Decode & Grow

GDPR and AI: How to Use ChatGPT Without Breaching Data Protection

Short answer: Using an AI tool on personal data makes the vendor your processor, which requires a data processing agreement, a lawful basis, coverage in your privacy notice, and an assessment of international transfers. The practical rules: use business or enterprise tiers that exclude your data from training, don't enter special category data, minimise what you input, and keep an AI use register.

General information, not legal advice.

When AI use engages data protection law

The moment personal data goes into the tool. That includes far more than obvious cases: a client email pasted in for summarising, a CV run through a screening prompt, meeting notes containing attendee names, a customer complaint drafted into a reply. All of it is processing of personal data, and all of it needs a basis.

Using an AI tool on entirely non-personal material — drafting generic marketing copy, explaining a concept, writing code — doesn't engage UK GDPR at all.

The five requirements

1. A lawful basis. Usually legitimate interests for internal business use, with a legitimate interests assessment documenting the balancing exercise. Consent is rarely the right basis for staff-operated tools, because it's difficult to make it freely given and easy to withdraw in that context.

2. A data processing agreement. The AI vendor processes personal data on your instructions, making them a processor. Article 28 requires a written contract with specified terms. Major providers offer a DPA on business tiers — you need to actually accept it, which is often a separate step people miss.

3. Transparency. Your privacy notice must reflect that AI tools are used in processing and identify the categories of recipient. A notice that predates your AI adoption is out of date.

4. International transfers. Most major AI providers process outside the UK. That requires a transfer mechanism — typically the UK addendum to the EU standard contractual clauses, plus a transfer risk assessment. Some providers offer UK or EU processing regions on higher tiers, which simplifies this considerably.

5. Data minimisation. Only input what's necessary. Redacting names and identifiers before pasting a document is often trivial and materially reduces your exposure.

The consumer versus business tier distinction

The single most consequential practical point. Consumer tiers of major AI tools have historically used inputs to improve models by default, with opt-outs of varying accessibility. Business and enterprise tiers generally exclude customer data from training by contract, and provide a DPA.

If your team is using free or personal accounts for work involving client data, you likely have both a contractual and a compliance problem. Moving to a business tier fixes most of it and is usually the highest-value single action available.

What should never go in

  • Special category data — health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation. Higher bar under Article 9, and rarely justifiable for convenience use.
  • Criminal offence data.
  • Children's data, without a careful assessment.
  • Client confidential information covered by an NDA that doesn't permit third-party processing.
  • Credentials and access tokens.

Do you need a DPIA?

A data protection impact assessment is required for processing likely to result in high risk to individuals. Routine internal use of AI for drafting and summarising generally doesn't meet that bar. You likely do need one for AI involved in decisions about people — recruitment screening, credit or eligibility assessment, performance evaluation — or for large-scale processing of sensitive data. Those are also the uses most likely to attract high-risk obligations under the EU AI Act.

The practical checklist

  1. Register every AI tool in use, including unapproved ones.
  2. Move client-data work onto business tiers with DPAs in place.
  3. Add AI processors to your record of processing activities.
  4. Update your privacy notice.
  5. Complete transfer risk assessments for non-UK processing.
  6. Write data rules into your AI usage policy and train the team.
  7. Review at least annually.

Frequently asked questions

Can we use AI on client data at all?

Yes, with the right basis, agreements and controls. Check your client contracts too — some prohibit third-party processing or require notification.

What if an employee already pasted client data into a free account?

Assess whether it's a reportable breach, document the assessment, and fix the underlying cause — which is usually that the compliant tool was harder to access than the non-compliant one.

Does the ICO have guidance on this?

Yes, and it's been expanding. Check the current guidance rather than relying on any secondary summary, including this one.

We handle GDPR and AI Act compliance together, because they overlap. See our compliance work.

2026-07-04 22:00 Compliance