Skip to content

Compliance

UK GDPR and AI: A Practical Compliance Checklist for Small Businesses

A practical UK GDPR checklist for using AI tools in a small business: lawful basis, DPIAs, supplier checks, staff policies, transparency and the Data (Use and Access) Act 2025.

SmarterBiz Editorial TeamUK SME Technology DeskUpdated 3 min read

Quick answer

To use AI tools lawfully under UK GDPR, a small business should: identify what personal data goes into each tool, choose business plans that don't train on your data, sign the vendor's data processing agreement, check international transfer safeguards, carry out a DPIA for higher-risk uses, update your privacy notice, and give staff a short AI policy. The ICO's AI guidance is the authoritative reference.

Key takeaways

  • Treat every AI tool as a data processor that needs checking like any other supplier.
  • Business plans usually exclude your data from model training; consumer plans may not.
  • A DPIA is required for high-risk processing — for example, using AI to make decisions about people.
  • A one-page AI policy prevents most staff mistakes.

The 10-point AI compliance checklist

  1. Map the data. For each AI tool, list what personal data may go in (customers, staff, suppliers).
  2. Pick business plans. Prefer tiers where the vendor does not train on your content by default.
  3. Sign the DPA. Make sure a data processing agreement is in place and saved.
  4. Check transfers. Where is data stored? Are UK transfer safeguards (such as the IDTA or UK Addendum) in place?
  5. Lawful basis. Confirm your lawful basis for the processing — often legitimate interests, backed by a short assessment.
  6. DPIA for high risk. Carry out a Data Protection Impact Assessment where AI makes or informs significant decisions about people.
  7. Be transparent. Update your privacy notice to mention AI tools and their purposes.
  8. Human oversight. Keep a person reviewing outputs that affect customers or staff.
  9. Staff policy. Publish a one-page AI policy: approved tools, forbidden data, review rules.
  10. Review annually. AI terms change quickly — diarise a yearly supplier review.

The Data (Use and Access) Act 2025

The Data (Use and Access) Act 2025 amends parts of UK GDPR and the Data Protection Act 2018, including rules on automated decision-making and recognised legitimate interests. Many provisions commence in stages, so check the ICO's guidance for what is in force when you read this. The core principles — transparency, fairness, security and accountability — remain.

A simple AI policy you can adapt

Staff may use approved AI tools (listed below) for drafting, summarising and research. Do not enter special category data, payment details, passwords or confidential client information unless the tool is approved for it. You are responsible for checking AI output before it is sent or published. Report any mistakes or data incidents to [name] immediately.

Frequently asked questions

Do I need a DPIA to use ChatGPT or Claude?

Not always. Everyday drafting with no or minimal personal data is usually low risk. A DPIA is required where processing is likely to result in high risk — for example, using AI to screen job applicants or make decisions about customers.

Can employees use AI tools at work?

Yes, with a clear AI policy that lists approved tools, sets out what data must never be entered, and requires human review of outputs.

Where can I find official guidance on AI and data protection?

The Information Commissioner's Office (ICO) publishes guidance on AI and data protection at ico.org.uk, including an AI and data protection risk toolkit.

SmarterBiz Editorial Team

Our editors test AI and business software against the realities of running a UK small business: sterling pricing and VAT, UK GDPR, HMRC's Making Tax Digital rules and British English output.

How we test · Report a correction

Keep reading