If the GDPR applies to you, for example because you have customers in the EU, treat each AI tool like any other supplier handling personal data: know what goes in, have a lawful basis, use a plan with a data processing agreement, switch off model training, set retention, update your privacy notice, and assess high-risk uses first.
None of this is exotic. It's the same GDPR you already apply to your email provider and accounting software. What's genuinely new with AI comes down to four things: vendors that want to use your data to train their models, outputs about people that can be confidently wrong, decisions about people that could be made automatically, and a technology that the law treats as a reason to assess risk before you start. This tutorial is general information, not legal advice; where a step depends on your circumstances, it says when to ask a data-protection adviser.
Where AI tools fit into the GDPR you already follow
Under the GDPR you are usually the controller: you decide why and how your customers' data is used. A supplier that handles that data on your instructions is a processor, and the law requires a contract with it (Article 28) setting out what it may and may not do. Your email host, payroll software and cloud storage are processors. So is an AI tool, when it's on the right plan.
That's the crux. Business plans of the major AI tools are set up to act as processors: they come with a data processing agreement, and they don't use your content to train their models by default. Consumer plans are different. The vendor sets the terms through its own privacy policy, training may be switched on, and there's no processor contract for you to rely on. That's why the single most important GDPR decision about AI is often not a setting but a plan: client data belongs on a business account.
Step 1: Map what personal data goes into which tool
You can't protect data you haven't listed. Spend an hour writing down each AI use, the tool, and what personal data it touches. Here's the map a four-clinician podiatry clinic produced (illustrative):
| Use | Tool and plan | Personal data | Health data? |
|---|---|---|---|
| Drafting replies to booking enquiries | ChatGPT Business | Names, contact details, appointment preferences | Sometimes, if patients describe symptoms |
| Summarising clinical notes into referral letters | Proposed, not yet approved | Full clinical history | Yes |
| Website FAQ chatbot | Chatbot builder, paid plan | Whatever visitors type | Possibly |
| Marketing posts and newsletters | Canva, ChatGPT Business | None | No |
| Staff rota drafts | Microsoft Copilot Chat | Staff names and availability | No |
The map immediately shows where the effort belongs. Marketing has no personal data and needs almost nothing. The referral letters involve health data, which the GDPR treats as a special category, and they're the use to hold back until the later steps are done. If you employ fewer than 250 people, the formal record of processing activities (Article 30) may not apply to you, but the exemption falls away when processing isn't occasional, is likely to result in a risk, or includes special categories such as health data, so most clinics using AI regularly should keep this map as their record.
Step 2: A lawful basis for each use
Every use of personal data needs one of the lawful bases in Article 6. For most business AI uses the candidates are:
- Contract: using a customer's details to deliver what they asked for, such as drafting a reply to their booking enquiry.
- Legitimate interests: using data for a reasonable business purpose people would expect, such as summarising your own sales enquiries. This needs a short, written balancing test showing your interest isn't overridden by theirs.
- Legal obligation: rarely the basis for AI use itself, but relevant when AI helps you keep records you're required to keep.
- Consent: sometimes appropriate, but hard to rely on for routine processing because people must be able to withdraw it.
Health data needs more. Alongside an Article 6 basis, special-category data needs an Article 9 condition, such as the one covering the provision of health care by professionals bound by confidentiality. The podiatry clinic's referral-letter idea sits squarely here, which is why it's the use to take to a data-protection adviser before switching on. The booking replies are simpler: contract, or legitimate interests, with a note that patients sometimes volunteer symptoms and the reply template shouldn't repeat them.
If you rely on legitimate interests, write the balancing test down; it needn't be long. The clinic's version for booking replies:
| Question | Answer |
|---|---|
| What's the purpose? | Replying to booking enquiries faster and more consistently |
| Is AI necessary for it? | Not strictly, but it cuts reply time from hours to minutes, and only the enquiry text is used |
| Would patients expect it? | Yes: they asked for a reply, and the privacy notice says AI helps draft messages |
| What protects them? | A business plan under a DPA, no model training, staff review of every reply, symptoms never repeated |
| Outcome | Proceed; review in six months or if the tool or its terms change |
Step 3: Get the data processing agreement, and read what it covers
Each major vendor offers a data processing agreement (DPA) for its business products, and each draws the line somewhere slightly different:
| Vendor | What the DPA covers | What it doesn't |
|---|---|---|
| OpenAI | ChatGPT Business, ChatGPT Enterprise and the API | Personal Free, Go, Plus and Pro accounts |
| Anthropic | Commercial products such as Claude for Work (Team, Enterprise) and the API; the DPA, with standard contractual clauses, is built into the Commercial Terms | Claude Free, Pro and Max |
| Google Workspace, including Gemini and Gemini Notebook on qualifying editions, under the Cloud Data Processing Addendum | Personal Google accounts | |
| Microsoft | Microsoft Copilot and Copilot Chat used by organisations, under the Microsoft Products and Services Data Protection Addendum | Web searches sent to Bing, which Microsoft handles as an independent controller |
Two practical points. For some vendors, accepting the business terms is accepting the DPA; for others you request or sign it. Either way, save a dated copy in your records. And note the exclusions: Microsoft's web-search carve-out means staff shouldn't put client names into Copilot questions that need the web. For how the four vendors compare more widely, see whether ChatGPT, Claude, Gemini and Copilot are GDPR-compliant.
Many DPAs also explain how data is transferred outside the EU, usually under standard contractual clauses. If you're unsure whether a vendor's transfer arrangements work for you, that's a reasonable question for your adviser.
Step 4: Switch off training and set retention
The GDPR's storage limitation principle says you keep personal data no longer than you need it. With AI tools that means two things: the vendor shouldn't be using your data for its own purposes, and chats shouldn't pile up forever.
On business plans, training is off by default at OpenAI, Anthropic, Google Workspace and Microsoft. If anyone uses a consumer plan for work, switch it off: in ChatGPT it's "Improve the model for everyone" under Settings, Data Controls; in Claude it's the model training setting under Settings, Privacy; in the Gemini app it's the Keep Activity setting.
Retention controls vary by plan. ChatGPT Enterprise and Edu let admins set how long content is kept, and deleted chats are removed within 30 days. Claude Enterprise lets owners set custom retention with a 30-day minimum. For Workspace users of the Gemini app, admins can auto-delete conversations after 3, 18 or 36 months, with 18 as the default. Microsoft Purview can apply retention policies to Copilot interactions. On smaller plans without these controls, set a house rule instead: delete client chats when the task is finished, and review projects monthly.
Step 5: Tell people, in your privacy notice and in the chat
Articles 13 and 14 require you to tell people how their data is used, including the categories of recipients. Add a plain paragraph to your privacy notice. The podiatry clinic's version:
We use AI tools from [vendor names] to help draft emails and appointment messages and to answer common questions on our website. These providers act on our instructions under data processing agreements and do not use your information to train their AI models. A member of our team reviews messages before they are sent. We do not use AI to make decisions about your care.
If you run a customer-facing chatbot and sell to customers in the EU, the EU AI Act adds a separate duty: under Article 50, people must be told they're interacting with an AI system unless it's obvious, and that duty has applied since 2 August 2026. A line in the bot's first message covers it.
Step 6: Decide whether a use needs a DPIA
A data protection impact assessment (DPIA) is required before processing that's likely to result in a high risk to people (Article 35), and the article names new technologies specifically. Using AI to draft marketing copy won't come close. Using it on health data, to make decisions about people, or to monitor staff or the public often will. The podiatry clinic's referral-letter idea, which combines health data with a new technology, is a clear candidate. Whether you need a DPIA before using AI tools covers the triggers and includes a filled-in example.
Step 7: Handle rights requests and breaches with AI in the picture
Access requests. When a customer asks for a copy of their personal data, you normally have one month to respond (Article 12). If staff have drafted emails about that customer in ChatGPT or Copilot, those chats may hold their personal data too. On business plans, admins have tools to find them: Microsoft's Content search and Purview cover Copilot interactions, and ChatGPT Enterprise offers a compliance API. On smaller plans, the practical answer is to avoid leaving client details in chats in the first place.
A realistic mistake. A hearing-aid shop's assistant, working late, pasted a customer's audiology report into her personal ChatGPT account to write a friendlier summary. Training was on. The next morning she told the manager, who deleted the chat and the uploaded file, recorded what had happened, and asked the shop's data-protection adviser whether it needed reporting. Under Article 33, a personal-data breach that's likely to risk people's rights must be reported to your data-protection authority within 72 hours of becoming aware of it, so speed matters. The lasting fix was a company account and a rule that audiology reports never go into general AI tools.
Step 8: Brief your staff
Most GDPR failures with AI are habits, not technology. Article 4 of the EU AI Act has required organisations since February 2025 to take measures to support their staff's AI literacy; since the Digital Omnibus changes in July 2026, that means taking measures, not guaranteeing a particular level. For a small business, a 30-minute briefing and a one-page rule sheet usually meets the spirit of it: which tools are approved, what may never be pasted, how to strip names from a task, and who to tell if something goes wrong. AI literacy requirements for staff covers what to include, and anonymising client data before it goes into AI is the practical skill most staff need.
Accuracy: the principle AI tests hardest
The GDPR requires personal data to be accurate and, where necessary, kept up to date, and it gives people the right to have inaccurate data corrected. AI tools make this principle more demanding, because they produce fluent text that can quietly get a detail wrong. An electrician's office used AI to tidy up engineers' job notes, and one summary merged two visits on the same street, recording the wrong customer's address against a fault report. Nobody noticed until the customer received a follow-up about work that wasn't theirs.
The safeguard is the same as for accuracy generally: a person checks any AI-produced record about an individual before it's saved or sent, and staff know how to correct a record when a customer points out an error. Treat AI summaries of people as drafts, never as the record itself, until someone has read them.
How long all this takes
For a small business with a handful of AI uses, the eight steps are an afternoon's work rather than a project: about an hour to map uses and data, 30 minutes on lawful bases and any balancing tests, 20 minutes to find and file each vendor's DPA, 15 minutes on settings, 30 minutes on the privacy notice, 30 minutes to screen each use for a DPIA, and 30 minutes to brief staff. Call it four hours, plus a short review each time you add a tool or a vendor changes its terms. A full DPIA, where one is needed, takes longer, and that's usually the point to involve your adviser.
When to bring in a data-protection adviser
You can handle the steps above yourself for routine uses. Take advice before you go ahead when:
- the AI will process health data or other special categories at any real scale, as with clinical notes or audiology records;
- a decision about a person will be made wholly by AI with legal or similarly significant effects, which Article 22 restricts;
- you're using AI in recruitment or to assess people's creditworthiness, uses the EU AI Act lists as high-risk in Annex III, with most obligations for stand-alone systems now deferred to 2 December 2027;
- anything would infer employees' emotions at work, including in recruitment, which the EU AI Act has banned since 2 February 2025;
- you're monitoring staff or members of the public, or processing children's data;
- a breach has happened and you're unsure whether to report it.
For everything else, the pattern is steady: business plans with signed agreements, training off, short retention, an honest privacy notice, and staff who know the rules. If you'd like a broader view of which rules touch your business, the AI compliance checklist for small businesses puts data protection alongside the other obligations.
Further reads
- What to Check in an AI Tool's Privacy Policy and Terms — What to read in an AI tool's privacy policy and terms.
- How to Keep Customer Data Private When Your Team Uses AI — Day-to-day habits that keep customer data private when staff use AI.
- How to Write an AI Usage Policy for Your Small Business — Turning these steps into a written AI usage policy.
- Does ChatGPT Train on Client Data? Business vs Free Plans — How ChatGPT's plans differ on training with client data.
- Is ChatGPT Safe for Business Use? Risks, Settings and Plan Choice — Plan choice and settings for ChatGPT specifically.
- AI Chatbot Disclosure: What to Tell Customers at the Start of a Chat — Disclosure wording for a customer-facing chatbot.
- How to Classify Business Data Before Using AI Tools — A four-tier scheme a small team can apply in an afternoon, with the AI rule for each tier and a fitness studio classified line by line.
- How to Clean Up Customer Records Before You Add AI — Four clean-up passes that stop AI emailing people twice, or at all when they said no, with matching rules and a merge log.
- AI Bias in Small Business Decisions: Hiring, Pricing and Credit — How AI tools pick up bias in hiring, quotes and payment terms, the proxies to strip out, and an afternoon test to check any AI-assisted decision.
- Is It Safe to Put Customer Data Into ChatGPT? — Which ChatGPT plans can take customer data, which data never goes in, and a two-minute routine for stripping identifiers when you must use a personal plan.
- Is It Safe to Let AI Listen to Mortgage Advice Calls? — The data on a mortgage advice call, six risks with a control for each, vendor small print to check, consent wording and an accuracy test to run first.
- Patient Data and AI: A Confidentiality Checklist for Small Practices — A 30-item checklist, with a filled-in example register, for keeping patient information confidential when a small practice uses AI tools.
- Charity AI Risks: Data Protection, Deepfakes, and Donor Trust — Three risk areas for charities using AI, with real cases, the controls that work for a small team, and a filled-in one-page risk register.
- Is It Safe to Use AI With Children's Data in a Nursery? — When a nursery can safely use AI with children's information, what must never go in, and the checks, parent wording and risk review to do first.
- How to Redact Personal Data From Documents With AI Before Sharing — AI is good at finding personal data in documents and bad at removing it. A detect, review, redact and verify routine for files you share outside.
- How to Set Up an AI-Assisted Hiring Process for a Small Team — A hiring pipeline for small teams where AI writes, summarises and schedules, people decide, and every rejection is read by a human first.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: the GDPR (Articles 6, 9, 12, 22, 28, 30, 33 and 35); the EU AI Act (Articles 4 and 50, as amended by the Digital Omnibus on AI); OpenAI's enterprise privacy page; Anthropic's privacy centre on the DPA and retention; Google's Generative AI in Google Workspace Privacy Hub; Microsoft Learn on enterprise data protection for Copilot (checked September 2026). This tutorial is general information, not legal advice.