GDPR and AI: A Plain-English Guide for UK Small Businesses (2026)

If your AI touches a customer name, an email or a CV, UK GDPR applies — there is no small-business exemption. Here is what that actually requires in 2026, after the Data (Use and Access) Act changed the rules on automated decisions, in plain English.

If your business uses an AI tool that touches personal data, a customer's name, an email address, a support ticket, a CV, then UK GDPR applies to you, whatever your headcount. There is no exemption for small businesses, and the Information Commissioner's Office has been consistent about that for years. The good news is that compliance for a normal small business is mostly common sense written down: know what data goes into which tool, have a lawful reason for it, tell people, and keep a human in charge of decisions that affect them. This guide walks through what that means in practice in 2026, including the changes the Data (Use and Access) Act brought in this year.

I'm not a lawyer, and nothing here is legal advice. It's the practical version I give clients before they bring in a solicitor for anything genuinely high-risk. If you'd rather talk your own situation through, book a free consultation.

Does GDPR apply to a small business using AI?

Yes, and the belief that it doesn't is one of the more expensive myths going around. UK GDPR applies to any organisation that processes the personal data of people in the UK, whatever its size or turnover. A two-person business handling customer emails has the same baseline duties as a bank; the difference is scale and risk, not whether the law applies (ICO).

What trips people up is the word "processing." It doesn't only mean storing a database. Pasting a customer complaint into ChatGPT to draft a reply is processing. Uploading a spreadsheet of leads so an AI can sort them is processing. Feeding a stack of CVs to a tool to shortlist them is very much processing, and a sensitive kind. The moment personal data goes into an AI tool, you are doing the thing the law governs.

So the question for a small business isn't whether GDPR applies. It's which of your AI uses touch personal data, and how risky each one is. Most fall into a low-risk bucket that needs a little tidiness and nothing more. A few need real care. The rest of this guide helps you tell them apart.

When does an AI tool actually trigger GDPR?

A quick test: would the information identify a living person, on its own or combined with something else you hold? If yes, it's personal data and GDPR is in play. Names, emails, phone numbers, postal addresses, IP addresses, photos, and notes about an identifiable customer all count.

A smaller, stricter category matters even more. "Special category" data covers things like health, ethnicity, religion, sexual orientation, trade union membership, and biometric data used to identify someone. The bar for processing any of that is much higher, and as you'll see below, it's the dividing line in the new rules on automated decisions. Most small businesses should simply keep special category data out of general-purpose AI tools altogether unless they've taken specific advice.

Plenty of AI use involves no personal data at all. Asking a chatbot to draft a generic blog post, summarise a public report, or write code touches nobody's data and carries no GDPR weight. Worth saying clearly, because fear of GDPR stops some owners adopting AI for things that were never a problem in the first place.

What changed in 2026: the Data (Use and Access) Act

The headline development for UK businesses is the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025 and came into force in stages, with the main data protection changes taking effect on 5 February 2026 (GOV.UK). It amends UK GDPR rather than replacing it, so the framework you may already know still stands. Two changes matter for AI.

The first is automated decision-making. The old Article 22 of UK GDPR was close to a ban on decisions made about people by software alone, where those decisions had a legal or similarly significant effect, allowing it only in narrow cases. From early 2026, that was replaced by a new regime (the new Articles 22A onwards) that loosens the rule for most data while tightening the guardrails. In short: a significant automated decision is now broadly permitted unless it relies wholly or partly on special category data, in which case the stricter old-style conditions still apply. Whenever a significant decision is made by AI alone, you must tell people it's happening, give them a way to make their case, and let them ask for a human to look again (Travers Smith).

The second is a statutory code of practice on AI and automated decision-making. Regulations made in 2026 require the ICO to produce it, and once published it will be the benchmark the regulator judges fair AI use against (legislation.gov.uk). For a small business the practical message is the same as it's always been: if you let AI make consequential calls about people, hiring, credit, who gets a refund, do not let it run unsupervised, and be able to explain how it reached its answer.

One caveat worth flagging. The UK and the EU have now taken different paths on automated decisions, so a setup that's fine under UK rules will not automatically satisfy EU GDPR. If you have customers or staff in the EU, that's a conversation to have properly rather than assume away.

Do I need a Data Protection Impact Assessment for AI?

Often, yes, and it's less daunting than it sounds. A DPIA is required where processing is "likely to result in a high risk" to people's rights, which the ICO says specifically includes the use of new or innovative technologies, and AI usually qualifies when personal data is involved (ICO).

For a small business, a DPIA is really a short, honest write-up that answers a handful of questions. What is the AI doing, and with whose data? Why do you need it, and is there a less data-hungry way to get the same result? What could go wrong for the people involved, and how likely is it? What are you doing to reduce that risk? You write it before you roll the tool out, keep it on file, and update it if the use changes. The ICO offers a free AI and data protection risk toolkit that walks you through the same ground if you'd rather not start from a blank page.

The point of the exercise isn't paperwork for its own sake. Done properly, a DPIA catches the obvious problems, customer data heading to a server outside the UK, a tool that trains on whatever you type, a decision that ought to have a person in the loop, while they're still cheap to fix.

A practical GDPR-and-AI checklist for SMBs

You can get most small businesses to a defensible position with a handful of steps, none of which need a consultant or a lawyer for the basics.

Keep a simple AI register. One spreadsheet listing every AI tool in use, who owns it, what data it touches, and how risky it is. This is the single most useful artefact you can have, because you can't protect data you haven't mapped, and the ICO will expect you to know what you're running.

Pin down a lawful basis for each use. For most SMB cases that's legitimate interests (you have a genuine business reason and it doesn't override people's rights) or consent. The Act also added a "recognised legitimate interests" ground that removes some of the balancing work for certain purposes. Write down which basis applies to each AI use; the act of choosing usually clarifies whether the use is sensible at all.

Check the tool's tier and terms. Consumer AI tools and business or enterprise tiers are different animals. Free and personal plans may use what you type to train their models and rarely come with a data processing agreement. Business and enterprise tiers (for example ChatGPT Business, or Microsoft 365 Copilot on the right licence) typically don't train on your content and do offer the contractual terms GDPR expects. If staff are pasting customer data into a free tool, that's a gap to close.

Tell people, in plain words. Your privacy notice should say that you use AI, broadly what for, and what it means for them. People generally don't object to AI drafting an email faster; they object to finding out it was used to decide something about them without being told.

Keep a human on consequential decisions. Anything that materially affects a person, an application, a price, a complaint outcome, should have a human who can review and overturn it. That's both good practice and, after this year's changes, an explicit expectation for significant automated decisions.

Write a one-page AI policy. What staff can and can't put into which tools, who to ask when unsure, and the short version of the above. This is the same one-pager that fixes the privacy fears behind low team adoption, so it does double duty.

What you should not automate

Some things are best kept away from AI, or kept firmly under human control, regardless of what's technically permitted.

Decisions that hinge on special category data, anything involving health, ethnicity, religion, and the like, sit on the wrong side of the new rules and carry real legal weight. Significant decisions about people, who to hire, who to lend to, who to let go, should never be handed wholesale to a tool, both because the law expects human involvement and because the reputational damage of getting one wrong publicly dwarfs any time you saved. And anything where you couldn't explain to the affected person how the answer was reached is a sign to slow down, because "the AI decided" is not a defence the ICO accepts.

None of this rules out using AI to assist these tasks. Drafting, summarising, and surfacing options for a human to weigh are fine. The line is between AI as a helper and AI as the decision-maker on things that matter to people's lives.

What's the realistic enforcement risk for a small business?

Worth being honest about scale here. The maximum UK GDPR fine is the headline-grabbing one, up to £17.5 million or 4% of global annual turnover, whichever is higher, with a lower tier of £8.7 million or 2% for less serious breaches (ICO/LegalVision). For a normal small business those numbers are a ceiling, not a forecast. The ICO tends to reserve large fines for serious, large-scale, or wilful failures.

That's not a reason to relax. The realistic cost for an SMB is rarely a record fine; it's the disruption of an investigation, the cost of cleaning up after a breach, and the trust you lose with customers when something goes wrong with their data. A complaint from one annoyed customer or one departing employee is enough to start an ICO conversation. The steps above are cheap insurance against an expensive afternoon.

What about the EU AI Act and South Africa's POPIA?

Two quick pointers, since clients always ask. The UK has not passed an equivalent of the EU AI Act; it regulates AI through existing law like UK GDPR plus its sectoral regulators and the new code of practice. If you sell into the EU, the AI Act is a separate regime with its own obligations and timelines, and it's worth checking whether any of your uses fall into its higher-risk categories.

If you operate in South Africa, the relevant law is POPIA rather than GDPR, and the principles rhyme more than they match. The instincts in this guide, map your data, have a lawful reason, be transparent, keep humans on big decisions, travel well across both. The detail does not, so treat each jurisdiction on its own terms.

Frequently asked questions

Is it against GDPR to put customer data into ChatGPT?

Not automatically, but it depends on the tool and the basis. On a free or personal plan, the provider may use what you enter to train its models and you likely have no data processing agreement, which makes putting customer data in risky. On a business or enterprise tier that doesn't train on your content and offers proper terms, and with a lawful basis and a privacy notice in place, it can be fine. The safest default is to keep customer data out of consumer-grade tools.

Do I need a DPIA before using an AI tool?

You need one whenever the AI use is likely to be high risk to people, which the ICO says generally includes new technologies processing personal data. For a small business that's a short written assessment of what the tool does, why, what could go wrong, and how you've reduced the risk. Do it before you roll out, keep it on file, and revisit it if the use changes.

What did the Data (Use and Access) Act change for AI?

Mainly two things. It replaced the old near-ban on solely automated significant decisions with a more permissive regime, except where special category data (like health) is involved, while requiring you to tell people, let them make their case, and give them human review. And it set in motion a statutory code of practice on AI and automated decision-making, which the ICO has been tasked with producing and will judge fairness against. The wider UK GDPR framework still applies.

Does GDPR apply to my business if I only have a handful of staff?

Yes. UK GDPR has no small-business exemption. The obligations scale with the risk and volume of what you do, not your headcount, so a micro-business doing simple, low-risk processing has a light load, but it is not zero.

Can AI make hiring or firing decisions for me?

You should not let it. Decisions that significantly affect someone are exactly where the rules expect meaningful human involvement, and hiring or dismissal decisions often touch special category data too. Use AI to help draft or summarise if you like, but the decision, and the ability to explain it, must stay with a person.


Vyrion Tech provides practical, hands-on AI consulting and adoption support for small and medium businesses in the UK, South Africa, and beyond. We help you put AI to work without tripping over data protection, from a quick risk map to a workable AI policy your team will actually follow. This guide is general information, not legal advice; for anything high-risk, take proper legal counsel. If you want a hand getting it right, start with a free consultation.