The short version: no AI tool is “GDPR compliant” in the way people mean it when they type that phrase into Google. GDPR compliance depends on how you set the tool up, what you feed into it, and the contract sitting behind it, not a badge the vendor slaps on their homepage. Microsoft Copilot, ChatGPT Team and Enterprise, Google Workspace with Gemini, and Claude for Work can all be used compliantly by a UK business, but only if you turn off training data sharing, sign the data processing addendum, and know where the servers sit.
Why “is it GDPR compliant” is the wrong question
I get asked this at least once a week now, usually by a business owner who has just read a scary LinkedIn post about AI and data protection. The question itself is the problem. GDPR doesn’t certify software. There’s no stamp. What GDPR does is put obligations on you, the data controller, and it makes the AI vendor a data processor if you’re feeding it customer information. So the real question isn’t “is ChatGPT GDPR compliant” but “have I configured ChatGPT, and my own processes around it, in a way that meets my obligations under UK GDPR.”
That distinction matters because I’ve watched businesses tick a box after reading a vendor’s marketing page and assume they’re covered. A vendor saying “we take privacy seriously” on their pricing page is not a legal document. What you need is their Data Processing Agreement (DPA), their sub-processor list, and clarity on where your data physically sits and whether it trains their models. Most people never ask for any of those three things.
The tools that hold up when you check them
These are the tools I recommend to UK clients once we’ve gone through the settings, not just because their brand is trustworthy.
- Microsoft Copilot for Microsoft 365 – covered by Microsoft’s commercial data protection terms, sits inside the EU Data Boundary if you’re on the right tenant settings, and your prompts and data are not used to train the underlying models. This is the one I recommend most often to UK small businesses because they’re usually already paying for Microsoft 365 anyway.
- ChatGPT Team, Business, or Enterprise (not the free or Plus personal tier) – OpenAI’s business plans come with a signed DPA on request and, by default, don’t use your inputs to train models. The free version and personal Plus subscription do not offer the same contractual protection and are the version I most often catch staff using without anyone in the business knowing.
- Google Workspace with Gemini – covered under Google’s existing Workspace data processing terms, which most UK businesses have already reviewed for email and Drive. Gemini for Workspace inherits those terms rather than introducing a new set of rules.
- Claude for Work (Anthropic) – offers a DPA, doesn’t train on business tier conversations by default, and has been increasingly popular with UK firms doing legal or financial document work because Anthropic publishes clear data retention windows.
- Grammarly Business – worth naming because it’s everywhere in UK offices and rarely gets scrutinised. The business tier has a DPA and lets admins turn off content used for product improvement. The free personal version, again, does not.
Notice the pattern. In every case it’s the business or enterprise tier that gets you the contract, the data controls, and the audit trail. The free or personal version of the exact same tool is usually where the risk sits.
Where it gets uncomfortable
Here’s the bit most guides on this topic skip over. Even a fully compliant tool, correctly configured, with a signed DPA and EU data residency, does not protect you if the problem is what your staff are typing into it. I worked with a marketing team last year who were using a licensed, business-tier AI writing tool, contract signed, settings checked, everything by the book. And someone was pasting entire customer complaint threads into it, full names, email addresses, order numbers, to get a “professional response drafted.” The tool was compliant. The use of the tool was not, because nobody had told staff what counted as personal data or trained them on what not to paste in.
You can buy the most compliant AI tool on the market and still breach GDPR within a week, because the compliance risk usually sits between the keyboard and the chair, not inside the software.
The ICO’s maximum fine under UK GDPR is £17.5 million or 4% of global annual turnover, whichever is higher, and while headline fines that size are rare for small businesses, the ICO has been increasingly active on AI-related complaints since 2024, mostly around unclear consent and undisclosed data sharing rather than the tools themselves.
The tools that need real caution
AI notetakers are the single biggest quiet risk I see in UK small businesses right now, and I’ve written a whole piece on why after seeing it play out on client calls, the AI notetaker consent problem is worth reading in full if you’re on video calls with clients regularly. Tools like Otter.ai and Fireflies.ai are useful, but many teams turn them on without telling the other party the call is being recorded and transcribed by a third-party AI system, which is a separate consent issue on top of the data processing question. Under UK GDPR you need a lawful basis for recording someone and for sending their voice and words to a US-based processor. “Nobody complained” is not a lawful basis.
Free-tier consumer AI tools generally sit in the same caution zone: free ChatGPT, free Grammarly, most browser AI extensions, and any AI feature bundled into free software that says data “may be used to improve our services” in the small print. If your staff have installed these off their own back because they’re useful, and plenty are, you have shadow AI running inside your business right now with none of it covered by a business contract.
A seven-step check before you roll out any AI tool
This is the actual process I take clients through, and it takes about half a day done, not the two-minute scroll through a privacy policy most people do instead.
- Find out exactly where the data is processed and stored (UK, EU, US, or elsewhere) and whether there’s a valid transfer mechanism if it leaves the UK, such as Standard Contractual Clauses or the UK-US Data Bridge.
- Get the actual DPA in writing, not a link to a general terms page. If a vendor can’t produce one on request, that tells you something.
- Check whether your inputs are used to train the vendor’s models by default, and switch this off if you can.
- Confirm the retention period. How long does the vendor keep your data after you stop using the tool or delete a conversation.
- Run a quick Data Protection Impact Assessment if you’re processing anything sensitive, special category, financial, or health-adjacent through the tool, even briefly.
- Write one page of plain-English staff guidance on what can and can’t be pasted into any AI tool. Not a 40-page policy nobody reads.
- Name someone internally who owns AI tool approval, so staff aren’t quietly signing up to free tools because IT never said no.
If you’re building this out across a whole team, it’s worth looking at what’s currently working well for other small businesses too, and I keep an updated rundown of the AI tools moving the needle for small businesses right now that flags which ones tend to come with proper business-tier data controls versus which are still consumer-first.
Sales, service, and analytics tools deserve the same scrutiny
This isn’t only about chatbots and writing assistants. If you’re using AI-enhanced sales prospecting tools that scrape or buy contact data, the GDPR question starts before the AI even touches it, because you need a lawful basis for holding that contact’s details in the first place. I go into this in more detail in the breakdown of sales prospecting tools and outbound sales, because outbound tools built on scraped data are a much bigger GDPR exposure than most AI writing tools will ever be.
The same logic applies to AI-powered customer service platforms. If you’re picking one for a UK business, data handling should be near the top of your checklist, not an afterthought once you’ve decided on features and pricing, which is why I put it early in what to look for in an AI customer service platform. And if you’re layering AI on top of booking systems that collect customer contact details and appointment history, the same due diligence belongs in how you choose a booking app suited to your business type, because a booking app holding names, phone numbers, and health or service details for years is exactly the kind of data an AI feature might later be pointed at without anyone reviewing consent again.
Even something as ordinary as your website analytics setup deserves a second look once AI enters the picture, because plenty of businesses don’t fully know what Google Analytics tracks on their website, and what it quietly misses, before adding an AI layer on top that processes that same visitor data for personalisation or lead scoring.
When to bring someone in
If you’re a small business trying to work all of this out alone, on top of running the business, it’s one of the areas where an outside pair of eyes pays for itself quickly, because a proper review of your current tools usually surfaces two or three quiet risks nobody had noticed. If that’s where you are, it’s worth reading through what an AI consultant for a small business does day to day, since a lot of the work is exactly this: checking contracts, tightening settings, and writing the one-page staff guidance most businesses skip.
Frequently asked questions
Is ChatGPT GDPR compliant for UK businesses?
ChatGPT Team, Business, and Enterprise tiers can be used compliantly because OpenAI offers a signed Data Processing Agreement and doesn’t train on your data by default. The free version and personal ChatGPT Plus don’t come with the same contractual protection, so the honest answer depends entirely on which tier your staff are using.
Do I need a DPIA before using AI tools in my business?
You need a Data Protection Impact Assessment if the AI tool processes personal data at scale or handles anything sensitive, such as health information, financial records, or special category data. For basic text drafting with no customer data involved, a lighter internal check is usually enough, but it’s worth documenting your reasoning either way.
Is Microsoft Copilot safer than ChatGPT for UK data protection?
Copilot for Microsoft 365 has an advantage for many UK businesses simply because it sits on top of a Microsoft 365 contract you likely already have, with the EU Data Boundary and existing data processing terms already in place. It’s not automatically safer than a licensed ChatGPT business account, but it’s often the quicker route to compliance if you’re already a Microsoft customer.
What’s the biggest AI and GDPR mistake UK small businesses make?
Assuming the tool being compliant means the usage is compliant. Staff pasting customer names, complaint details, or contact information into a licensed AI tool is still a data protection risk, because the gap is usually in training and awareness, not in the software itself.