Lesson 3 of 6
GDPR without the jargon
The plain-English version of what UK GDPR actually requires when AI touches customer data, built around realistic small-business scenarios.
Say the letters “GDPR” out loud in a room of small business owners and watch the shoulders tense. Add AI into the same sentence and it can feel like a minefield only a lawyer could cross safely. The reality is calmer than that. AI does not tear up the data-protection rulebook and write a new one. It just means the rules you already follow now stretch to cover one more tool.
The one idea to hold on to
UK data-protection law rests on a simple principle: if you hold information about identifiable people, you have a duty to look after it and use it responsibly. That is true whether it sits in a filing cabinet, your booking software, or a chat with an AI tool. AI is not a special exception where the rules cannot reach. It is just another place personal data can end up.
Three realistic scenarios
A gardening business quoting a new client. You want AI to help draft a quote from an enquiry email. The email has the client’s name, address and a note about a dog in the garden. Do you need any of that to draft a polite, professional reply? No. Describe the job, “a client wants a quote for a garden tidy and hedge trim, medium-sized garden”, and add their name back in afterwards. Problem solved before it started.
An estate agent summarising viewing feedback. You have twenty viewing feedback forms with names and phone numbers, and you want AI to summarise the common themes. Strip the names and numbers out first, or work from a version with just the comments. The summary is exactly as useful either way.
A driving school choosing a scheduling tool with AI built in. This is the scenario that actually needs a proper check. Before you connect any tool to pupils’ names, addresses and payment details, look for a privacy policy, a data processing agreement on the business plan, and a setting to turn off training on your data. A reputable provider will have all three within a few clicks. If you cannot find them, that is your answer.
The practical steps that keep you tidy
You do not need a compliance department. A few habits, done consistently, cover almost everything:
- Minimise. Put in the least personal data that gets the job done. This is the single most protective habit and it makes every other question easier.
- Use proper business accounts. For anything that might touch personal data, use a paid business plan with training switched off, not a free consumer tool with no privacy terms to speak of.
- Keep a short list. A one-page note of which AI tools you use, for what, and with what settings, is usually enough to show you have thought about it properly.
- Check before you act on it. AI can state things about a person with total confidence and be wrong. If it is recording or summarising anything about a real customer, check it before it goes anywhere near a file or a decision.
Where AI adds a genuinely new wrinkle
One thing is worth naming because it is newer than the classic rules: automated decisions about people. If you ever let AI decide something significant about a person entirely on its own, refusing a booking, say, with no human involved, that is the moment to get proper advice. Most small businesses are nowhere near this, because a person is making the actual call. Keep it that way and you are on safe ground.
The bottom line
GDPR and AI is your existing responsibility to look after people’s data, applied to one more tool. Minimise what you put in, use proper business accounts, keep a short record, and get real advice for the genuinely tricky edges. Next, we look at what changes once AI stops being a chat window and starts running inside your actual workflows.
For the fuller picture, see our guide AI and GDPR for small businesses, without the panic.