The short answer
It can be, if you use the right kind of account, have a lawful reason to use the data that way, and put a few basic safeguards in place. It isn't safe when staff paste customer details into whichever free AI tool they like, and nobody knows what's been shared or where it went.
This is a practical guide, not legal advice. If you handle sensitive data at scale, such as health records, financial details or anything about children, talk to a data protection specialist before you roll anything out.
UK GDPR has no AI exemption
Putting personal data into an AI tool is processing it, and the usual rules apply. You need a lawful basis for using the data that way. You need to be open with people about how their data is used. You should use only as much as the task needs. And you stay responsible for it, even when someone else's software is doing the work.
The Information Commissioner's Office publishes detailed guidance on AI and data protection, and it's worth reading if you're planning anything beyond everyday drafting. The principles aren't new. What's new is how easy AI makes it to move a lot of data somewhere without thinking about it.
Free accounts and business accounts are not the same
This is the distinction most people miss. AI providers usually treat data from personal accounts differently from data in their business products.
Take OpenAI as an example. It states that, by default, it doesn't use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu or its API platform to train its models. On personal accounts, conversations can be used to improve models unless the user turns that off in their data controls. Business products also come with a data processing agreement, which UK GDPR expects you to have whenever a supplier processes personal data on your behalf.
Other providers draw similar lines between personal and business terms, though the details differ and they change. Read the current terms for the tool you use, and look again when the provider updates them.
What should never go into a free AI tool
Even on a business account, ask whether the task needs the personal details at all. Usually it doesn't. 'Draft a polite reply to a customer whose delivery is late' works just as well without the customer's name and address. On a free personal account, keep all of the following out:
- Customer names with contact details, account numbers or order histories
- Anything about health, finances, criminal records or other special category data
- Employee records, payroll, appraisal notes or grievance details
- Contracts, tenders or anything covered by a confidentiality agreement
- Passwords, API keys, or screenshots that happen to contain them
A one-page policy that covers most of the risk
You don't need a thick document. A single page, shared with everyone and actually read, should cover the points below. Then add a line to your privacy notice explaining that you use AI tools to help with tasks such as drafting correspondence, and update your record of processing activities if you keep one.
- Which AI tools are approved, and that they're used through the company's business account
- What must never be pasted in, with examples
- That personal details are removed first wherever the task allows
- That a person checks anything AI-written before it reaches a customer
- Who to ask when someone isn't sure
When you need to do more
Everyday drafting and summarising with de-identified content on a business account is low risk. The picture changes when AI starts making or shaping decisions about people, such as screening job applicants, assessing credit or deciding which customers get priority, or when you connect it straight into databases full of personal data.
Uses like those may need a Data Protection Impact Assessment before you start, and people have specific rights where decisions about them are made by automated means. If you're heading that way, design privacy in from the start rather than bolting it on afterwards.
Where to start this week
Find out which AI tools people already use. Ask openly and make it clear nobody's in trouble, because you'll get a more honest answer. Move the useful ones onto business accounts, write your one-page policy and explain to the team why it matters. Those steps deal with most of the risk, and people keep the time savings they've already found.
Is ChatGPT GDPR compliant?
No tool is compliant on its own. Compliance depends on how you use it. A business account with a data processing agreement, a lawful basis, openness with the people concerned and sensible limits on what goes in puts you in a far stronger position than a free personal account.
Does ChatGPT keep what I type?
Conversations are stored in your account history, and how long they're kept depends on the product and your settings. Business products generally give administrators more control. Check the current settings and terms for the account you're using.
Do I have to tell customers we use AI?
If AI tools process their personal data, your privacy notice should explain that in plain terms. There's no general UK requirement to label every email that AI helped you draft, but you do need to be open about how personal data is used.
Want AI in your business without the data headaches?
We help teams choose tools, set sensible rules and build AI into their workflows with privacy designed in from the start. It's a free, no-pressure consultation, and we never chase you afterwards.