Is AI use covered by UK GDPR?
Chris Duffy
Certified Chief AI Officer • • 2 Min Read
Yes. If your AI use touches personal data, staff records, customer details, anything that identifies a person, UK GDPR applies the same as any other processing. Higher-risk uses need a Data Protection Impact Assessment before you start. The common trap for SMEs is putting customer or staff data into a public AI tool without checking where it goes.
The practical test: would you be comfortable explaining to that person, or to the ICO, exactly what happened to their data inside the tool? If you can't answer that, you've got a gap to close.
Closing it doesn't take much. A clear line on what data can go into which tools, a DPIA where the processing is higher-risk, and a short record that proves both. Where the tool stores and trains on data matters too, which is why AI data storage and GDPR gets its own guide.
Read next: What is a DPIA · AI governance for UK SMEs · Book a call