing the tool more widely.
Frequently asked questions
Is ChatGPT GDPR compliant?
There is no universal yes-or-no answer. Compliance depends on the particular service and account type, its configuration, the information entered, the purpose of processing, the provider’s terms and the safeguards your organisation puts in place. A tool’s security features do not by themselves make every proposed use compliant.
Can employees put customer data into an AI tool?
Only where the organisation has approved the tool and the specific use after considering lawful basis, transparency, data minimisation, security, supplier terms and any need for a DPIA. As a safe default, staff should not enter customer data into public or unapproved AI services.
Does a small business need an AI policy?
If employees use or are likely to use AI for work, a short and practical policy is worthwhile. It establishes approved tools, prohibited data, review responsibilities and an incident-reporting route. The policy should be proportionate to the organisation and its use of AI.
When is a DPIA needed for AI?
A DPIA is required where processing is likely to result in a high risk to people’s rights and freedoms. AI used for profiling, significant decisions, large-scale sensitive-data processing or systematic monitoring is especially likely to require one. Even where a business decides a DPIA is unnecessary, it should document that assessment.
Is Microsoft Copilot automatically safe to use with company data?
No business tool is automatically safe for every task. The organisation still needs to review the exact Copilot product and licence, identity and access controls, data permissions, configuration, connected services and intended use. Existing oversharing within Microsoft 365 can become more visible when powerful search and AI capabilities are introduced.
Responsible AI starts with good IT governance
AI governance is not separate from everyday IT management. It depends on knowing which applications are in use, controlling identities and permissions, protecting data, configuring services securely and giving employees clear guidance.
LAN Support Systems Ltd helps organisations introduce new technology in a controlled and practical way. We can help you review your current AI use, assess security and access controls, identify shadow IT and turn business requirements into a workable employee AI policy.
Planning to introduce AI tools or concerned they may already be in use? Talk to LAN Support about an AI readiness review.
Sources
ICO: Guidance on AI and data protection
ICO: Accountability and governance implications of AI
ICO: Security and data minimisation in AI