Skip to content
AI in practice

GDPR and AI: what UK SMEs must check before deploying AI tools

Easy Insight Team ·

Before deploying an AI tool, a UK SME needs six answers: which tier staff use, whether the vendor trains on your data, who is controller and processor, whether a DPIA is needed, what people are told, and whether the tool decides anything about people on its own. UK GDPR applies in full; the 2026 changes mainly affect automated decisions.

This is not legal advice. It is the checklist we would want answered before an AI tool touched customer or employee data, built from ICO guidance and vendor terms as of September 2026. For health data, children, recruitment or credit decisions, take specialist advice too.

Why does this matter now?

Two reasons. AI tools arrive by the back door: someone pastes a customer email into a free chatbot, and personal data has left your control before anyone decided anything. And the law moved this year. The Data (Use and Access) Act 2025 amended UK GDPR in stages; the bulk of the changes, including the new automated decision-making rules, came into force on 5 February 2026, and the ICO says all of its data protection provisions were in force by 19 June 2026.

The six checks at a glance

Check The question to answer What "done" looks like
1. Tier Which version of the tool will staff actually use? A named business tier, with personal accounts ruled out for work data
2. Training and retention Does the vendor train on your inputs, and how long does it keep them? Written vendor terms that match what your privacy notice says
3. Roles and contract Is the vendor your processor, and is there a DPA? A signed or accepted data processing agreement on file
4. DPIA Is the processing likely to be high risk? A DPIA, or a written note of why one was not needed
5. Transparency Would a customer be surprised by how their data is used? An updated privacy notice and an "I'm an AI" line on chatbots
6. Automated decisions Does the tool decide anything about people on its own? Either a human makes the decision, or the Article 22C safeguards are in place

Which version of the tool are your staff using?

The check most SMEs miss: the same brand can have very different data terms depending on the plan. OpenAI's data controls page says personal-plan conversations escape training only when each user turns off "Improve the model for everyone", and even then thumbs-up or thumbs-down feedback can put a conversation into training. By default, content from ChatGPT Business or Enterprise workspaces is not used for training (as of September 2026).

Microsoft's Copilot privacy documentation says prompts, responses and Microsoft Graph data are not used to train foundation models, and Copilot only surfaces data a user can already view (updated August 2026). Copilot Chat's "enterprise data protection" is provided under Microsoft's Data Protection Addendum, with Microsoft acting as processor, and is marked by a green shield; web searches sent to Bing sit under separate terms, with Microsoft acting as an independent controller.

Our view: pick one business tier, pay for it, and make "no work data in personal AI accounts" a rule. An outright ban tends to push use onto personal accounts, the worst outcome.

Does the vendor train on your data, and where does it go?

Read the vendor's terms for training, retention and processing location, then check your privacy notice says the same. Details hide: Microsoft notes that Anthropic models used as a subprocessor are currently outside its EU Data Boundary, and OpenAI keeps API abuse-monitoring logs for up to 30 days by default, although API data is not used for training unless you opt in.

Is the vendor your processor?

Using a business AI service on your own data, you are normally the controller and the vendor your processor. The ICO's guidance on AI and data protection is more nuanced: roles depend on who decides what data is used and for what, and an organisation can be a controller for one phase and a processor for another.

UK GDPR requires a written contract with a processor. Microsoft and OpenAI both offer a data processing agreement for business use; free consumer accounts are a different relationship. Keep a copy of what you accepted.

Do you need a DPIA?

Probably. UK GDPR requires one before processing likely to result in a high risk to people, and the ICO's list includes "innovative technology" such as AI, combined with another risk factor such as evaluating people or sensitive data. Its AI guidance says AI involves high-risk processing in the vast majority of cases.

If you decide one is not needed, write down why. For one well-scoped tool it is a few pages, not a project; our 90-day implementation plan puts it in month one for that reason.

What do you need to tell people?

Your privacy notice must describe the processing, including AI tools that receive personal data. The simplest test is surprise: would a customer be surprised their email was summarised by a third-party AI model? If so, say it plainly. Chatbots should announce themselves at the start of the conversation; our AI customer service guide covers the chatbot-specific points.

The Act also added a new duty: the ICO's complaints guidance says every organisation must have a process for handling data protection complaints, with no exemptions.

What changed for automated decisions?

The old Article 22 largely prohibited solely automated decisions with legal or similarly significant effects. Articles 22A to 22D, in force since 5 February 2026, allow them on any lawful basis, except where special category data is involved.

The price of the new flexibility is safeguards. The ICO's draft automated decision-making guidance (published 31 March 2026; consultation closed 29 May 2026; not yet final as of September 2026) says you must let people receive information about decisions, make representations, obtain human intervention and contest the decision. Those safeguards must apply consistently: the draft is explicit that spot-checking an automated process does not meet the requirement.

For most SMEs the easy answer is design: let AI draft, sort and recommend, and keep a person making any decision about someone's job, money or access to a service. Take advice before building recruitment screening.

Where should you start?

Run the six checks on the AI tool your business already uses most. It usually takes an afternoon and produces three documents: a tool decision, a DPIA or a note of why none is needed, and a privacy notice update.

For the wider picture, our AI readiness assessment scores data and governance alongside the other eleven questions, and our AI strategy work starts with exactly this kind of inventory. The AI practice overview sets out how we scope the rest.

Sources (checked 29 September 2026): ICO DUAA overview (updated 19 June 2026); SI 2026/82 reg. 2; ICO AI and data protection guidance (under review); ICO DPIA guidance; ICO draft ADM guidance (31 March 2026); ICO complaints guidance (updated 8 May 2026); OpenAI data controls, business data and API data pages; Microsoft Learn Copilot privacy pages (August 2026).

Frequently asked questions

Can our staff put customer data into the free version of ChatGPT?

Not without a decision you can defend. On personal ChatGPT plans, conversations can be used to train OpenAI's models unless the "Improve the model for everyone" setting is turned off, and that setting sits with each user rather than with you. OpenAI says it does not train on content from ChatGPT Business or Enterprise workspaces by default. For personal data, a managed business tier is the defensible choice.

Did the Data (Use and Access) Act 2025 change the rules for AI?

Partly. The main UK GDPR amendments, including new Articles 22A to 22D on automated decision-making, came into force on 5 February 2026, and the ICO says all of the Act's data protection provisions were in force by 19 June 2026. The core duties on lawful basis, transparency, security and DPIAs did not go away, and the ICO's AI guidance is marked as under review.

Is the AI vendor the controller or the processor?

Usually the processor, with your business as the controller, when you use a business AI service on your own data for your own purposes. The ICO's guidance says roles depend on who decides what data is used and why, and can differ by phase. Check that the vendor offers a data processing agreement; Microsoft and OpenAI both do for their business tiers.

Do we have to tell customers we use AI?

If AI processes their personal data, yes: UK GDPR's transparency duty means your privacy notice must describe the processing, and a chatbot should say it is a chatbot at the start. For solely automated decisions with a significant effect, the safeguards in Article 22C also require you to give people information about those decisions.

Can an AI tool make decisions about people on its own?

Sometimes, but only with safeguards. Since February 2026 UK GDPR allows solely automated decisions with legal or similarly significant effects on any lawful basis, except where special category data is involved. You must let people get information, make representations, obtain human intervention and contest the decision, and apply those safeguards every time, not by spot check.


Easy Insight is a UK consultancy for AI, web, apps and data — senior specialists only, no juniors.

Next step

Wondering where AI would actually pay in your business?

An AI strategy and readiness review (from £2,500) tells you where AI pays, where it doesn't, and what to leave alone. The price is fixed in writing before we start, and the advice comes from a team that runs AI in its own products.

Keep reading