A quiet reading corner in a modern office at blue hour, an armchair and floor lamp by tall glazing

Data protection

What UK GDPR asks of a business using AI

Nothing in UK GDPR is specific to AI. The same duties you already had apply the moment a new tool touches personal data: know what you are doing and why, have a lawful basis, use the least data you can, tell people, keep it secure, and have a written contract with whoever processes it for you.

Last checked 19 September 2026

The starting point most people get wrong #

There is no AI chapter of UK GDPR waiting to be complied with. The law regulates the processing of personal data, and an AI tool is simply a new place where processing happens.

That is good news, because it means the framework is the one you already deal with, and it means a business with its ordinary data protection house in order has far less to do than it fears.

It also means the obligations follow the personal data. A tool used entirely on things that are not personal data, such as drafting a description of a product or restructuring your own notes, raises almost none of what follows.

1. Know what is actually happening #

Before anything else, write down what personal data goes into the tool, whose it is, what comes out, and where it is stored. This sounds bureaucratic and is the step that resolves most of the confusion, because a surprising number of AI questions dissolve once somebody establishes that no personal data was involved in the first place.

Be specific about whose data it is. Customers, employees, candidates and the clients of your clients all sit in different positions, and the last of those is where professional service firms tend to find their real constraint, because their own client contracts often say more than the law does.

2. Have a lawful basis, for each separate thing #

The ICO's guidance on lawfulness in AI is explicit that you should break down and separate each distinct processing operation and identify a purpose and an appropriate lawful basis for each one. It also draws a line most summaries miss: processing personal data to develop an AI system is a different purpose from processing it to use one, and a basis that is appropriate for the second may not be appropriate for the first.

In business terms: deciding you may lawfully use a tool to draft replies does not also cover your clients' information being used to improve that tool. If the plan you are on permits that, it needs its own answer. How to find out which plan you are actually on is in is ChatGPT GDPR compliant.

3. Use the least data that does the job #

Data minimisation is the principle AI puts under most pressure, and the ICO addresses the tension head on: AI systems generally want large amounts of data, and you are still required to identify the minimum amount of personal data you need to fulfil your purpose and process only that.

For a business this is usually the most practical lever available, and it is unglamorous.

  • Send the paragraph rather than the file
  • Strip the name when the name is not needed
  • Do not paste a whole spreadsheet to ask about one row

Most of the benefit of these tools survives that discipline entirely intact.

4. Tell people #

Transparency is not a separate AI duty, it is the existing one. The ICO expects you to be clear about your purposes for processing, your retention periods and who you share data with. A new supplier handling your customers' information is usually a privacy notice change.

Our own notice is on the privacy page, which is a reasonable model for the level of detail a business needs: plain, specific about who processes what, and clear about how to make it stop.

5. Get the contract right #

Where a supplier processes personal data on your behalf, UK GDPR requires a written contract with specific terms in it. This is the duty businesses most often miss entirely, because signing up to a service online does not feel like entering a data processing relationship, and consumer terms are generally not written to satisfy it.

What the contract has to contain, and how to find out whether you have one, is set out in what a data processing agreement is for.

6. Work out whether the project needs a DPIA #

Some processing requires a data protection impact assessment before it starts, particularly where it is likely to result in high risk to people, involves innovative technology, or affects people in significant ways. Many small automation projects do not trigger it. Some plainly do, and doing the assessment afterwards is not the same thing.

The threshold questions are in do you need a DPIA.

7. Keep a person in front of decisions that matter #

The design implication is the same one that good practice would suggest anyway, and it is covered in what should always wait for a person.

Where to check, and what is still moving #

The ICO publishes a section of advice aimed specifically at small and medium organisations, which is written in far plainer language than the main guidance and is the right first stop. Its detailed AI guidance, meanwhile, is currently under review following the Data (Use and Access) Act, which we cover in what the ICO says about AI.

None of that uncertainty prevents a business acting sensibly now. The duties above are stable, they predate this technology, and a business that meets them is in a good position whatever the updated guidance says.

Questions people ask

Does UK GDPR apply to a business with three staff?
Yes. There is no headcount threshold. Some record keeping obligations are lighter for small organisations, but the principles, the lawful basis requirement and the rights people have over their own data apply whatever the size of the business.
Does using an AI tool need a new lawful basis?
It needs you to have one for each thing you are doing. The ICO advises separating each processing operation and identifying a purpose and a lawful basis for each, and it treats developing an AI system and using one as distinct purposes. So if your content may also be used to improve the model itself, that is a second operation, not a footnote to the first.
Do we have to tell customers we use AI?
You have to tell them what you do with their personal data, including who you share it with and how long you keep it. In practice that usually means your privacy notice needs updating when a new supplier starts handling their information, whether or not you use the word AI.
What is the single most common mistake?
Putting personal data into a tool nobody has a contract with, usually through accounts staff opened themselves. It is not the most serious thing that can go wrong, but it is by a distance the most frequent.

Where these numbers come from

  1. ICO, How do we ensure lawfulness in AI? , read 19 September 2026
  2. ICO, How should we assess security and data minimisation in AI? , read 19 September 2026
  3. ICO, How do we ensure transparency in AI? , read 19 September 2026
  4. ICO, Advice for small and medium organisations , read 19 September 2026

Last checked 19 September 2026.

Our workings are on the methodology page .

Free audit

Find out what the repeated work costs you

The audit counts every job the business repeats, ranks them by the hours they eat, and maps the five worth automating first. It is free, you keep everything, and there is no obligation at the end of it.

AI automation, explained

Plain answers to what businesses ask before they automate anything.

All of ai automation, explained

Read next