Compliance
UK GDPR and AI: A Practical Compliance Checklist for Small Businesses
A practical UK GDPR checklist for using AI tools in a small business: lawful basis, DPIAs, supplier checks, staff policies, transparency and the Data (Use and Access) Act 2025.
Quick answer
To use AI tools lawfully under UK GDPR, a small business should: identify what personal data goes into each tool, choose business plans that don't train on your data, sign the vendor's data processing agreement, check international transfer safeguards, carry out a DPIA for higher-risk uses, update your privacy notice, and give staff a short AI policy. The ICO's AI guidance is the authoritative reference.
Key takeaways
- Treat every AI tool as a data processor that needs checking like any other supplier.
- Business plans usually exclude your data from model training; consumer plans may not.
- A DPIA is required for high-risk processing — for example, using AI to make decisions about people.
- A one-page AI policy prevents most staff mistakes.
The 10-point AI compliance checklist
- Map the data. For each AI tool, list what personal data may go in (customers, staff, suppliers).
- Pick business plans. Prefer tiers where the vendor does not train on your content by default.
- Sign the DPA. Make sure a data processing agreement is in place and saved.
- Check transfers. Where is data stored? Are UK transfer safeguards (such as the IDTA or UK Addendum) in place?
- Lawful basis. Confirm your lawful basis for the processing — often legitimate interests, backed by a short assessment.
- DPIA for high risk. Carry out a Data Protection Impact Assessment where AI makes or informs significant decisions about people.
- Be transparent. Update your privacy notice to mention AI tools and their purposes.
- Human oversight. Keep a person reviewing outputs that affect customers or staff.
- Staff policy. Publish a one-page AI policy: approved tools, forbidden data, review rules.
- Review annually. AI terms change quickly — diarise a yearly supplier review.
The Data (Use and Access) Act 2025
The Data (Use and Access) Act 2025 amends parts of UK GDPR and the Data Protection Act 2018, including rules on automated decision-making and recognised legitimate interests. Many provisions commence in stages, so check the ICO's guidance for what is in force when you read this. The core principles — transparency, fairness, security and accountability — remain.
A simple AI policy you can adapt
Staff may use approved AI tools (listed below) for drafting, summarising and research. Do not enter special category data, payment details, passwords or confidential client information unless the tool is approved for it. You are responsible for checking AI output before it is sent or published. Report any mistakes or data incidents to [name] immediately.
Frequently asked questions
Do I need a DPIA to use ChatGPT or Claude?
Can employees use AI tools at work?
Where can I find official guidance on AI and data protection?
SmarterBiz Editorial Team
Our editors test AI and business software against the realities of running a UK small business: sterling pricing and VAT, UK GDPR, HMRC's Making Tax Digital rules and British English output.