UK GDPR does not have an AI exemption. Everything it says about personal data applies in exactly the same way when the processing happens inside a prompt box, and the fact that it feels like typing into a search engine changes nothing at all.

This is the practical version. What actually applies, what you need to have written down and the specific data that should never go near an AI tool regardless of which plan you are on.

The moment UK GDPR engages

It engages as soon as a prompt contains information about an identifiable living person. That is a lower bar than most people assume.

Draft a reply to this complaint from Mrs Hendry about the delayed delivery to her home address is processing personal data. So is pasting in a CV, a customer email thread, a list of attendees or a spreadsheet with a name column. The tool does not need to store it for the processing to have happened.

Which lawful basis

For most business use, legitimate interests. You have a genuine business need, the processing is a reasonable expectation in the context and the impact on the individual is low. Document the reasoning once in a legitimate interests assessment covering AI-assisted drafting and analysis, and you have covered the routine cases.

Consent is rarely the right basis and is often actively unhelpful, because it must be freely given and withdrawable, and neither is realistic for an internal tool your staff use to do their jobs.

Where the processing has real consequences for a person — screening applicants, scoring customers, monitoring employees — legitimate interests is much harder to sustain and you are into policy territory that needs proper thought rather than a paragraph.

The plan tier is the compliance boundary

This is the single most important practical point in this article, and it is the one businesses most often get wrong.

Consumer and free tiers of AI services generally reserve the right to use your inputs to improve their models, and offer you no meaningful contract. Business and enterprise tiers of Microsoft 365 Copilot, ChatGPT Business and Claude for Work contractually exclude your content from training, act as processors under your instructions and provide the data processing agreement you need to have on file.

The brand on the tool tells you almost nothing about whether it is safe to use. The plan tier tells you nearly everything.

Before approving a tool, get three documents: the data processing agreement, the statement on training and the sub-processor list. If a supplier cannot produce all three quickly, that is the answer.

International transfers

Most major AI providers process data outside the UK. That is a restricted transfer and it needs a mechanism.

In practice the mainstream business services provide this through the UK Addendum to the EU Standard Contractual Clauses, or through the UK Extension to the EU-US Data Privacy Framework. Both are legitimate. What matters is that the supplier names one, and that you have recorded which one in your records of processing.

Where data residency genuinely matters to you or to a client contract, Microsoft's EU and UK data boundary commitments for Microsoft 365 are usually the easiest route to a defensible answer, which is one reason regulated clients tend to consolidate on the Microsoft estate rather than assembling a stack of separate tools.

When you need a DPIA

A Data Protection Impact Assessment is required where processing is likely to result in a high risk to individuals. The ICO's own guidance points at systematic evaluation, automated decision-making with legal or similarly significant effects, large-scale processing of special category data and monitoring of individuals.

Applying that honestly:

  • Almost certainly needs a DPIA — AI sifting job applications, scoring or profiling customers, monitoring staff productivity or communications, anything processing health data.
  • Usually does not — drafting assistance, summarising internal documents, meeting notes for internal meetings, extracting data from your own supplier invoices.
  • Judgement call — customer-facing chatbots, automated triage that affects how quickly somebody is helped, transcription of external calls.

A DPIA is not a punishment. It is a two-page document that makes you write down what could go wrong, and it is the thing you will be extremely glad to have if anybody ever asks.

What your privacy notice must say

If AI touches personal data you hold, your privacy notice needs to reflect it. In practice one short paragraph covering what you use AI for, the categories of data involved, your lawful basis, whether any of it leaves the UK and how somebody objects.

You do not need to name every product. You do need to be accurate about the categories of processing, because a privacy notice that describes a business you stopped being two years ago is the thing that turns a minor incident into a serious one.

The never list

Regardless of plan tier, keep these out of general AI tools unless you have specifically assessed that use case and documented it:

  • Special category data — health, ethnicity, religion, sexual orientation, political opinions, trade union membership, genetic and biometric data.
  • Criminal offence data — including DBS check outcomes and disciplinary matters that touch on allegations.
  • Children's data.
  • Credentials, card numbers and bank details. Not a GDPR point so much as a basic security one.
  • NDA-covered material that identifies the counterparty. Your contractual obligations are separate from and often stricter than data protection law.
  • Anything a client contract restricts to named systems or named jurisdictions.

Getting this to a defensible position

For most small businesses the whole job is: one legitimate interests assessment, a one-page acceptable use policy, three supplier documents on file, one paragraph added to the privacy notice and a DPIA for anything in the high-risk list. That is an afternoon of work, not a project.

What takes longer is the technical side — making sure the tools staff can actually reach are the approved ones, that data is not syncing somewhere unassessed and that retention is enforced rather than aspirational. That is where our security solutions and IT consultancy teams spend most of their time. Get in touch if you would like the technical controls to match what your policy already promises.