Home » Using ChatGPT and Copilot at Work Without Breaking UK GDPR

Using ChatGPT and Copilot at Work Without Breaking UK GDPR

A practical guide to using ChatGPT and Copilot at work under UK GDPR: account tiers, DPIAs, privacy notices and the controls that protect customer data.

Person typing on a laptop displaying the ChatGPT interface, illustrating ChatGPT and Copilot use at work

Yes, your staff can use ChatGPT and Copilot at work without breaking UK GDPR, but only if you control what goes into the prompt and which version of the tool they use. UK GDPR (the data protection law that applies in Britain since Brexit, enforced by the Information Commissioner’s Office) does not ban AI chatbots. It governs personal data, so the risk is not the tool, it is the customer names, contact details, health notes and case files people paste into it.

The short version: pick a business or enterprise tier that does not train on your data, ban real client identifiers from prompts unless you have a clear reason and a lawful basis to use them, and write these rules down in a one-page policy everyone signs. Do that and the compliance risk of ChatGPT GDPR UK questions drops sharply. This guide walks through exactly what the law requires and the practical controls that satisfy it.

What UK GDPR actually requires when you use AI

UK GDPR applies whenever you process personal data, meaning any information that identifies a living person. A customer’s name and email is personal data. So is a photo, a phone number, a job reference or a complaint that names someone. The moment that data enters a chatbot, you are “processing” it, and the law has expectations.

Four principles matter most for AI use.

Lawful basis

You need a lawful reason to process personal data. For most small firms the relevant bases are legitimate interests (a genuine business need, balanced against the person’s rights) or contract (you need the data to deliver what you sold). You do not usually need consent to use AI as a general tool, but you do need a basis for the underlying activity. If the only reason the data is in the prompt is convenience, you probably have not thought this through.

Purpose limitation

Data collected for one purpose should not be quietly repurposed for another. Feeding a customer’s details into an AI to draft a reply is arguably part of serving them. Feeding your whole client list into a chatbot to “see what patterns it finds” is a new purpose you did not tell anyone about.

Data minimisation

Only use what you need. This principle is your best friend with AI, because most prompts do not need a real name at all. “Draft a polite chaser for an overdue invoice” works exactly as well as the version with the client’s name, address and account number in it.

Transfers outside the UK

Both OpenAI (ChatGPT) and Microsoft (Copilot) are US companies and may process data outside the UK. UK GDPR allows international transfers where appropriate safeguards exist, and the main enterprise providers publish the contractual terms that support this. For everyday business use with a paid business tier this is generally manageable, but it is a reason to prefer business and enterprise plans, which come with proper data processing terms, over personal accounts that do not.

Consumer accounts versus business and enterprise tiers

This is the single most important decision, and most firms get it wrong by default because staff sign up with a personal email.

The difference is not the quality of the answers. It is what the provider does with your prompts. On free and personal paid consumer accounts, providers have historically been able to use conversations to help train their models unless you turn that setting off. On business, team and enterprise tiers, the standard commitment is that your content is not used for training and is governed by a proper contract.

Retention also differs. Consumer accounts keep history to serve you and may keep it longer for abuse monitoring. Business and enterprise tiers give administrators control over retention and, on the top plans, the ability to reduce it.

Comparison of data handling by tier

Tier Trains on your prompts? Data control Best for
Free consumer (ChatGPT Free) Can, unless you opt out in settings Minimal; personal account only Personal use and learning, never customer data
Paid consumer (ChatGPT Plus, approx £20/month) Can, unless you opt out Personal settings, no admin oversight An individual’s own productivity, low-risk content
Business or team (ChatGPT Team, Copilot for M365, roughly £20 to £30 per user/month) No, by default under business terms Admin controls, data processing terms Most SMEs handling customer data
Enterprise (ChatGPT Enterprise, custom pricing) No Strong retention and audit controls, contract Larger firms, regulated or sensitive data

Prices are approximate, quoted per user, and change often, so check the vendor’s current page before you buy. OpenAI sets out its business commitments on its enterprise privacy page, and Microsoft publishes equivalent terms for Copilot. The practical takeaway: if staff touch customer data, put them on a business tier, not a personal one. If you are still choosing between providers, our comparison of Claude, ChatGPT and Copilot for non-technical owners weighs the data handling alongside the features.

Do you need a DPIA?

A Data Protection Impact Assessment (DPIA) is a written risk assessment you carry out before a type of processing that is likely to be high risk to people. It is not a form you file with the ICO. It is a document you keep, showing you thought about the risks and how you reduced them.

You genuinely need one when the AI use is high risk: large-scale processing of sensitive data, systematic profiling that affects people, monitoring, or handling children’s data. A solicitor feeding case files into AI, a clinic drafting from patient notes, or a firm scoring job applicants should do a DPIA and probably take legal advice too.

You probably do not need a full DPIA to let staff use a business-tier chatbot to tidy up emails and draft marketing copy with no real personal data in the prompts. Even then, a short note recording your decision is sensible. The ICO explains the threshold clearly in its guidance for organisations, and when in doubt, do the assessment; it is cheap insurance.

Special category and children’s data: extra care

Some data carries higher risk under the law. “Special category data” includes health, ethnicity, religion, sexual orientation, trade union membership and biometric data. Criminal offence data is treated with similar caution. Processing this needs an additional condition beyond your normal lawful basis, and the bar is higher.

The practical rule for small firms: keep special category data out of AI chatbots unless you have taken advice, documented a lawful basis and a DPIA, and are on an enterprise tier with the right contract. A throwaway prompt mentioning a customer’s illness or a client’s criminal matter is exactly the kind of thing that turns a minor slip into a reportable breach.

Children’s data deserves the same restraint. If you serve under-18s, do not put their details into general chatbots without proper assessment. The default should be no.

Your one-page acceptable use policy for AI

You do not need a 30-page policy. You need one page people will actually read and sign. Cover these points in plain English.

  • Approved tools. Name the exact tools and tiers people may use, for example “ChatGPT Team” or “Copilot in Microsoft 365”. Everything else is off-limits until approved.
  • What must never go in a prompt. Full client names paired with details, contact data, financial information, health or other special category data, passwords, and anything you would not email to a stranger.
  • Redaction first. Replace names with placeholders such as “the customer” or “Client A” before pasting anything.
  • Check before you send. AI output can be wrong or invent facts. A human checks anything that goes to a customer or the taxman.
  • Report mistakes fast. If someone pastes something they should not have, they tell a named person the same day, no blame.

Have every user sign it and keep the signed copies. If you are also formalising other staff processes, the same discipline appears in our checklist for hiring your first employee, where written policies and onboarding go hand in hand.

What to tell customers in your privacy notice

Your privacy notice already tells people what data you collect and why. If AI tools now form part of how you handle their data, your notice should reflect that in general terms. You do not need to name every prompt, but you should be honest that you use third-party AI and software providers to help deliver your service, that some may process data outside the UK under appropriate safeguards, and that a human remains responsible for decisions.

Transparency is a legal principle, not a nicety. A short, clear line about using reputable AI providers to draft and process communications is far safer than saying nothing and hoping nobody asks.

The practical controls that keep you safe

No client names in prompts

Make this the headline rule. Most business tasks do not need a real identifier. Train the habit of writing “a customer in Leeds who ordered last month” rather than the person’s name and order number.

Redaction habits

When you must include context, strip identifiers first. Swap names for labels, remove account numbers, and delete anything that would identify a person on its own. It takes seconds and removes most of the risk.

An approved-tool list

Decide centrally which tools and tiers are allowed, and block the personal free versions for work use where you can. This prevents “shadow AI”, where staff quietly use random apps you have never assessed. Choosing a small, sensible stack matters here as much as it does across the rest of your operations stack.

Audit and oversight

Business and enterprise tiers give administrators visibility of who has access. Review that access quarterly, remove leavers promptly, and keep your signed policies and any DPIAs together so you can show the ICO your workings if you ever need to. Pair this with basic security hygiene; our explainer on Cyber Essentials for UK small businesses covers the access and account controls that support all of this.

The mistakes people actually make

Most breaches are not exotic. They are ordinary and avoidable.

  • Using personal free accounts for work. Convenient, and the worst option for data handling. Fix it by moving everyone to a business tier.
  • Pasting whole documents to “summarise”. A contract or spreadsheet often carries names, salaries and account details the summariser never needed.
  • Assuming the AI forgets. Retention varies, and on consumer plans your words may be kept and reviewed. Do not rely on a chatbot to be discreet.
  • Trusting output blindly. AI invents plausible nonsense, including fake figures and fake case law. Every customer-facing or financial output needs a human check.
  • Ignoring document-borne threats. Malicious files can target AI assistants directly, as we explained in our piece on the Copilot AI worm hidden in Word documents. Treat unexpected attachments with the same caution you would any phishing.

Get these five right and you have removed the majority of real-world risk, no legal degree required. If you are only just starting, our guide to starting with AI without a tech team shows low-risk tasks to begin with.

Frequently asked questions

Are my prompts used to train the AI?

On free and personal paid consumer accounts, they can be unless you turn training off in the settings. On business, team and enterprise tiers, the standard commitment from the main providers is that your content is not used to train their models. This is the single biggest reason to move work use onto a business tier.

Do I have to tell customers I used AI?

There is no blanket rule that you must announce AI use in every email. UK GDPR does require transparency about how you process personal data, so your privacy notice should reflect that you use AI and software providers in general terms. If AI is making a significant decision about someone, be open about it and keep a human in the loop.

What happens if a staff member leaks customer data into a chatbot?

Assess whether it is a personal data breach. If it is likely to risk people’s rights, you may need to report it to the ICO within 72 hours of becoming aware, and possibly tell the affected individuals. Record what happened and what you did. This is exactly why a fast, no-blame reporting rule belongs in your policy.

Is Copilot safer than ChatGPT for UK data?

Neither is inherently safer; it depends on the tier and how you use it. Microsoft Copilot inside a paid Microsoft 365 subscription operates under your existing Microsoft data terms, which many firms already trust. ChatGPT on a business or enterprise plan offers comparable commitments. Our comparison of Copilot versus Gemini digs into the differences.

Can I use AI in customer service without breaking the rules?

Yes, with the same controls: a business tier, minimal personal data in prompts, human review of anything sensitive, and honesty in your privacy notice. Our guide to AI chatbots for customer service covers the practical setup, and the same redaction habits apply.

What to do next

  1. Move everyone off personal accounts. Put any staff who touch customer data onto a business or enterprise tier this month, and switch off training where you keep any consumer accounts.
  2. Write and sign the one-page policy. Use the points above, name your approved tools, and get every user to sign it. Keep the copies.
  3. Decide on a DPIA. If any AI use touches special category data, children’s data or automated decisions about people, do a DPIA and take professional advice before going live. Check the threshold on the ICO website.
  4. Update your privacy notice. Add a plain-English line about using reputable AI and software providers, and set a reminder to review access and retention every quarter.

This guide is practical information, not legal advice. For anything high risk, or if you are unsure whether your processing crosses the line, take advice from a data protection specialist before you proceed.