AI and GDPR: How UK Businesses Should Handle AI Tools and Personal Data

Learn how UK GDPR applies when employees and organisations use AI tools with personal data. This guide covers generative AI risks, safe prompting, supplier checks, automated decision-making, DPIAs, acceptable use policies and staff training. Discover how UK businesses can benefit from AI while protecting customer, employee and confidential information.
T
Theo Carter
Jul 31, 2026
9 min read
UK business team reviewing compliant AI use, data risk, human oversight and GDPR documentation.

AI tools are now part of everyday business operations. Employees use chatbots to draft emails, summarise documents, analyse spreadsheets, write code and respond to customers. However, the relationship between AI and GDPR UK requirements is often misunderstood, particularly when staff enter personal information into public generative AI services.

UK GDPR does not ban artificial intelligence. It requires organisations to understand when AI involves personal data, use that data lawfully and fairly, minimise it, keep it secure and remain accountable. The Data Protection Act 2018 also forms part of the UK framework, while the Data (Use and Access) Act 2025 changed the automated decision-making rules that apply in 2026.

For business owners, IT managers and compliance officers, the practical question is how to gain the benefits of AI without losing control of customer, employee or supplier information.

Why AI Tools Raise GDPR Questions

Generative AI changes how information moves through an organisation. A member of staff may paste a complaint, CV, medical note, customer record or internal report into a chatbot without realising that they are disclosing data to another provider.

That action may amount to processing personal data. Even where names are removed, combinations of details such as role, location, age, transaction history or case circumstances may still identify someone.

AI data protection risks commonly arise because:

  • Staff use personal accounts or free public tools without approval.
  • Prompts contain more information than the task requires.
  • The organisation does not know whether prompts are retained or reused.
  • Outputs contain inaccurate, biased or invented information about people.
  • Suppliers process information overseas or use subprocessors.
  • Teams rely on AI recommendations without meaningful human review.

This unapproved use is often described as shadow AI. It can be difficult to detect because the activity happens through an ordinary browser tab and may leave little evidence in internal systems.

Does UK GDPR Apply to AI Systems?

UK GDPR applies when an AI system processes information relating to an identified or identifiable living person. This may include customer details, employee records, online identifiers, recordings, behavioural data, opinions, predictions and profiles.

The law applies to the processing activity, not the product label. A tool does not fall outside UK GDPR because it is called a chatbot, assistant or copilot. An AI tool used only with genuinely anonymous information, however, may not involve personal data.

Where personal data is involved, establish:

  • The purpose: What problem is the AI used to solve?
  • The organisation’s role: Is it a controller, joint controller or processor?
  • The lawful basis: Which UK GDPR lawful basis supports the processing?
  • Transparency duties: What must people be told?
  • Safeguards: How will security, accuracy, bias, retention and individual rights be managed?

The core principles remain central: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability. The ICO makes clear that organisations must be able to demonstrate compliance, including when a supplier performs the processing.

AI projects should sit within the wider governance described in an IT compliance and GDPR guide, rather than being treated as innovation experiments with no privacy oversight.

Common Risks When Staff Use AI Tools at Work

The most immediate risk is accidental disclosure. An employee may ask a public chatbot to rewrite a customer email, summarise a disciplinary case or diagnose a technical problem using a live log containing names, email addresses or IP addresses.

Other common risks include:

  • Loss of confidentiality: Information leaves approved systems and enters a supplier environment.
  • Unclear reuse: Prompt data may be stored, reviewed or used for service development.
  • Inaccurate output: Generative AI can produce convincing but incorrect statements about individuals.
  • Excessive processing: Staff upload full documents when an anonymised extract would be enough.
  • Bias and unfairness: Models may reproduce patterns that disadvantage people or groups.
  • Weak access control: Shared accounts make activity difficult to trace.
  • International transfers: Personal data may be accessed or processed outside the UK.
  • Poor incident visibility: A disclosure may remain undiscovered.

A prompt-related disclosure can become a personal data breach if it causes accidental or unlawful disclosure, access, loss, alteration or destruction of personal data. Connect AI controls to your data breach prevention guide, reporting route and breach assessment procedure.

Inputting Personal Data Into AI Tools — What to Avoid

As a default rule, employees should not paste identifiable customer, employee, patient, learner or client information into a public AI tool unless the organisation has approved the specific supplier and use case.

Staff should avoid entering:

  • Names, addresses, telephone numbers or personal email addresses.
  • Account, payroll, payment or identification details.
  • Health, biometric or other special category data.
  • Criminal allegation or conviction information.
  • CVs, interview notes, appraisals or disciplinary documents.
  • Customer complaints, case files or support tickets.
  • Confidential contracts, legal advice or commercial records.
  • Credentials, API keys, passwords or live security logs.

Data minimisation should guide every prompt. Use only what is necessary, remove direct identifiers, generalise details and use fictional or synthetic examples where possible. Pseudonymisation can reduce risk, but information remains personal data if the organisation can reconnect it to an individual.

Before approving a supplier, check where data is stored, whether prompts are used for training, retention periods, subprocessors, security measures, deletion processes and international transfer safeguards. Contracts should clearly define controller and processor responsibilities, and procurement should include privacy and security due diligence.

For a practical foundation in handling information lawfully, explore GDPR Essentials for UK Businesses. It can help managers establish the principles staff should apply before using AI.

Automated Decision-Making and Profiling Under UK GDPR

Automated decision-making matters when AI is used to assess applicants, approve credit, set prices, detect fraud, rank employees or determine access to services.

Many resources still refer to “Article 22 rights”. However, the Data (Use and Access) Act 2025 replaced the former Article 22 framework with UK GDPR Articles 22A to 22D. The main data protection changes came into force on 5 February 2026.

The framework is more permissive for significant decisions based solely on automated processing of non-special-category data, but businesses must still use a valid lawful basis and provide safeguards. A decision is solely automated where there is no meaningful human involvement; merely approving an AI recommendation without examining the evidence is unlikely to be meaningful oversight.

Safeguards for significant solely automated decisions include:

  • Informing the individual about the decision.
  • Allowing them to make representations or challenge it.
  • Enabling meaningful human intervention.
  • Enabling reconsideration of the decision.

Stricter conditions apply when special category data is used. Businesses must also consider fairness, discrimination, accuracy, explainability and whether people would reasonably expect AI to be used.

Map every AI-supported decision and document what a human reviewer must check. Human involvement should be informed, independent and capable of changing the outcome.

What ICO Guidance Says About AI

The ICO’s position is that data protection law supports responsible innovation; it does not prevent AI use. Compliance depends on the purpose, data, system design, risks and safeguards.

Its guidance and audit framework emphasise:

  • Accountability and clear senior ownership.
  • Data protection by design and by default.
  • A lawful basis and transparent privacy information.
  • Data minimisation, security and accuracy.
  • Documented controller and processor roles.
  • Supplier due diligence and contractual controls.
  • Effective human review and individual rights.
  • Monitoring throughout the AI lifecycle.

A Data Protection Impact Assessment is required when processing is likely to result in a high risk to individuals. Many AI uses may reach that threshold, particularly systematic evaluation, significant automated decisions, large-scale special category data use, tracking, matching or novel monitoring. If an organisation decides a DPIA is unnecessary, it should document why.

An AI DPIA should describe the purpose, data sources, affected people, data flows, supplier roles, lawful basis, necessity, proportionality, potential harms and controls. It should compare less intrusive alternatives and record residual risks. If high residual risk cannot be reduced, the organisation may need to consult the ICO before processing begins.

Buying a product does not transfer accountability to the supplier. Your organisation must understand the service well enough to decide whether it can be used lawfully and fairly.

IT and compliance teams may benefit from Data Protection & GDPR for IT Professionals and GDPR training for IT professionals. These courses support teams translating legal duties into technical and operational controls.

Building an AI Acceptable Use Policy

An AI acceptable use policy gives employees clear rules before problems occur. It should cover generative AI chatbots, embedded assistants, image tools, code generators, transcription services and other AI used for work.

A practical policy should include:

  • Approved tools and accounts: Identify permitted services and managed accounts.
  • Prohibited data: Define personal, confidential, security-sensitive and special category information that must not be entered.
  • Permitted uses: Give examples, such as drafting generic copy or working with synthetic data.
  • Human verification: Require checks for accuracy, bias, confidentiality and legality.
  • Approval thresholds: State when IT, compliance, HR, legal or DPO review is required.
  • Record-keeping: Explain when prompts, outputs, decisions, DPIAs and approvals must be retained.
  • Supplier onboarding: Require privacy, security, contract and transfer checks.
  • Incident reporting: Provide a route for reporting accidental disclosure or unauthorised use.
  • Individual rights: Explain how access, correction, objection and automated-decision challenges will be handled.
  • Review: Update the policy as tools, contracts, law and ICO guidance change.

A policy should not be so restrictive that staff ignore it. Provide approved alternatives, a quick review route and realistic examples. ICO governance materials similarly emphasise documented roles, policies, procedures and training for AI systems.

Training Staff on Safe AI Use

A policy alone is not enough. Employees need practical training showing how ordinary prompts can create data protection, confidentiality and security risks.

Training should help staff recognise personal and special category data, minimise prompt content, use approved accounts, verify outputs and report mistakes quickly.

Make training role-specific:

  • General employees: Safe prompting and prohibited data.
  • Managers and HR: Fairness, profiling and employment decisions.
  • IT and security: Supplier assessment, access controls, logging and incidents.
  • Compliance and DPO teams: DPIAs, lawful basis, transparency and rights.
  • Senior leaders: Accountability, ownership and risk appetite.

Use short scenarios rather than abstract rules. Ask employees whether a prompt is safe, what information should be removed and when approval is required. Refresh training when tools or business uses change.

For organisations asking how to make using AI tools GDPR compliant, the strongest approach combines controlled technology, documented governance and staff judgement. Training turns these controls into consistent daily behaviour.

FAQs

Does UK GDPR apply to AI tools like ChatGPT?

Yes, when the tool processes personal data in a context covered by UK law. For ChatGPT GDPR UK compliance, consider what information is entered, why it is used, what the provider does with it and which safeguards your organisation has implemented.

Can employees put customer data into AI chatbots?

Not by default. Employees should only enter customer data when the organisation has approved the tool and use case, identified a lawful basis, completed suitable supplier and risk checks, and limited the information to what is necessary.

Do I need a DPIA before using AI in my business?

A DPIA is required when processing is likely to create a high risk to people’s rights and freedoms. Many AI uses may meet this threshold, especially significant automated decisions, profiling, large-scale sensitive data use or novel monitoring.

What does the ICO say about generative AI?

The ICO says data protection law does not prevent generative AI, but developers and users must meet duties including lawfulness, fairness, transparency, accuracy, security, data minimisation and individual rights. It also highlights accountability, supplier roles and appropriate risk assessment.

Is automated decision-making by AI regulated under UK GDPR?

Yes. Since February 2026, Articles 22A to 22D regulate significant decisions based solely on automated processing, replacing former Article 22. Safeguards include information, representations, human intervention and reconsideration, with stricter rules for special category data.

Stay ahead of AI risk. Make sure your team understands the data protection risks of AI. Explore our GDPR Essentials for UK Businesses course and build safer, more accountable AI practices.

Article by:

Professional portrait of an IT governance, compliance and data protection systems writer

Theo Carter

Theo Carter is an IT governance, compliance and data protection systems writer. He explores how organisations can align technology, security controls and operational processes with GDPR and wider information governance requirements.

Start Building Your Data Protection Skills Today

Explore flexible online courses designed to help you learn, apply, and strengthen data protection knowledge at your own pace.

Browse Courses