What are the GDPR implications of using AI in the UK?

1 April 2026

What are the GDPR implications of using AI in the UK?

If your AI system uses personal data, UK GDPR applies. AI is not banned, but you need a lawful basis, transparency, data minimisation, security controls, supplier checks, and usually a DPIA before using AI on customer, employee, or prospect data. The practical implication for a UK business is simple: treat AI as a data-processing system, not a harmless productivity tool.

The GDPR implication is not that UK businesses cannot use AI. The implication is that AI must be governed like any other system that handles personal data. If the tool reads customer emails, drafts replies from CRM history, scores leads, analyses employee performance, summarises meeting notes, reviews CVs, processes call recordings, or searches internal documents containing names, UK GDPR is in scope.

The ICO guidance on AI and data protection says organisations need to think about accountability, transparency, lawfulness, accuracy, fairness, security, data minimisation, and individual rights across the AI lifecycle. That is a broad list, but for most UK SMEs it comes down to five practical questions: what personal data goes in, why are you allowed to use it, who can see the output, what happens if the AI is wrong, and can you prove your controls if challenged?

A common mistake is assuming the AI provider carries the risk. In most business use cases, you are still the controller because you decide why the data is used and what the tool is supposed to achieve. The AI vendor may be a processor, or sometimes an independent controller for parts of the service, but that does not remove your responsibility. If your staff paste customer data into a tool without the right settings, contract, or approval, the customer will not blame the model provider first. They will blame you.

More than most businesses think. Personal data is not just a name, email address, phone number, or home address. In AI projects, it often includes chat transcripts, support tickets, call notes, voice recordings, user IDs, IP addresses, job applications, employee objectives, meeting summaries, financial records, CRM activity, complaint history, and behavioural signals.

AI also creates new data. A tool might infer that a customer is likely to churn, that an employee is underperforming, that a sales lead is high value, or that a support ticket is urgent. Those inferences can be personal data if they relate to an identifiable person. They can also be wrong, biased, incomplete, or difficult to explain.

This is where UK businesses get into trouble. They do not set out to build a high-risk AI system. They start with a small productivity use case, such as summarising emails or searching a document library. Then someone connects the tool to a mailbox, CRM, helpdesk, HR folder, or call recording archive. Suddenly the AI is processing personal data at scale.

Fully anonymised data is different. If the data cannot identify a person, directly or indirectly, GDPR obligations reduce sharply. But anonymisation is a high bar. Replacing a name with a customer number is usually pseudonymisation, not anonymisation, if someone can link it back. For most practical AI work, assume personal data is involved until you have proved otherwise.

Start with a data map. List the tool, the use case, the data categories, the people affected, the supplier, the storage location, the retention period, the users who can access it, and whether the AI can make or influence decisions. This does not need to be a 40-page document for a small use case, but it does need to be written down.

Then choose a lawful basis. For many commercial AI uses, legitimate interests is the likely route, but it is not a magic phrase. You need to document the business interest, show the processing is necessary, and balance it against the rights and expectations of the people affected. Consent is sometimes appropriate, but it must be freely given, specific, informed, unambiguous, and easy to withdraw. For employee monitoring or customer service tools, consent is often weaker than businesses expect because the person may not have a real choice.

Next, decide whether you need a DPIA. The ICO DPIA guidance says a DPIA is required where processing is likely to result in high risk to people. AI can trigger that where it involves profiling, automated decisions, large-scale personal data, special category data, vulnerable people, invisible processing, or innovative technology. A practical DPIA screen can take a day. A full DPIA for a sensitive AI workflow may take 1 to 4 weeks.

Finally, update your privacy information. If AI materially changes how you use personal data, customers, staff, candidates, or users should be told in plain English. Do not hide it inside vague wording about improving services.

The riskiest AI use cases are not usually drafting blog posts or summarising public reports. They are decisions about people. That includes AI used for recruitment shortlisting, credit decisions, insurance pricing, fraud flags, customer prioritisation, employee performance scoring, disciplinary triggers, vulnerable customer handling, or deciding whether a complaint is escalated.

UK GDPR has specific rules around solely automated decisions that produce legal or similarly significant effects. The Data (Use and Access) Act 2025 is changing parts of the UK data protection framework, and the ICO has already marked parts of its AI guidance as under review. The practical position for business leaders is still clear: if AI makes or heavily influences a significant decision about a person, you need stronger safeguards.

Those safeguards should include meaningful information about the logic involved, a way for the person to challenge the decision, human review, accuracy checks, bias checks, and evidence that the decision process is fair. If the AI is only supporting a human, make sure the human is genuinely reviewing the case rather than rubber-stamping the machine output.

Recruitment is a good UK example. If an AI tool ranks CVs, screens interview answers, or predicts candidate fit, it may process personal data, infer sensitive information, and affect someone's employment prospects. That does not mean you cannot use it. It means you need to know what the tool measures, what data trained it, how bias is tested, how candidates are informed, and how a person can challenge a bad outcome.

Third-party AI tools are usually where GDPR risk becomes practical. The question is not whether the logo is reputable. The question is whether your specific plan, settings, contract, data flow, and use case are suitable for the personal data you want to process.

Before personal data goes into any AI supplier, ask these questions: do we have a data processing agreement, where is data processed, is data used for model training, how long are prompts and outputs retained, who are the sub-processors, can we delete data, can we export logs, can we restrict user access, and what happens if the supplier changes terms?

Consumer-grade tools are usually the wrong place for customer or employee data. Business and enterprise plans may provide stronger contractual terms, admin controls, training opt-outs, audit logs, and retention settings, but you still have to configure them. Buying Microsoft Copilot, ChatGPT Enterprise, Claude Team, Gemini for Workspace, Salesforce Einstein, HubSpot AI, or Zendesk AI does not automatically make the use compliant.

International transfers also matter. If data moves outside the UK, you need a lawful transfer mechanism and an assessment of whether the protection is adequate. For some businesses, especially those handling regulated, sensitive, or high-volume personal data, a private cloud, UK-hosted deployment, or local model may be worth considering. That is not because cloud AI is always unsafe. It is because some data is valuable enough that you should reduce unnecessary movement.

If this is your biggest concern, our related guide to security and privacy risks of connecting AI to business data goes deeper on access, retention, leakage, and supplier exposure.

AI is no longer a fringe issue. GOV.UK's AI activity in UK businesses research reported that around 15% of all UK businesses had adopted at least one AI technology, equivalent to 432,000 companies. It also projected adoption rising to 22.7% by 2025, with another 267,000 businesses using AI in their operations.

The same research found that 68% of large companies, 34% of medium companies, and 15% of small companies had adopted at least one AI technology. That matters because GDPR risk rises as AI moves from isolated experimentation into normal business systems. A sales assistant using AI for public research is one thing. A business-wide assistant connected to CRM, email, files, support, finance, and HR is another.

Cyber risk adds another layer. The Cyber Security Breaches Survey 2025 reported that 43% of UK businesses identified a cyber security breach or attack in the previous 12 months, equivalent to around 612,000 businesses. For medium businesses it was 67%, and for large businesses it was 74%.

The same survey found that only 14% of businesses reviewed cyber security risks from immediate suppliers, and only 7% reviewed wider supply chain risks. That is uncomfortable in an AI context because most AI projects depend on suppliers: model providers, cloud platforms, CRM vendors, automation tools, vector databases, analytics services, and implementation partners. If you connect personal data to AI without supplier review, you are accepting a risk you may not have priced.

For most UK SMEs, the GDPR work around AI is not a huge legal transformation programme. It is a focused control exercise. The cost depends on how close the AI gets to sensitive data and decisions about people.

AI use caseGDPR work neededTypical external costTimeframe
AI for public research or generic copyAcceptable-use rules and staff guidance£500 to £1,5002 to 5 days
AI summarising internal documents with limited personal dataData map, lawful basis, supplier check, privacy note update£1,500 to £4,0001 to 2 weeks
AI connected to CRM, support, sales, email, or call notesDPIA screen, supplier review, access model, retention controls, staff training£3,000 to £8,0002 to 4 weeks
AI used for HR, finance, health, vulnerable customers, profiling, or automated decisionsFull DPIA, legal or DPO review, testing evidence, challenge process, audit logs£7,500 to £25,000+4 to 10 weeks

Those costs are separate from licences and build work. They cover the thinking that stops the implementation becoming a liability: data mapping, risk assessment, supplier questions, policy writing, approval gates, privacy updates, and staff rules.

The cheapest route is not always irresponsible. If AI never touches personal data, keep governance light. The expensive route is not always necessary either. But if AI can see customer history, employee records, complaints, financial information, or regulated data, spending nothing on GDPR preparation is false economy. The potential ICO fine is up to £17.5 million or 4% of annual global turnover, whichever is higher. For an SME, the more immediate risk is usually reputational damage, lost customer trust, contract breach, and a painful clean-up.

This does not apply in the same way if you are using AI only with public, anonymous, or dummy data. If your team asks AI to rewrite public website copy, draft ideas from product specifications, summarise a government report, or generate code using test data, GDPR risk is low. You still need confidentiality rules, but you probably do not need a full DPIA.

It also may not be the first problem to fix if your basic data hygiene is poor. If shared drives are chaotic, old exports sit everywhere, CRM permissions are too broad, and nobody knows which suppliers process customer records, fix that before obsessing over model choice. AI will amplify weak data controls.

There is also a point where you need specialist advice. If your AI use involves children, health, biometrics, criminal offence data, employee monitoring, financial vulnerability, automated rejection, credit, insurance, legal advice, regulated professional services, or large-scale profiling, do not rely on a general article. Involve your DPO, legal adviser, compliance lead, security lead, and the business owner of the process.

The practical line is this: if a customer, employee, or candidate could reasonably ask, "What has this AI system done with my data?", you need an answer before the system goes live.

Is This Right For You?

This applies if your AI tool can see personal data: customer emails, CRM notes, support tickets, employee records, call transcripts, chat logs, forms, proposals, invoices, behavioural data, or anything that could identify a living person.

It also applies if the AI does not store the data permanently. UK GDPR is triggered by processing, and processing includes collection, analysis, retrieval, generation, logging, disclosure, and deletion.

It does not really apply if you only use AI with genuinely anonymous information, public material, dummy data, or internal ideas that contain no personal or confidential information. Be strict about that word genuinely. Pseudonymised data can still be personal data if someone can be re-identified.

Frequently Asked Questions

Do I need to tell customers I am using AI?

Yes, if AI materially affects how you process their personal data. Your privacy notice should explain what data is used, why, who receives it, how long it is kept, and whether AI supports decisions about them. Use plain English, not vague wording about improving services.

Can I put customer data into ChatGPT, Claude, Gemini, or Copilot?

Only if the plan, contract, settings, retention policy, training controls, access permissions, and data processing terms are suitable for that data. Consumer-grade tools are usually inappropriate for customer or employee records. Enterprise tools can still be non-compliant if configured badly.

Do I need a DPIA for every AI tool?

No. You need a DPIA where the processing is likely to create high risk for individuals. However, you should run a DPIA screening check for any AI tool that processes personal data, especially if it involves profiling, sensitive data, employee data, large-scale processing, or decisions about people.

What happens if AI use breaches UK GDPR?

The ICO can investigate, issue enforcement notices, require changes, and impose fines of up to £17.5 million or 4% of annual global turnover, whichever is higher. For most SMEs, the bigger immediate damage is customer trust, contract risk, operational disruption, and the cost of remediation.

Is AI-generated content personal data?

Sometimes. If the output relates to an identifiable person, such as a customer profile, employee assessment, candidate ranking, complaint summary, or support recommendation, it can be personal data. The fact that AI generated it does not remove GDPR rights or accountability.

Can we rely on legitimate interests for business AI?

Often, but not automatically. You need a documented legitimate interests assessment showing the business purpose, why the processing is necessary, and why the individual's rights do not override your interest. For intrusive monitoring or significant decisions, legitimate interests may not be enough.

Does GDPR apply if the AI provider says it does not train on our data?

Yes. Training is only one issue. GDPR can still apply to prompts, source documents, outputs, logs, metadata, retention, access controls, support access, sub-processors, international transfers, and deletion rights.

What is the minimum safe starting point for a UK SME?

Create an AI tool register, ban personal data in unapproved tools, map data flows for approved tools, check supplier terms, run DPIA screening for personal-data use cases, update privacy information where needed, and train staff on what they can and cannot enter into AI systems.