Guide · 5 min read · Stan Hunter
Using AI with customer data: the UK GDPR basics
The handful of rules a small business needs to follow before pasting anything about a customer into an AI tool.
This is a practical guide, not legal advice. It covers the rules that come up most often when a small business starts using AI with customer information.
The core idea
Customer data is still customer data when it goes into an AI tool. You need a reason to process it, you must keep it secure, and you must not send it somewhere that uses it for its own purposes without telling the customer.
Four practical rules
- Use business accounts, not free personal ones. Paid tiers of Claude and ChatGPT do not train on your data; free consumer tiers may.
- Do not paste more than the task needs. A complaint reply needs the complaint, not the customer's date of birth.
- Say what you use in your privacy notice. One sentence is enough.
- Write a one-page policy for staff so everyone follows the same rules.
Special categories
Health, financial and legal information carry extra weight. Clinics, solicitors and accountants should keep that data inside tools with a proper data processing agreement, such as Microsoft 365 Copilot or an enterprise AI account.
If you want it checked
A usage policy is included in the AI readiness audit, and a team workshop covers the rules with staff in an hour.