Somebody in your business has already asked this, or has quietly decided not to ask. It is the right question, and the answers online are unhelpfully split between "it is completely fine" and "you will be fined into oblivion".
Neither is true. The useful version is narrower: which data, into which account.
The short version
- The risk is not the AI. It is putting other people's information somewhere you have not assessed.
- Free consumer accounts and business accounts are different products with different data terms. This is the distinction that matters most.
- Anonymous business context is almost always fine. Anything that identifies a person is not, unless you have done the paperwork.
- You remain the data controller. Using someone else's tool does not move that.
What actually happens to what you paste
Three things, in order.
It is transmitted. Over an encrypted connection to the provider's servers, which are very unlikely to be in the UK. That is normal, and lawful with the right terms in place.
It is retained. Conversations are stored on your account so you can return to them, and typically kept for a period even after deletion, for abuse monitoring. Retention periods vary by provider and tier.
It may be used for training. This is the one that matters, and it is where free and paid tiers have historically diverged sharply. Consumer free tiers have generally used conversations to improve the models, with an opt-out setting most people never find. Business, team and enterprise tiers generally do not, and say so contractually.
That last distinction is the single most valuable thing in this article. "We use ChatGPT" tells you nothing about your exposure. "We use ChatGPT on a business tier with training disabled and a signed data processing agreement" tells you a great deal.
Where UK GDPR actually bites
UK GDPR does not mention AI. It does not need to. It governs the processing of personal data, and pasting a customer's email into a tool is processing personal data.
Four obligations do the work here:
- You are the controller. The AI provider is your processor. Their compliance is not a substitute for yours, and a provider's assurances do not transfer the duty.
- You need a processing agreement. Business tiers offer one. A free personal account signed up with a Gmail address does not give you a meaningful one.
- Data minimisation applies. Send only what is needed. In practice this is the rule that saves you: most tasks do not need the name.
- People have rights over their data. Access, erasure, objection. If personal data sits in a conversation history in an account you do not control, honouring those rights becomes awkward.
The ICO's own guidance on AI and data protection is written for organisations of your size and is more readable than its reputation suggests. Worth an hour.
The traffic-light rule
Policies fail when they require judgement at speed. This one does not.
| Colour | What | Rule |
|---|---|---|
| Green | Published material, generic industry questions, your own draft writing, anonymised scenarios, public pricing, marketing copy | Go ahead, any approved tool |
| Amber | Internal documents with no personal data: processes, plans, non-sensitive commercial context, anonymised customer situations | Approved business-tier account only |
| Red | Anything naming a person, health or financial details, HR and disciplinary material, credentials, client work under NDA, unpublished accounts, tender pricing | Never, in any tool, without a specific documented assessment |
Print it. Two lines on a wall beat forty pages in a shared drive.
The habit that solves ninety per cent of it
Redaction, and it takes seconds. Nearly every task a small business wants help with works just as well without the identifying details, because the AI is helping with the shape of the problem, not the person in it.
Draft a reply to Sarah Williams at Hafod Engineering, sarah@hafod-eng.co.uk, who is complaining that her order 4471 is three weeks late.
Draft a reply to a long-standing business customer whose order is three weeks late because of a supplier delay. Apologise properly without grovelling, explain the cause in one sentence, give a firm new date, and offer something concrete. Under 150 words, warm but professional.
The second gets you a better reply, because you told it what good looks like instead of who it was for. You paste the name in yourself afterwards, in ten seconds, in your own email client.
What to do on Monday
- Find out what is already in use. Ask without blame. You cannot govern what you cannot see.
- Move everyone onto business tiers of one or two approved tools, and check the training setting is off.
- Download the provider's data processing terms and keep the PDF. That file is your evidence.
- Print the traffic lights.
- Write the one-page policy. There is a template ready to copy in Write an AI policy for your small business in one page.
- Add it to induction, so the next person you hire learns it in week one rather than year two.
The risk of doing nothing
It is worth being straight about the other side. The most common outcome of a blanket "no AI" is not safety. It is the same activity happening on personal phones, on personal accounts, with no agreement, no record and no way to find out what was sent. You have swapped a manageable risk for an invisible one, and lost the productivity as well.
Approve two tools. Buy the proper tier. Print the traffic lights. That is most of the job, and it takes an afternoon.
Data questions come up in the open floor after almost every AI Breakfast Club webinar, and they are among the most useful thirty minutes on offer. It runs free, online, every other Friday morning.
This article is general guidance, not legal advice. If you handle special category data or work in a regulated sector, take proper advice on your specific circumstances.