Do I Need Staff Consent or Client Permission Before Using AI on Their Information?
6 October 2026
Do I Need Staff Consent or Client Permission Before Using AI on Their Information?
The correct question is not simply whether somebody has said yes to AI. A UK business must identify a lawful basis for each use of personal data, tell people what it is doing, limit the data used and check its supplier terms. Client permission may still be required where your contract, professional duty or confidentiality promise says so, even when consent is not the UK GDPR lawful basis.
Consent is not the same as lawful permission
UK data protection law does not say that every use of personal information requires consent. Consent is one possible lawful basis, but it is not a universal permission slip and it is often the wrong basis for routine business processing. The Information Commissioner's Office says an organisation must separate each processing operation, define its purpose, select the basis that reflects the real relationship and document that choice before processing starts. Its AI lawfulness guidance also warns that the basis for developing a system may differ from the basis for using it with live information.
For a small business, the likely candidates include contract, legal obligation and legitimate interests. Contract applies only where the processing is objectively necessary to provide what the person asked for. Legitimate interests requires a documented three-part test: identify the legitimate purpose, show the processing is necessary, then balance it against the person's rights and reasonable expectations. If a less intrusive method works just as well, that weakens the case for using AI.
Consent can be appropriate when a person has a genuine choice, understands the specific use and can withdraw as easily as they agreed. That is a higher bar than placing a broad AI clause in terms and conditions. If you rely on consent and the person withdraws it, you cannot simply swap to legitimate interests because the workflow has become inconvenient.
The practical answer is therefore purpose by purpose. Using AI to format a fully anonymised procedure is different from uploading named customer complaints. Summarising an employee's voluntary training feedback is different from scoring their performance. Write down the purpose, the data and the legal basis for each use rather than approving AI as one undivided activity.
Why staff consent is usually the wrong starting point
An employee may technically tick a box, but the employment relationship makes it difficult to prove that the choice was freely given. A member of staff may reasonably worry that refusing will affect their job, promotion or relationship with their manager. The ICO's consent guidance says employers should consider alternatives because of this imbalance of power.
The Serco Leisure case shows why this matters. In February 2024, the ICO ordered Serco Leisure, Serco Jersey and seven associated trusts to stop using facial recognition and fingerprint scanning for attendance. More than 2,000 employees across 38 leisure facilities were affected. Staff had not been proactively offered a clear alternative, and the ICO found that less intrusive options such as cards or fobs were available. Nine enforcement notices required the organisations to stop the processing and destroy biometric data they were not legally required to retain. The regulator's Serco Leisure report is not about a chatbot, but its lesson applies directly to workplace AI: calling something consent does not make unnecessary or disproportionate monitoring lawful.
For ordinary staff administration, another lawful basis may fit better. Payroll processing may be necessary for the employment contract or a legal obligation. A narrowly designed tool that helps route internal requests may support legitimate interests, provided the business completes the balancing work and gives staff clear information. Health, biometric, trade union and some equality information is special category data, so it needs both an Article 6 lawful basis and a separate Article 9 condition.
Whatever basis applies, tell staff what tool is used, which information enters it, why, how long data is retained, who can see outputs and how to challenge an error. A policy hidden on a shared drive after launch is not meaningful transparency.
When client permission or notice may be required
With clients, separate four questions. First, do you have a lawful basis under data protection law? Second, have you given the required privacy information? Third, does your contract permit the proposed use and any supplier access? Fourth, do professional confidentiality rules or a duty of confidence require permission?
You may not need consent to use AI to perform a service that a client has contracted you to provide, but contract is not a blank cheque. The processing must be objectively necessary for that service. If you could deliver the same work without sending identifiable information to an external AI provider, you need to justify why the extra processing is necessary or choose another appropriate basis. Using client material to improve a supplier's general model is a different purpose from using it to produce the client's requested output.
Your written agreement may be stricter than data protection law. A non-disclosure agreement might prohibit sharing with third parties without written permission. A solicitor, accountant, clinician or other regulated professional may have duties that go beyond a basic UK GDPR analysis. A client may also have promised its own customers that data stays in a defined location or only goes to approved subprocessors. In those situations, client permission or a contract variation can be necessary even though consent is not your Article 6 basis.
Transparency still matters where permission is not required. Update the privacy notice before the new use begins. State the purpose, categories of information, lawful basis, relevant recipients, retention approach and rights. If an AI provider processes information on your instructions, put the required processor terms in place and examine its subprocessors, security, deletion and international transfer arrangements. If the provider decides its own purposes, it may be an independent controller, which changes what you must tell people and may change whether the arrangement is acceptable at all.
Higher-risk uses need more than a privacy notice
The risk rises sharply when AI evaluates people, infers sensitive characteristics, monitors workers or influences significant decisions. Articles 13 and 14 of the UK GDPR require information about solely automated decision-making with legal or similarly significant effects, including meaningful information about the logic and likely consequences. Article 22 includes safeguards such as human intervention, the ability to express a view and the ability to contest a decision. Article 35 requires a data protection impact assessment when new technology is likely to create a high risk to people.
A DPIA should be completed before deployment, while the design can still change. Map the data sources, affected people, purpose, lawful basis, necessity, likely harms, security controls, human review and fallback process. Record whether the reviewer has real authority and enough information to overturn the AI output. A person who merely rubber-stamps a score is not meaningful human involvement.
The ICO's 2024 audits of AI recruitment providers found substantial room for improvement. It made almost 300 recommendations, all accepted or partially accepted. The regulator highlighted tools that collected more personal information than necessary, retained it indefinitely, failed to explain their use clearly or allowed filters involving protected characteristics. Its recruitment AI findings tell buyers to complete a DPIA, define controller and processor roles, test for bias and minimise data.
This is why permission alone is not enough. A client cannot consent away poor security, excessive collection or discrimination. An employee's agreement does not remove the need for proportionality. If the use affects recruitment, discipline, pay, credit, eligibility, health or another significant outcome, involve a competent data protection or legal adviser and consider the Equality Act 2010 as well as UK GDPR.
A practical approval checklist for small businesses
Do not begin with a company-wide request for everyone to consent to AI. Begin with one defined workflow and answer ten practical questions.
- Purpose: What business result are we trying to achieve?
- People: Whose information is involved: staff, clients, prospects or another group?
- Data: What exact fields, documents or messages will the tool receive, and can identifiers be removed?
- Lawful basis: Which basis applies to this purpose, and is special category or criminal offence data involved?
- Expectation: Would the person reasonably expect this use, or would it surprise them?
- Supplier: Does the provider train on inputs, retain prompts, use subprocessors or move data overseas?
- Contract: Do client terms, confidentiality promises or professional rules allow the disclosure?
- Transparency: What must change in privacy notices, staff guidance or direct communications?
- Control: Who checks outputs, handles objections and stops the process if it fails?
- Evidence: Do we need a legitimate interests assessment, DPIA, processor contract or written client approval?
Use the minimum information needed. A redacted extract is often safer than a whole client file. A secure business account with admin controls is usually more appropriate than a personal free account. Turn off model training where the supplier offers that control, restrict integrations to the smallest set of records and set a deletion period rather than keeping everything indefinitely.
Keep the decision in an AI register. Record the owner, tool, purpose, data, lawful basis, risk assessment, contract status and review date. Revisit it when the supplier changes its terms, the workflow expands or staff start using the output for a new decision. A five-minute experiment can quietly become a business process, so the review needs to follow the real use rather than the original intention.
When this does not apply
This article does not mean that every mention of a person triggers a permission exercise. Truly anonymised information that cannot reasonably identify anyone falls outside UK GDPR, although removing names alone may not be enough if the remaining details point to a person. It also does not mean AI always creates a new legal basis. If an approved tool processes the same minimum information for the same lawful purpose under an appropriate contract, the existing basis may remain suitable, but transparency and supplier checks still need review.
It also does not mean a tick box cures a risky design. Do not rely on staff consent for compulsory monitoring, use broad client consent to cover unrelated model training, or treat a supplier's security badge as proof that your own use is lawful. Avoid putting live personal information into consumer AI accounts simply to test whether a workflow is useful. Start with synthetic or redacted examples until governance is ready.
Pause and get specialist advice if the proposed system handles biometric, health, ethnicity, trade union, sexual life, criminal offence or children's information. The same applies if it profiles vulnerable people, monitors workers continuously, makes or strongly influences significant decisions, or uses confidential professional records. The cost of advice is usually smaller than rebuilding a workflow after clients object or the regulator intervenes.
The most honest answer is simple: you do not automatically need consent, but you always need justification. For staff, prove that the use is necessary, proportionate and transparent without pretending that an employee can freely refuse a compulsory process. For clients, check both data protection law and the promises in your engagement terms. If the purpose, provider or information cannot be explained clearly in writing, the workflow is not ready to use on real data.
Is This Right For You?
This guidance is useful if your business wants to summarise emails, analyse call notes, draft from client files, review employee information or connect an AI assistant to a CRM. It is designed to help an owner or manager ask the right questions before switching the tool on.
It is not a substitute for legal advice where you process health information, criminal records, biometric data, children's data, large volumes of sensitive information or data for regulated professional work. It is also not enough for AI that makes final decisions about recruitment, dismissal, credit, insurance, medical care or access to essential services. In those cases, involve your data protection lead or a qualified adviser before deployment.
If you want an independent sense-check, start by documenting one use case, the data involved, the supplier and the person who will review the output. We can then have an honest conversation about whether it needs a simple policy change, a DPIA or a more tightly controlled system. No pitch and no pressure.
Frequently Asked Questions
Can employees refuse to let us use AI on their information?
It depends on the purpose and lawful basis. If you rely on consent, refusal and withdrawal must be genuine options without detriment. If another basis applies, refusal may not stop the processing, but staff still have rights and may be able to object. Compulsory monitoring needs particularly careful necessity and proportionality checks.
Do we need client consent before putting an email into an AI assistant?
Not automatically, but you need a lawful basis, transparency, a suitable supplier arrangement and compliance with your confidentiality terms. If the contract bans third-party disclosure or the supplier uses content for its own purposes, obtain permission or do not upload it. Redact unnecessary personal details wherever possible.
Is anonymised information safe to use with AI?
Properly anonymised information falls outside UK GDPR, but removing a name is not always enough. Job titles, dates, locations and unusual facts can identify someone when combined. Test whether re-identification is reasonably possible and prefer synthetic data for early experiments.
Do we need a DPIA for every AI tool?
No. A DPIA is required where the processing is likely to create a high risk to people, and it is good practice for many personal-data AI uses. Profiling, worker monitoring, sensitive information and significant automated decisions are strong reasons to complete one before launch.
Can legitimate interests cover our use of client data with AI?
Sometimes. You must identify a legitimate purpose, show the processing is necessary and balance it against the person's rights and expectations. Document that assessment. Legitimate interests does not override confidentiality clauses, professional duties or the need for a proper supplier contract.
What if an AI provider says it does not train on our data?
That is useful but not sufficient. Check retention, subprocessors, international transfers, security, deletion, access controls, incident terms and whether the provider acts only on your instructions. Keep evidence of the settings and contract version you relied on.
Do we have to tell people that AI helped a human make a decision?
Where personal data is involved, transparency is still required even if a human participates. The level of detail depends on the effect of the decision. For significant decisions, explain the AI's role, the logic in meaningful terms, likely consequences and how the person can challenge errors.