Practical rules for using ChatGPT and similar tools with customer data in a UK business: which accounts to use, what never to paste in, and a simple policy your team can follow.

It can be, but not by default and not on a personal account. Using ChatGPT or a similar AI tool with customer data is only sensible if you use a business plan with the right settings, share the minimum data needed, have a lawful reason to use it that way, and tell staff clearly what they may and may not paste in. Your data protection obligations under UK GDPR still apply when the processing happens inside an AI tool. This guide is practical, not legal advice; check your specific obligations with the ICO’s guidance or a qualified adviser.

The main risks

  • Where the data goes. Anything you type is sent to the provider’s servers, which may be outside the UK.
  • How it is used. Some consumer accounts allow conversations to be used to improve the provider’s models unless you switch that off.
  • Who can see it. Shared logins, browser extensions and chat history can expose data to people who should not have it.
  • Accuracy. AI can produce confident, wrong statements about a real person, which is a data accuracy problem as well as a customer service one.
  • Loss of control. Once staff copy data into a personal account, the business has no record of it and no way to delete it.

Business accounts versus consumer accounts

In general terms, the main AI providers offer consumer plans for individuals and separate business or enterprise plans for organisations. Business plans typically come with a contract or data processing terms, admin controls over who has access, and a commitment not to train models on your content by default. Consumer plans are designed for personal use, and their settings and terms are different.

Terms change, so do not rely on a blog post, including this one. Before you approve any tool, read its current business terms and check where data is stored, how long it is kept, whether it is used for training, and whether the provider will act as your data processor under a written agreement.

What not to paste in

Even on a business plan, some information should stay out of general AI tools unless you have a specific, reviewed reason:

  • Passwords, access codes and API keys.
  • Bank details, card numbers and full financial records.
  • Health information, or anything about ethnicity, religion, sexuality, criminal records or other special category data.
  • Information about children.
  • Full customer lists or database exports.
  • Documents covered by a confidentiality agreement or legal privilege.
  • Staff HR records, grievances or disciplinary notes.

Where you can, remove names and identifying details first. “A customer in Kettering ordered the wrong size and wants a refund” is usually enough context for a good draft reply.

A simple usage policy

A one-page policy that people actually read beats a long one that nobody opens. A starting point:

  1. Approved tools only. List the AI tools the business has approved, on business accounts. No personal accounts for work.
  2. Minimum data. Share only what the task needs. Remove names and identifiers where possible.
  3. Never paste. Include the list above.
  4. A person checks. AI output is a draft. Someone reviews it before it reaches a customer or is relied on for a decision.
  5. Be open with customers. Update your privacy notice to explain how you use AI tools, if it involves their data.
  6. Report mistakes. If someone pastes something they should not have, they tell a named person straight away, without fear of blame.
  7. Review it. Look at the policy again every few months, because the tools change.

Before you connect AI to your systems

Copying and pasting is one thing. Connecting an AI tool directly to your CRM, inbox or files is another, because it can then read far more than any one person would paste. Before that happens, agree in writing:

  • Which data sources it can read, and which it cannot.
  • What it is allowed to write, send or change.
  • Where a person must approve an action.
  • Where data is stored and for how long.
  • Who owns the prompts, workflows and outputs.

You may also need a data protection impact assessment if the processing is likely to be high risk; the ICO’s guidance explains when. This is how I work on any agents and automation project: boundaries, review points and ownership are agreed before any data source is connected. The responsible AI page sets out the approach in more detail.

Training your team

Most data leaks through AI tools are well-meaning people trying to save time. A short session with real examples from your own business, covering what is fine, what is not and why, does more than a policy on its own. That is a core part of team enablement.

If you want help choosing a tool, writing a policy or planning a safe first project, get in touch. I can help with the practical side, and point you to a qualified adviser where you need a legal view.

More insights

All insights