compliance / 6 August 2026

AI and UK GDPR: What Small Businesses Get Wrong

The UK GDPR mistakes small businesses make with AI, what the 2025 law change means, and how to use AI tools without breaching data rules.

The most common UK GDPR mistake with AI is assuming the tool provider handles compliance for you. It does not. If you decide what personal data goes into an AI tool and why, you are the data controller, and the responsibility is yours. Almost every other mistake follows from getting that one point wrong. Here are the ones we see most often, and what to do instead.

Mistake 1: thinking the AI vendor is responsible

When you use an AI tool on personal data, you are usually the controller and the tool provider is the processor. Under UK GDPR, the controller carries the legal duty. The provider processes data on your instructions, but you decide the purpose, and you answer for it.

What to do: make sure there is a data processing agreement in place with any AI tool that touches personal data. This is required under Article 28 of the UK GDPR, and a reputable provider will offer one.

Mistake 2: pasting personal data into public AI tools

Dropping a customer email, a spreadsheet, or a document into a free public AI tool is one of the fastest ways to create a breach. You may be sending personal data to a third party you have not vetted, on terms you have not read, possibly to be used for training.

What to do: never put personal or confidential data into a public AI tool unless you have checked its terms, confirmed it does not train on your inputs, and satisfied yourself it meets your obligations. For sensitive work, use a tool where you control the data flow.

Mistake 3: no lawful basis and no record of why

UK GDPR requires a lawful basis for processing personal data, and it requires you to be able to show your reasoning. Many small businesses adopt an AI tool because it is useful, without ever recording why the processing is justified.

What to do: write down, briefly, what personal data the tool uses, why, and on what lawful basis. It does not need to be long. It needs to exist.

Mistake 4: ignoring the rules on automated decisions

If AI makes a decision about a person with no meaningful human involvement, special rules apply, particularly where sensitive data is involved. This matters most in areas like hiring, credit, or anything affecting a person's rights.

What to do: keep a human meaningfully in the loop on any decision about a person. Do not let a tool decide and act on its own where the outcome affects someone materially.

Mistake 5: assuming nothing has changed

UK data protection law was reformed by the Data (Use and Access) Act 2025. It does not replace UK GDPR, it amends it, and its main provisions came into force through 2026. A few points a small business should know:

  • A complaints process is now expected. Organisations need a clear route for people to raise data protection complaints, with acknowledgement within a set timeframe. This applies to small businesses too.
  • Automated decision making rules were clarified, with the strongest restrictions focused on special category data and decisions made without meaningful human involvement.
  • Some processing grounds were made easier to rely on, for example certain security and internal administration purposes, and a few narrow cookie consent exemptions were added.

The reassuring part: if you already follow good data protection practice, this is a review and a tidy up, not a rebuild.

What good looks like for a small business

  1. A data processing agreement with every AI tool that touches personal data.
  2. A short written note of what data each tool uses, why, and the lawful basis.
  3. No personal or confidential data in unvetted public tools.
  4. A human accountable for any decision an AI helps make about a person.
  5. A simple, visible way for people to complain about how you use their data.

None of this is heavy. It is mostly writing down decisions you should be making anyway.

Final thought

AI does not create a special category of data protection risk. It just makes the ordinary risks faster and easier to trip over. The businesses that use AI safely are not the ones with the biggest compliance budgets. They are the ones who remember a simple truth: if you chose the data and the purpose, the responsibility is yours, and a good tool is one that makes that responsibility easier to meet.

For related reading, see our guide on AI tools for UK professional services, our notes on using AI in a regulated sector, and our ReporaPro case study, built for a regulated clinical setting.

This article is general information, not legal advice. For your specific situation, consult a data protection professional.

Frequently Asked Questions

Who is responsible for GDPR when using an AI tool?

Usually you are. If you decide what personal data goes into the tool and why, you are the controller and carry the legal duty. The provider is the processor acting on your instructions.

Is it against GDPR to put customer data into ChatGPT or other public AI?

It can breach UK GDPR if you have not checked the terms, confirmed the data is not used for training, and satisfied your obligations. For personal or confidential data, avoid unvetted public tools.

Did UK GDPR change in 2025?

Yes. The Data (Use and Access) Act 2025 amended UK GDPR. It did not replace it. Changes include an expected complaints process and clarified rules on automated decisions, with most provisions in force through 2026.

What is the simplest way for a small business to stay compliant with AI?

Have a data processing agreement with each tool, record why you process data, keep personal data out of unvetted public tools, keep a human on decisions about people, and offer a clear complaints route.