What GDPR still requires when AI does the processing

· · AI

Somewhere in your business right now, someone is probably pasting a customer's name, email, or contract details into ChatGPT, Copilot, or Claude to draft a reply faster. Nobody told them not to, because nobody wrote it down. It feels like a productivity shortcut. Legally, it is personal data leaving your business for a company you did not choose to process it, and UK GDPR still applies to every word of it.

UK GDPR was written years before generative AI tools were in everyday business use. It still applies in full. Nothing about "the AI did it" changes who is responsible. If your business decides what personal data gets used for, you are the one accountable for what happens to it, whichever tool does the processing.

Why these tools sit awkwardly with the law

UK GDPR rests on a handful of plain ideas. Only collect and use the personal data you actually need, for a clear purpose. Be able to explain to a customer what happens to their data. Delete it if they ask. Most businesses have historically met this by knowing where their data lives: a CRM, an email system, a filing cabinet. You can point at it, describe it, and delete a record from it.

A generative AI tool breaks that picture in three ways. Where the data goes is harder to pin down: type a customer's details into an AI assistant and that text may reach a model provider you have no direct contract with, processed on infrastructure you have never audited, logged in ways your privacy notice does not mention. What happens next is hard to fully explain: if a customer asks how their data was used, "we typed it into an AI to draft a reply" is not much of an answer if you cannot say whether it was stored or who else can see it. And deletion is not always straightforward: wiping a record from your own CRM is simple, but clearing it from an AI provider's logs, caches, or any training pipeline it may have touched is a different question, and the honest answer for a lot of tools right now is "we are not certain."

None of this means the tools are unsafe to use. It means the paperwork most businesses have for data protection was written for filing cabinets and databases, not for a service that ingests whatever you type into it.

What a director can actually check

You do not need to become a data protection lawyer. You need answers to a short list of questions, for every AI tool anyone in the business actually uses, including the free version someone downloaded themselves.

Ask your suppliers: does the contract say whether what we type in trains the model, where is it processed and stored and for how long, can we get it deleted on request, and is there a data processing agreement in place, the document that sets out how a supplier is allowed to handle personal data on your behalf. A supplier who cannot answer plainly has told you something.

Then look inwards. Do you know which AI tools are in use across the business, including ones nobody formally approved. Have staff been told what they can and cannot paste into them. If a customer asked today what happens to their data when your team uses AI, could anyone give a straight answer.

How Steelwise can help

Working out which AI tools are already handling your customers' personal data, and whether your data protection paperwork actually covers what those tools do, is the kind of review we do. Get in touch.

Further reading

← All filings