Your business can use AI. The GDPR does not forbid ChatGPT, Copilot, Gemini or an AI notetaker, and the EU AI Act does not either. What both laws ask is that you know which AI tools your team uses, what data goes into them, and that you have taken sensible measures. This article explains the issues and the measures, in that order.
Use AI with your eyes open
AI tools save small teams real time: drafting emails, summarising meetings, translating, writing code. Banning them rarely works. Staff who find AI useful simply switch to their personal account on their phone, and then you have the same risk with no control at all.
The better approach is the one you already take with other software: pick the tools you trust, set them up properly, and tell your team how to use them. AI is not a special legal zone. As soon as a name, an email address, a CV or a customer complaint goes into a tool, that is processing of personal data under the GDPR, with the same rules as your CRM or your accounting software.
Which laws apply
- The GDPR does most of the work. It applies to every AI use that involves personal data, whatever the tool. See the GDPR text on EUR-Lex.
- The EU AI Act adds a few duties for businesses that use AI (it calls them “deployers”). For a typical small business these are: supporting AI literacy among staff, transparency towards people who deal with your chatbot or see AI-generated content, and stricter rules if you use AI in high-risk areas such as hiring. See the AI Act on EUR-Lex.
- Your supervisory authority enforces the GDPR side: the GBA/APD in Belgium, the AP in the Netherlands, the CNIL in France, and the competent state authority or the BfDI in Germany.
The privacy issues AI raises for small businesses
1. Free and personal accounts
This is the most common problem. Free and personal versions of AI tools are usually offered under consumer terms: the provider decides what happens with your input, there is typically no processing agreement, and your input may be used to train the model unless someone switches that off. Business versions of the same tools generally offer a processing agreement and do not train on your data by default. Same tool, very different legal position.
2. No processing agreement
When an AI provider processes personal data on your behalf, Article 28 GDPR requires a processing agreement (often called a DPA). Without one, you have no contractual control over retention, security or sub-processors.
3. Data leaving the EU
Many AI providers are based in the United States or use servers there. Sending personal data to them is a transfer to a third country (Chapter V GDPR), which needs a safeguard such as the EU-US Data Privacy Framework or standard contractual clauses. Some providers now offer EU data storage, which is worth choosing where available.
4. Sensitive and confidential data
Health data, data about religion, ethnicity, sexual orientation or trade union membership (Article 9 GDPR), and data about criminal convictions (Article 10 GDPR) need extra protection. So does confidential business information covered by an NDA or professional secrecy. This kind of data should only go into an AI tool after a deliberate decision and with strong safeguards, if at all.
5. AI hidden inside tools you already use
AI is not only ChatGPT. Your email, video calls, CRM, helpdesk and accounting software increasingly have AI features built in: meeting transcription, automatic summaries, suggested replies, lead scoring. Meeting notetakers deserve special attention, because they record everyone in the call, including people outside your business, and the transcripts are kept.
6. Decisions about people
If AI decides on its own about a person with legal or similarly significant effects, for example rejecting a job applicant or refusing credit, Article 22 GDPR applies: the person has the right to human intervention and to contest the decision. AI used for recruitment, staff evaluation or credit scoring is also high-risk under the AI Act. Using AI to recognise the emotions of employees or applicants is banned outright under Article 5 of the AI Act.
7. Wrong answers about real people
AI tools can produce information that sounds right but is false. If that ends up in a customer file, a reference or an HR note, you are processing inaccurate personal data, which breaches the accuracy principle (Article 5(1)(d) GDPR). A human always checks AI output before it is used.
8. Transparency and rights
People have the right to know how you use their data (Articles 13 and 14 GDPR). If AI processes personal data of customers or staff, your privacy policies must say so. Access requests also reach AI chat histories, transcripts and AI-generated notes about the person, so you need to know where those are kept.
9. Mistakes and leaks
When someone pastes a customer list into a free chatbot, that can be a personal data breach. You must document every breach and notify the supervisory authority within 72 hours if it is likely to result in a risk to the people concerned (Article 33 GDPR).
What the AI Act asks of an ordinary small business
- AI literacy (Article 4). Since February 2025, businesses that use AI must take measures on AI literacy for staff who work with it. Following the amendments that entered into force on 27 July 2026, the duty is to take measures that support the development of AI literacy, suited to people’s roles. In practice: a policy, short training, and a record of both.
- Transparency (Article 50). Since 2 August 2026, people must be told when they are interacting with an AI system, such as a chatbot on your website, unless that is obvious. Deepfake images, audio or video must be labelled as AI-generated.
- High-risk uses (Annex III). If you use AI for recruitment, evaluating staff, or deciding access to credit or essential services, extra deployer duties apply from 2 December 2027: use the system as instructed, ensure human oversight, keep logs, and inform the workers and people affected.
- Banned practices (Article 5). Some uses have been banned since February 2025, including emotion recognition in the workplace.
Measures to take: a practical plan
- Make an inventory. Ask your team which AI tools they use, including free accounts, browser extensions, notetakers and AI features in existing software. You will likely find more than you expect.
- Decide per tool. For each tool, decide whether it is allowed, allowed with conditions, or not allowed, and whether personal data may go into it. Be specific about the account type: “ChatGPT” is not enough, “our company’s business account” is.
- Use business accounts. For tools that may receive personal data, use a business plan with a processing agreement, check that training on your data is off, and choose EU data storage where offered. Close or forbid personal accounts for work.
- Update your GDPR records. Add each AI tool that processes personal data to your records of processing and your list of processors, and check the transfer safeguard.
- Update your privacy policies. Mention AI processing in your customer privacy policy and your staff privacy policy where relevant. Add a clear notice to any chatbot on your website.
- Write a short AI policy. Tell staff which tools they may use, what they must never enter, that a human checks all AI output, and whom to ask before trying a new tool.
- Train your staff and keep a record. A short session or course for everyone, with more depth for managers and power users, covers your AI literacy duty. Keep a record of who completed it and who confirmed they read the policy.
- Check risky uses before you start. For AI in hiring, staff monitoring or evaluation, profiling, or sensitive data, do a DPIA first and make sure a human makes the final decision.
- Prepare for mistakes. Make it easy and blame-free to report a wrong paste, and treat it through your normal data breach procedure.
- Review regularly. Revisit the tool list and the policy at least once a year, and whenever you adopt a new tool or the rules change.
How to Create an AI Acceptable Use Policy for Your Business
A section-by-section guide to the internal AI policy described in step 6.
Read more arrow_forwardQuick rules for your team
- Use only the AI tools and accounts your business has approved.
- Do not enter personal data into a tool unless the tool list says it is allowed.
- Never enter health data, HR files, passwords or confidential client information into an AI tool that is not explicitly approved for it.
- Remove names and details you do not need before you paste text.
- Check every AI answer before you send, publish or file it.
- Do not let AI decide on its own about a person.
- Pasted something you should not have? Report it straight away and do not delete the conversation first.
If AI is used for hiring, read our article on using AI in recruitment. If you need to assess a risky use, our DPIA guide explains how.
GDPRWise scans your website, detects processing activities and third parties, and helps you build your complete GDPR file, including your processing register and processing agreements for the AI tools you use.