Governance

AI and your data: what UK businesses need to know

Straightforward guidance on using AI without breaching UK GDPR, and the questions to put to any supplier before you sign anything.

Moonfleck · 24 March 2026 · 7 min read

This is not legal advice, and if you handle sensitive personal data you should take some. But there is a body of practical knowledge here that is not complicated, and being aware of it will save you a great deal of trouble.

The thing that goes wrong most often

An employee pastes something into a free public AI tool. A customer list. A draft contract. A spreadsheet of staff salaries. They are trying to be productive and they have no idea they have just transferred personal data to a third party, possibly outside the UK, with no lawful basis and no record of it happening.

This is by far the most common AI-related data incident in smaller businesses, and it is entirely preventable with a one-page policy and a ten-minute conversation.

What UK GDPR actually requires

The principles have not changed because the technology did. If you process personal data with AI, you still need:

A lawful basis. Usually legitimate interests or contract. Write it down before you start, not after somebody asks.

Transparency. People must know their data is being processed and, broadly, how. If an AI agent is handling their enquiry, say so.

Data minimisation. Only send the AI what it needs. An agent answering a delivery question does not need the customer's full order history.

Purpose limitation. Data collected for one reason cannot be quietly repurposed to train something else.

Security. Appropriate technical and organisational measures, which now includes thinking about what your AI supplier does with the data.

Questions to ask any supplier

Before you sign anything, get written answers to these.

Is our data used to train your models, or anyone else's? The answer you want is no, and it should be in the contract rather than the marketing page.

Where is our data processed and stored? UK or EU is straightforward. Elsewhere requires a transfer mechanism and a look at whether you are comfortable.

How long is it retained? "Indefinitely" is not an acceptable answer.

Can we delete it on request, and how quickly? You have obligations to your customers that you cannot meet if your supplier cannot meet them to you.

Who at your company can see it? There should be a real access control answer here.

What happens to our data if we leave? You want export and deletion, in writing.

Practical safeguards that are not difficult

Write a one-page acceptable use policy naming which AI tools are approved and what must never be pasted into any of them. Circulate it. That single document prevents most incidents.

Use business accounts rather than free consumer tools. Business tiers generally come with contractual commitments that free tiers do not.

Keep a simple record of which AI systems process personal data and why. If you already maintain a record of processing activities, add them there.

Do a data protection impact assessment for anything involving significant automated decisions about individuals. It is less onerous than it sounds and it makes you think clearly.

Keep a human in the loop for any decision that materially affects a person. This is both good practice and, in some circumstances, a legal requirement.

The reassuring part

None of this is a reason not to adopt AI. Handled sensibly, an AI system with proper access controls and audit logging is frequently more compliant than the spreadsheet emailed around the office that it replaces.

The risk is not AI. The risk is AI adopted casually, without anybody writing anything down.

Want this applied to your business?

A free half-hour conversation, and an honest answer about whether any of this is worth doing for you.

Book a call