Introduction
Most UK businesses already understand GDPR in the context of their website, their CRM, and their marketing lists. AI introduces a genuinely new set of questions on top of that — where does your data actually go when you send it to an AI provider, what happens to it, and what does "compliant" even mean when a third-party AI model is involved in processing it.
This guide walks through what specifically changes with AI, the risks worth understanding, and a practical checklist for building AI features responsibly under UK GDPR.
This builds on the broader picture in our AI development guide for UK businesses, and applies directly to sector-specific use cases like those covered in our AI in Finance and AI in Healthcare guides.
What Actually Changes With AI, GDPR-Wise
UK GDPR's core principles don't change because AI is involved — you still need a lawful basis for processing, you still need to handle personal data proportionately, and individuals still have the same rights. What changes is the practical complexity of applying those principles:
- Data often leaves your own systems — when you use a third-party AI API, personal data may be transmitted to and processed by that provider, which adds a data processor relationship (and sometimes an international transfer question) that needs proper handling.
- It's harder to fully explain how a decision was reached — AI models, particularly complex ones, can make it genuinely difficult to give the level of explanation that GDPR's transparency principles expect, especially for automated decision-making.
- Data can end up in places you didn't intend — without careful design, personal data can end up in AI prompts, logs, or even (in some cases) training data, in ways that are easy to overlook if privacy isn't considered from the start
Key Risks to Understand
1. Third-party AI provider data handling: When you send data to an AI provider's API, understand exactly what happens to it: is it used to train their models, how long is it retained, and where is it processed. This varies significantly by provider and by plan/tier — enterprise or business-tier API access typically comes with stronger data handling commitments than free consumer tools, and this distinction matters a great deal for any business use case involving personal data
2. International data transfers: If an AI provider processes data outside the UK/EU, this can trigger UK GDPR's international transfer rules, which require an appropriate safeguard (such as Standard Contractual Clauses) to be in place. This is worth checking explicitly with any AI provider you're evaluating, not assumed.
3. Special category data: Health data and other special category data types require a higher standard of protection and a specific legal basis under UK GDPR — this applies just as much when AI is involved in processing it as it does with any other system. See our AI in Healthcare guide for how this applies specifically in that sector.
4. Automated decision-making: UK GDPR gives individuals specific rights regarding decisions made solely by automated means that have legal or similarly significant effects on them, including the right to request human review. If your AI feature makes or heavily influences decisions like this (credit approval, pricing, eligibility), this needs specific attention in your compliance approach, not just general data protection good practice.
5. Data minimisation with AI: It's tempting to feed an AI system as much data as possible "in case it's useful," but GDPR's data minimisation principle still applies — only process the personal data genuinely necessary for the AI feature to work.
6. Prompt and log retention: User inputs to AI chatbots or tools are often logged for debugging, quality improvement, or analytics — if those inputs contain personal data, that logging is itself a form of data processing that needs to be accounted for in your privacy documentation and retention policy.
Do You Need a Data Protection Impact Assessment (DPIA)?
A DPIA is likely required (and is good practice even when not strictly mandatory) for AI projects that involve:
- Large-scale processing of personal data
- Special category data (health, biometric, etc.)
- Automated decision-making with significant effects on individuals
- Systematic monitoring of individuals
- New or innovative use of technology where the risk isn't well understood yet — which describes a lot of AI use cases by definition
If you're unsure whether your specific AI project needs a DPIA, it's worth checking against the ICO's guidance directly for your use case, or getting input from a data protection professional — this is genuinely one of those areas where getting a specific, current answer matters more than a general rule of thumb.
Practical GDPR Checklist for AI Projects
- Identify what personal data (if any) the AI feature will process, and confirm it's genuinely necessary for the feature to work
- Confirm your lawful basis for processing that data through the AI feature specifically
- Review your AI provider's data handling terms — retention, training use, and where data is processed
- Confirm appropriate safeguards are in place if data is processed outside the UK/EU
- Update your privacy notice to reflect the AI processing, in plain language
- Assess whether a DPIA is required, and complete one if so
- Build in a clear human review/escalation path for any AI output that could significantly affect an individual
- Define a retention policy for AI prompts, logs, and outputs that may contain personal data
- Test the AI feature specifically for data minimisation — is it processing more personal data than it actually needs to function well
Building Privacy-Conscious AI: What Good Practice Looks Like
- Choosing AI providers with clear, business-appropriate data handling terms, rather than defaulting to free consumer-tier tools for anything involving customer or business data
- Anonymising or pseudonymising data before it reaches an AI model wherever the feature allows for it
- Designing AI features so a human is genuinely able to review and override AI output that affects individuals, not just nominally able to
- Keeping AI-related data processing documented clearly enough that you could explain it to a regulator, a customer, or an auditor without scrambling to reconstruct what actually happens
- Reviewing AI data handling practices periodically, since AI providers' terms and capabilities do change over time
Building an AI Feature and Need Privacy Guidance?
Getting data protection right from the design stage — not as an afterthought — is what makes an AI project both compliant and genuinely trustworthy to your customers. Our AI development team builds privacy considerations into the development process from day one.
Get in touch to talk through your AI project, or read our full AI development guide for the broader fundamentals.
This guide provides general information and is not a substitute for legal advice. For specific compliance requirements, consult a qualified data protection professional or the ICO's current guidance.

