Skip to main content

AI and GDPR for UK Small Businesses: A Plain-English Guide

What UK GDPR means when your business uses AI tools: personal data, choosing suppliers, call recording, the new complaints duty and a one-page AI policy you can copy.

A grey filing cabinet with a padlock beside a desk lamp and a laptop in a small office at night
AI-generated illustration by Apex Automate.

Yes, a UK small business can use AI tools and stay within GDPR. The rules that matter are the ones you already follow for customer data: know what personal data goes in, use suppliers with proper data processing terms, tell people what you do, and keep a person accountable for decisions that affect them. This guide covers AI and GDPR for small business owners in the UK in plain English, including what changed in 2026.

This is general information, not legal advice

We build AI systems for UK service businesses, but we are not solicitors. Use this guide to ask better questions, and take specific advice if you handle high-risk data.

AI and GDPR for UK small businesses: the short version

AI is now normal in small firms. The ONS found 29% of UK businesses used at least one AI technology in June 2026, and the FSB's Confidence Code report (July 2026) found 55% of small firms use AI, with 92% still having concerns such as data security.

Those concerns are sensible, but they rarely mean avoiding AI. In our experience most of the risk sits in three places: customer details pasted into free tools, AI that acts without anyone checking, and supplier terms nobody has read.

  • Know your data. List your AI tools and the personal data each one sees.
  • Check the supplier. Use business plans with proper data terms.
  • Tell people. Cover AI, call recording and automated replies in your privacy notice.
  • Keep a person in charge. Humans decide anything with a real effect on someone.
  • Have a complaints route. Required since 19 June 2026.

What counts as personal data in AI tools

Personal data is anything that identifies a living person, directly or indirectly. In AI tools that is broader than most owners expect: an email signature, a photo showing a house number, a call recording, or a note saying 'Mrs Patel at number 14, worried about cost' all count.

Health information, details about children and anything about vulnerability should not go into general AI tools at all, unless a system has been designed for it with proper controls.

Common AI uses in a service business and the personal data involved
AI usePersonal data involvedMain question to ask
Drafting emails in ChatGPT or ClaudeWhatever you paste in: names, addresses, job detailsIs this a business plan that does not train on our data?
AI receptionist or call answeringVoice, phone number, call contentDo callers know they are speaking to AI and being recorded?
Email triage on a shared inboxEvery email that arrivesWhere is the data stored, and what does the AI see?
Call or meeting transcriptionEveryone on the callHas everyone been told, and how long is the transcript kept?

One habit helps more than any policy: before pasting anything into an AI tool, remove the details the task does not need.

Choosing AI tools: data terms and where data is stored

When you use an AI tool for business data, the supplier usually acts as your processor, and UK GDPR expects a written contract with processors, usually a data processing agreement (DPA). Free and personal plans often sit under consumer terms instead, so the plan matters more than the brand.

Is ChatGPT GDPR compliant in the UK?

No tool is compliant on its own: what matters is how you use it. OpenAI states that by default it does not use data from ChatGPT Business, ChatGPT Enterprise or its API platform for training. Personal accounts have different terms, so keep customer data out of them. The same applies to Claude, Gemini and Copilot: use a business plan and read the data terms.

Where the data is stored

UK hosting is a preference, not a legal requirement. UK GDPR allows personal data to go abroad if the destination is covered by adequacy regulations or the transfer has appropriate safeguards, such as the International Data Transfer Agreement or the UK Addendum. The ICO's international transfers guidance explains the options. What you do need is to know where data goes and to confirm the supplier has the right mechanism in place.

Some suppliers offer a choice: OpenAI says eligible Enterprise and API customers can store certain content at rest in the UK. When we control a build, we usually choose UK or EU hosting because it is simpler to explain to customers, not because the law insists on it.

  • Is there a DPA for our plan, and have we accepted it?
  • Is our data used to train models, and can we turn that off?
  • Where is data stored and processed, and what transfer safeguards apply?
  • How long are prompts, files and logs kept, and can we delete them?

AI receptionists and call recording

AI receptionists answer calls, take details and book jobs. They raise two data protection points that owners often skip.

First, transparency. Callers should know early in the call that they are speaking to an automated assistant and whether the call is recorded or transcribed. A short line in the greeting does this, backed by a fuller explanation in your privacy notice. The ICO's guidance on the right to be informed sets out what people must be told.

Second, retention. Recordings and transcripts are personal data, so decide how long you keep them and who can listen back. Many firms only need the summary, not the audio.

If the AI makes decisions with a real effect on someone, such as refusing a booking, you are into automated decision-making. The Data (Use and Access) Act 2025 relaxed some of these rules, but safeguards still apply, and the ICO consulted on new guidance between March and May 2026. The simplest approach is to let AI gather information and a person make the decisions.

What changed under the Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 updated UK GDPR rather than replacing it. Changes arrived in stages, with the main data protection changes due from February 2026 under the government's commencement plan. The ICO confirmed that all outstanding provisions were in force from 19 June 2026.

For a small business, the changes worth knowing are:

  • A complaints process is now required. You must give people a clear way to raise a data protection complaint, acknowledge it within 30 days, investigate, and tell them the outcome, as the ICO set out in May 2026. The ICO says this applies to all organisations.
  • Subject access requests. You only have to make reasonable and proportionate searches when someone asks for their personal information.
  • Automated decisions. The Act opens up a wider range of lawful bases for significant automated decisions, as long as safeguards are in place, including a way for people to challenge the decision and have a person look at it.

If AI handles your inbound email, it needs to recognise a data protection complaint and route it to a person quickly, so the 30-day deadline is never missed.

A one-page AI policy for your small business

You do not need a 40-page framework. The ICO's own internal AI use policy, effective from August 2025, rests on ideas a small firm can copy: use approved tools only, have a person review outputs, be open about AI use and protect personal data. Here is a one-page version you can adapt.

  1. Approved tools. List the AI tools and plans staff may use with customer data.
  2. What never goes in. Bank details, passwords, health information, children's details and anything about vulnerability.
  3. Minimise first. Remove names and addresses the task does not need.
  4. A person checks. Anything sent to a customer, or any decision about a customer, is reviewed by a named person first, unless it is a pre-approved automated reply.
  5. Be open. Your privacy notice says which kinds of AI you use, and callers are told when they are speaking to an automated assistant.
  6. Keep records. Note which systems process personal data, where it is stored and for how long.
  7. Complaints and requests. Data protection complaints and access requests go to a named person, with complaints acknowledged within 30 days.
  8. Review. Look at the policy every six months, or whenever you add a new tool.

What privacy by design looks like in practice

Our email triage build for The PE Specialists, a school sport and holiday camp provider in London and Essex, is a useful example. Every email to their shared parent inbox is classified, then answered from approved facts, drafted for approval, or passed to a person.

Two design choices did most of the data protection work. Sensitive messages go to a person before any AI step, so the model never processes them, and the data sits in a London-region database. A daily report shows what was sent and what was held. More on our work page.

When it is worth getting help (and when it is not)

If you only use ChatGPT or Claude for marketing copy or quotes without customer details, you probably need no outside help. A business plan, the policy above and a line in your privacy notice will cover most of it.

Help is worth having when AI will touch customer data automatically: inbox triage, call answering, CRM updates, or anything involving children, health or vulnerable people. The ICO's DPIA guidance says innovative technology, including AI, can trigger the need for a data protection impact assessment. Its wider guidance on AI and data protection is worth a skim too.

Our AI assessment costs £495, credited in full against your first build, and flags the data protection points before any money goes on building. Or start with a free 30-minute discovery call.

Frequently asked questions

Does my AI data have to be stored in the UK?

No. UK GDPR does not require UK hosting. Personal data can go abroad when the destination is covered by UK adequacy regulations or appropriate safeguards are in place, such as the International Data Transfer Agreement. You do need to know where your data goes and check your supplier has the right mechanism. Many firms still prefer UK or EU hosting because it is simpler to explain.

Do I need to tell customers I use AI?

You need to be transparent about how you use personal data, including in AI tools. In practice that means a clear line in your privacy notice, and telling callers or chat users when they are dealing with an automated assistant or being recorded. You do not need to label every email drafted with AI help, but be honest if asked.

Can my staff use free ChatGPT for customer emails?

We would advise against putting customer details into free or personal AI accounts. They sit under consumer terms rather than a business data processing agreement, and their settings vary. Give staff an approved business plan instead, and teach them to remove names, addresses and other details the task does not need. That one change removes most of the everyday risk.

Do I need a DPIA before using AI?

Not always. A DPIA is required when processing is likely to result in high risk, and the ICO says innovative technology such as AI can be a trigger, especially alongside sensitive data. Drafting marketing text rarely needs one. An AI system that reads every customer email or answers calls usually deserves at least a short written assessment.

Want AI without the data headaches?

Book a free 30-minute call. We will look at what you want to automate and flag the data protection points before anything is built.

Book my free call

Sources

  1. ONS, Business insights and impact on the UK economy, 2 July 2026
  2. FSB, The Confidence Code: AI and small firms (July 2026)
  3. OpenAI, Business data privacy, security and compliance
  4. ICO, International transfers guidance
  5. ICO, The right to be informed
  6. ICO, The Data (Use and Access) Act 2025: what does it mean for organisations?
  7. ICO, Consultation on draft guidance about automated decision-making (March to May 2026)
  8. GOV.UK, Data (Use and Access) Act 2025: plans for commencement
  9. ICO, New data protection complaints law now in force (23 June 2026)
  10. ICO, One month to go: what businesses need to know to meet new data law (19 May 2026)
  11. ICO, Internal AI use policy (effective August 2025)
  12. ICO, When do we need to do a DPIA?
  13. ICO, Guidance on AI and data protection

Freddie, Founder of Apex Automate

Freddie founded Apex Automate in Braintree, Essex, to help businesses of every kind put AI and automation to practical use. He designs and builds the systems himself, from inbox triage and AI receptionists to CRM and job-software integrations.