How does GDPR work when there is AI involved?
How would that work in terms of GDPR? It comes up on nearly every call in the UK, and rightly.
I am not a lawyer and this is not legal advice. It is what I have had to get right in practice, and where I have seen people caught out.
GDPR does not care that it is AI
This surprises people. The rules are about processing personal data, and they apply the same whether the processing is a script, a spreadsheet or a language model. There is no separate AI exemption and no AI-specific horror.
What changes with AI is the practical questions: where the data goes, who else processes it, and whether anyone could reconstruct a person from the output.
What actually needs doing
- Know your lawful basis for the processing you are already doing. Automating it does not change the basis, but it does mean somebody finally has to write it down.
- Have a data processing agreement with anyone who touches personal data on your behalf — including me, and including the AI provider. This is the one people miss.
- Minimise. If the tool does not need names to do the job, do not send names. This is both good compliance and good design.
- Know where it is processed, and be able to say so in a sentence.
- Keep a record of what the system did, so a subject access request is answerable.
The question people actually mean
One client asked, mid-project: have we got to sign some GDPR thing as well, obviously giving out people's details? Yes — and the fact that it was a surprise mid-project was my failure, not theirs. It belongs at the start.
Another asked why a rebuilt system raised GDPR questions the old one never had. Usually because the old one was never looked at properly. Rebuilding does not create the obligation. It just turns the lights on.
Got a version of this problem? Twenty minutes minimum, seven questions, and a one-page Bottleneck Blueprint within 48 hours. If it's not a fit, we'll say so.
Book a call →