The moment you mention GDPR, a lot of owners tense up. Add AI on top and it can feel like a minefield only a lawyer could cross. The reality is calmer than that. AI does not tear up the data-protection rulebook and write a new one. It just means the rules you are already meant to follow now apply to one more type of tool. Handle it with the same common sense you apply to your CRM or your email, and you are most of the way there.

This is general guidance, not legal advice. GDPR obligations depend on your specific circumstances, and if you handle sensitive data at scale or are unsure, you should take proper advice from a professional who knows your business.

The one idea to hold on to

UK data-protection law is built on a simple principle: if you hold information about identifiable people, you have a duty to look after it and use it responsibly. That is true whether the information sits in a filing cabinet, a spreadsheet, your accounting software, or a chat with an AI tool.

So the honest headline is this. AI is not a special exception where the rules do not reach. It is just another place personal data can end up, and the same duties follow it there. Once you see it that way, the panic drains out and it becomes a checklist.

The questions worth asking

Before you use an AI tool with anything that counts as personal data (a customer name with contact details, for example), a few plain questions cover most of what matters.

Do I actually need to put personal data in at all? Often the answer is no. The rules reward you for minimising: only use the personal data you genuinely need. As we cover in our guide on what never to paste into AI, you can usually describe the situation without the real names and details. That instinct is also good data-protection practice.

Does this tool have proper terms for business use? A reputable AI provider will have a privacy policy, will tell you where data is processed, and on business plans will offer a data processing agreement. Free consumer tools often will not, and that is a signal to keep personal data out of them.

Is training on my data switched off? If a tool learns from what you type, personal data could, in theory, surface elsewhere. Business accounts usually let you turn training off, and often have it off by default. Switch it off and confirm it.

Where is the data processed, and for how long? You do not need a law degree here, but knowing roughly where a provider stores data and how long they keep it is part of doing your homework on any supplier who handles personal information.

The practical steps that keep you tidy

You do not need a compliance department. You need a few habits done consistently.

  • Minimise. Put in the least personal data that gets the job done. Anonymise wherever you can. This is the single most protective thing you can do, and it makes almost every other question easier.
  • Use business accounts with the right terms. For any AI tool that might touch personal data, use a paid business or team plan with a data processing agreement and training turned off. Treat the free consumer versions as fine for general, non-personal work only.
  • Keep a short list of your AI tools. Part of the rules is simply knowing what you use and being able to explain it. A one-page note of which AI tools you use, for what, and with what settings, is enough to show you have thought about it.
  • Tell people if it matters. Your privacy notice tells customers how you use their data. If AI tools become a meaningful part of how you handle personal information, it is good practice to reflect that in plain language.
  • Set team rules. If others in your business use AI, a simple internal rule about what can and cannot go into which tools prevents most problems. Our one-page AI policy guide gives you a starting template.

Where AI adds a genuinely new wrinkle

Two things are worth naming because they are slightly newer than the classic filing-cabinet rules.

Automated decisions about people. The rules give people protections when a purely automated system makes a significant decision about them, such as refusing credit, with no human involved. Most small businesses are nowhere near this, because a human is making the actual call. But if you ever let AI decide something important about a person on its own, that is the moment to get proper advice.

Accuracy. AI can state things with confidence that are simply wrong. If you use it to record or communicate anything about a real person, the “AI drafts, you check” rule is not just about quality, it is about not holding or acting on inaccurate personal data. Check before it counts.

The honest bottom line

GDPR and AI is not a minefield. It is your existing responsibility to look after people’s data, applied to one more tool. Minimise what you put in, use proper business accounts with training off, keep a short record of what you do, and get real advice for the genuinely tricky edges. Do that and you are being a responsible business, which is all the rules are really asking.

If you would like to work through this in plain English, with your own situation in the room, that is exactly the kind of thing our AI Automation Masterclass in Manchester makes time for. No jargon, no scare tactics. Tickets are normally £20. This one’s free, a limited-time offer to launch the series.

And grab our plain-English safety sheets and the one-page policy starter from the free resources shelf, so you have something to build on.