Can I Use AI On Customer Data?

The question I get asked most once a business decides AI is useful. Not whether it is a good idea, but whether you are allowed to.

This is the question I get asked most often once a business has decided AI is genuinely useful to them. Can we put customer information through it? Not "is it a good idea", but "are we allowed to".

The honest answer is usually yes, with conditions, and the conditions are the part worth understanding. I should say plainly at the outset that I build systems to meet these requirements rather than advise on them. If you handle anything sensitive, or you are unsure where you stand, that conversation belongs with someone qualified. What I can do is set out the shape of the question so you know what you are asking about.

Nothing about AI changes who is responsible

Under UK GDPR you are the controller of your customers' data. You decide what is collected and why. When you send some of it to an AI provider to process on your behalf, that provider is acting as your processor, in the same way your accounting software or your email host does.

That relationship is not created by clicking accept on a sign-up page. It needs a written contract covering what they may do with the data, that they will keep it secure, and that they will help you if a customer exercises their rights. Providers call this a data processing agreement, or DPA.

What this means for you

The first practical question about any AI tool is whether the provider offers a DPA on the plan you are actually on. Business and enterprise plans generally do. Free and personal plans frequently do not, which is the clearest reason not to run customer data through a personal account.

You still need a reason to be doing it

Every use of personal data needs a lawful basis. For most ordinary business operations that will be legitimate interests, which requires you to have actually weighed your interest against the effect on the person. For some things it will be contract, because you cannot deliver what they bought without it.

Adding AI to a process does not create a new basis and does not remove the need for one. What it can do is change the balance, because a customer who expected their enquiry to be read by you may not have expected it to be sent to a third party. That is a transparency problem more than a lawfulness one, and it has a straightforward fix.

Your privacy notice has to be honest about it

If an AI provider now processes personal data on your behalf, your privacy notice should say so, in terms a customer can understand. What categories of data, for what purpose, and the fact that a third-party provider is involved.

This is the single most commonly missed step I come across. The technical side gets done properly and the privacy notice still describes a process that stopped being accurate months ago.

What this means for you

Whenever you add an AI tool to a process that touches customer information, put "update the privacy notice" on the same task list as the setup. It is a ten-minute job at the time and an awkward one to explain later.

Where the data physically goes

Most large AI providers are based outside the UK, so using them usually involves an international transfer of personal data, which carries its own requirements. Some providers are covered by arrangements that make this straightforward, and the mechanism a given provider relies on can change.

I am not going to state the current position for particular providers here, because it would be out of date faster than this page will be. The durable point is that this is a real question with a real answer, and the answer lives in that provider's current data protection documentation rather than in an article.

Some data needs a much higher bar

UK GDPR treats certain categories as special: health, ethnicity, religion, trade union membership, sexual orientation, biometric and genetic data. Processing any of it needs a specific additional condition, not just a lawful basis, and the bar is considerably higher.

Criminal offence data has its own separate rules. Children's data attracts extra care.

Businesses trip over this in unglamorous ways. A physiotherapist pasting case notes to get a letter drafted is handling health data. A recruiter running applications through a summariser may be handling several special categories at once without having thought of it that way.

What this means for you

If your business touches any of those categories, treat AI adoption as a proper piece of work with advice attached rather than something to trial informally. That is not me being cautious for the sake of it. It is the one area where getting it wrong is expensive.

Decisions made about people, rather than work done for you

There is a meaningful difference between using AI to draft a reply and using it to decide something about a person. Where a decision is made purely automatically and has legal or similarly significant effects on someone, such as screening job applicants or determining eligibility for something, UK GDPR places specific restrictions on it.

Keeping a person genuinely in the loop, rather than nominally rubber-stamping an output, is what usually keeps a process on the right side of this.

Being able to honour a request

A customer can ask what data you hold about them, and can ask you to delete it. You have to be able to do both.

This is where informal AI use quietly creates a problem. If a member of staff pasted a customer's details into a chat window eight months ago, that conversation is data you hold, in a place you cannot search, on a system you may not control. It is a much harder request to answer honestly than one about your CRM.

What this means for you

This is the strongest practical argument for approved tools and a written policy rather than leaving people to their own accounts. Not because staff cannot be trusted, but because you cannot answer for data that lives somewhere you cannot see.

A workable order to do this in

  1. Decide which AI tools are approved, and on which plan.
  2. Check each one offers a DPA and read what it actually commits them to.
  3. Write down which categories of customer data may go in and which may not.
  4. Update your privacy notice to match what you now do.
  5. Agree how long AI-held conversations are kept and how they get cleared.
  6. Tell your team, in one page they will actually read.
  7. If the processing looks high-risk, novel or large-scale, take advice on whether a data protection impact assessment is needed before you start rather than after.

The Information Commissioner's Office publishes guidance on AI and data protection that is more readable than its reputation suggests, and it is the right first stop if you want to go deeper.

Step six is its own piece of work, covered in how to write an AI policy your team will actually follow. The technical side of where text goes when it leaves your business is in what happens to what you type into an AI tool, and the wider picture sits in my guide to using AI safely in a small business. If you would rather work this through against your actual processes, that is what the AI Setup Package is for.

More In This Series

← All posts

Want A Second Opinion On Your Own Setup?

Get in touch and your message comes straight to me. I reply within 48 hours, usually sooner.

Contact Us