[{"data":1,"prerenderedAt":35},["ShallowReactive",2],{"$fKq3zA_P7KZBpkFe7ehqTciFi9-madrC1oTGFbBo1moU":3},{"id":4,"slug":5,"url":6,"date":7,"modified":8,"title":9,"excerpt":10,"content":11,"featuredImage":12,"featuredImageAlt":13,"tags":14},566,"ai-customer-data-gdpr","https://blog.grizzlyware.com/ai-customer-data-gdpr/","2026-08-27T15:14:43","2026-08-27T15:14:46","Can you put customer data into an AI tool?","\u003Cp>Four practical things to check before an AI tool touches your customer records. Settings and permissions, explained for UK small businesses.\u003C/p>\n","\n\u003Cp class=\"wp-block-paragraph\">For AI to be truly useful, it will usually need to work with your customer data. Simple tasks such as reading your inbox, summarising client calls or searching customer records all count as processing personal data &#8211; and depending on the tool you use, that processing often happens through a company based outside the UK.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">This isn&#8217;t a reason not to use AI for these tasks. It is, however, a reason to make sure the way your customer data is handled complies with UK GDPR.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">You are responsible\u003C/h2>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">The most important thing to understand is that bringing in a third party does not move the responsibility off your desk. Under UK GDPR, if it is your customers&#8217; data, \u003Cstrong>you\u003C/strong> are the controller. The ICO&#8217;s position on this is clear: using AI does not reduce your obligations, and any errors it produces are yours to deal with.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">The \u003Cstrong>controller\u003C/strong> decides why and how personal data gets used, and holds the legal responsibility for it. A \u003Cstrong>processor\u003C/strong> only handles that data on the controller&#8217;s instructions. Most businesses assume they are the controller and the AI vendor is their processor. That is often the case, but the ICO warns against treating it as a universal rule. If a provider uses the data you give it for anything beyond what you have instructed &#8211; including using it to train its own models &#8211; it is no longer simply following instructions, and becomes a controller in its own right. Your settings and the terms of your plan are what determine this, so both are worth checking.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">Four questions to ask about any AI tool\u003C/h2>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">All of these should be answerable from the vendor&#8217;s documentation and your own admin settings.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">1. What does it do with what you put in?\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">You are looking for what happens to your prompts and any documents you upload: whether they are stored, how long for, and whether any staff at the provider can access them.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">2. Where is that data stored?\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Many of these companies are American. Sending personal data outside the UK is allowed, but only with appropriate safeguards in place. The major providers have mechanisms for this, so what you need to ask is whether you are on a plan that includes them.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">3. Does it train on your content?\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">This varies between providers, and often between plans too. Business and enterprise tiers usually exclude your data from training by default, although you still need to check. Consumer and free tiers frequently do the opposite. On a personal ChatGPT account, for example, OpenAI turns data sharing on by default, and you have to switch it off yourself under Settings, Data Controls, &#8216;Improve the model for everyone&#8217;.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">4. Who on your team can see what?\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">This is often overlooked, and it can cause you the most problems. An\u003Ca href=\"https://www.grizzlyware.com/which-ai-assistant-small-business\"> assistant built into your office suite\u003C/a> can see whatever the person using it can see. If your shared drive has been accumulating permissions for a decade, AI will not create a new problem, but it can very easily expose one. Somebody who has always had access to the payroll folder, without anyone noticing, is now one question away from being shown what is in it.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">Two things that catch people out\u003C/h2>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">The first is personal accounts. A team member signs into their own account by accident, or because they are fed up waiting for a license. It is the same assistant, so they see no harm in it. But the moment they put customer data in, every safeguard you put in place when setting up your business account counts for nothing. This is a problem you solve through training rather than through settings.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">The second is assuming that being on a business plan takes care of everything. A business plan usually means your data is not used for training, and that the provider is contractually acting as your processor. It does not configure your permissions, decide what data your team should be putting in, or teach anyone to use the tool responsibly.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">Limitations of settings\u003C/h2>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">For straightforward tasks like the ones above, configuring your AI assistant properly deals with most of what you need to get right. But if you branch into uses that significantly affect people &#8211; screening job applicants or monitoring staff, for example &#8211; you are heading into higher-risk territory. In those cases a Data Protection Impact Assessment is likely to be required. The ICO publishes a\u003Ca href=\"https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/guide-to-accountability-and-governance/data-protection-impact-assessments/\"> DPIA screening checklist\u003C/a> and an\u003Ca href=\"https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ai-and-data-protection-risk-toolkit/\"> AI and data protection risk toolkit\u003C/a>, both free, and they are a good starting point.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">Data sovereignty \u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Should you be handling especially sensitive data, such as medical data, self-hosted AI is also an option &#8211; albeit not the most cost effective for a standard user. We can advise on this if required.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">If you are using our\u003Ca href=\"https://www.grizzlyware.com/managed-ai\"> setup service\u003C/a>, we will tell you if your use case calls for additional measures, and can point you towards legal advice if you need it.\u003C/p>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">Checking your setup\u003C/h2>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">We help businesses choose, set up and manage AI tools, and we are vendor-neutral. We take no commission from Microsoft, Google, OpenAI or Anthropic.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">If you have already connected something and are not sure what it can see, or you want it checked before you go any further, we do a free 20-30 minute call as part of our\u003Ca href=\"https://www.grizzlyware.com/managed-ai\"> managed AI\u003C/a> service.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Send us a message and tell us what you are using.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">\u003C/p>\n","https://blog.grizzlyware.com/wp-content/uploads/2026/08/kaffeebart-KrPulSdUetk-unsplash1-scaled.jpg","padlock",[15,19,23,27,31],{"id":16,"name":17,"slug":18},79,"AI for business","ai-for-business",{"id":20,"name":21,"slug":22},108,"AI in business","ai-in-business",{"id":24,"name":25,"slug":26},68,"data protection","data-protection",{"id":28,"name":29,"slug":30},120,"managed AI","managed-ai",{"id":32,"name":33,"slug":34},119,"UK GDPR","uk-gdpr",1787840526433]