UK GDPR
UK GDPR and AI: what applies when you use an AI tool
There is no UK AI Act. For most UK businesses, the law that governs AI use today is the one that already governed your customer database — UK GDPR, alongside the Data Protection Act 2018. Here's what that means in practice.
Last reviewed: August 2026
Why UK GDPR is the law that matters
The UK chose not to pass a single AI statute. Instead, existing regulators apply existing law to AI. Because almost every commercially useful AI tool ends up handling information about real people, UK GDPR is the rulebook that catches most businesses first.
The obligations aren't new. What's new is that an AI tool can breach them at a speed and scale a spreadsheet never could — and that staff often adopt these tools without telling anyone.
1. You need a lawful basis, and you need to know which one
You can't process personal data because it's useful. You need one of six lawful bases, and you should be able to say which one applies to each AI tool. For business AI use, three come up repeatedly.
- Legitimate interests — the usual basis for internal efficiency tools. Requires a short balancing exercise: your benefit against the intrusion on the person. Write it down.
- Contract — where the AI is genuinely necessary to deliver what the customer bought, such as an automated service update.
- Consent — needed rarely, but properly needed for things like marketing profiling. Consent must be a real, freely given choice, and withdrawable.
Special category data — health, ethnicity, religion, sexual orientation, biometrics, trade union membership — needs an additional condition on top. If an AI tool is anywhere near that data, treat it as higher risk by default.
2. Transparency: people have to be able to find out
If you use AI on someone's data, they're entitled to know. In practice that means your privacy notice says so — not in a way that requires a law degree, and specifically enough that a reader understands what's happening.
"We may use technology to improve our services" is not transparency. "We use an AI assistant to draft replies to support emails; a member of our team reviews every reply before it's sent" is.
The clause worth adding today
3. Automated decision-making has its own rules
Article 22 of UK GDPR restricts decisions made solely by automated means that have a legal or similarly significant effect on someone. Job rejections, credit decisions, insurance pricing, and account closures all fall inside that description.
Where those rules apply, you generally must: tell the person the decision was automated, give them a way to get human review, and let them contest the outcome. The human review has to be real — someone with the authority and information to reach a different answer.
This is the clause that catches recruitment CV-screening tools most often, because the tool ranks or filters candidates and nobody re-reads the ones it discarded.
4. DPIAs: the written assessment
A DPIA is a Data Protection Impact Assessment — a structured note covering what the tool does, what data it touches, what could go wrong for the people involved, and what you've done to reduce that. It's required for higher-risk processing, which explicitly includes automated decisions with significant effects, large-scale use of sensitive data, and systematic monitoring.
A DPIA doesn't need to be long. It needs to exist, to be honest, and to be dated.
5. Where does the data go?
Most AI vendors are not UK companies. Sending personal data to a supplier outside the UK is an international transfer, and you need a valid mechanism for it — usually the UK adequacy regulations for that country, or the International Data Transfer Agreement or UK Addendum in your contract.
- Check whether the vendor trains its models on your inputs. Many business tiers switch this off — free tiers often don't.
- Check retention: how long do prompts and uploads sit on their servers?
- Check where the processing happens, and whether a UK or EU region is available.
- Keep the vendor's data processing agreement on file. If they don't offer one, that itself is the finding.
6. The rights people can exercise still apply
Subject access, correction, erasure and objection don't pause because AI is involved. If a customer asks what data you hold about them, "it's inside the AI tool" is not an answer. You need to know which tools hold what — which is, again, a register problem before it's a legal one.
See where your own AI use actually stands
Register the AI tools your team uses and get a risk rating for each one, in plain English. Free, and it takes about ten minutes.
Not legal advice. This guide explains how the rules are generally understood and is here to help you get organised. It isn't a substitute for advice from a qualified solicitor or your own compliance team.
