AI Policy Maker

AI policy and UK GDPR

AI policy and UK GDPR

If staff use AI tools with personal data, your policy needs to make the boundaries clear. A GDPR-aware AI policy helps people understand what information can be used, which tools are approved, when human review is needed and when to ask for help.

Why AI policies should address personal data

AI tools can be useful for drafting, summarising, searching, analysing and decision support. They can also create data protection risk if staff enter personal data into tools that have not been assessed or approved.

A practical AI policy helps staff recognise when personal data is involved, what they must not do, and when a proposed AI use needs review before it goes ahead.

This works best when the policy is written in everyday language. Staff need to know what to do with emails, spreadsheets, meeting transcripts, case notes, tickets, customer records and other material they actually handle.

Public AI tools and personal data risk

Public AI tools can feel like ordinary websites, but staff may use them with information that belongs to customers, pupils, clients, patients, employees, volunteers or suppliers. That can create problems if the organisation has not approved the tool, the terms, the configuration or the purpose.

The safest default is simple: do not put personal data, special category data or confidential case information into public AI tools unless the organisation has explicitly approved that tool and use case.

Examples of personal data in AI prompts

Personal data can appear in prompts more easily than people expect. Staff may think they are asking for help with wording, summarising or analysis, while the prompt includes identifiable details that should not be entered into an unapproved AI tool.

Customer or client records

A support ticket, case note, complaint, legal matter or account history may identify a person even if the prompt feels routine.

Staff and HR information

Performance notes, absence information, disciplinary material or recruitment details should be handled with particular care.

School, charity or care records

Pupil, beneficiary, patient, citizen or safeguarding information should not be pasted into public AI tools without explicit approval and controls.

Meeting notes and transcripts

AI meeting summaries can contain names, opinions, decisions, health details, finances or confidential business information.

Approved vs unapproved AI tools

A GDPR-aware policy should separate approved tools from unapproved tools. The question is not simply whether a tool is popular or useful; it is whether the organisation has checked the terms, data handling, security, access controls and permitted use cases.

For example, an organisation may allow staff to use an enterprise AI tool for internal drafting, while prohibiting customer records or HR data in a public chatbot. Another organisation may approve Microsoft Copilot for some staff but require extra checks around permissions and sensitive files before wider rollout.

The AI policy template UK guide covers how approved tools, human review and staff responsibilities fit into the wider policy.

A simple GDPR-aware AI workflow

Staff do not need a long legal checklist for every AI task. They do need a short, memorable route for deciding whether AI is appropriate and when to pause for review.

Identify data Check whether the task includes personal or sensitive information
Use approved tools Match the data and task to an approved AI service
Minimise Remove identifiers or unnecessary detail where possible
Review output Check accuracy, tone, fairness and context
Record or escalate Keep evidence or ask for help where risk is higher

Practical examples for staff

GDPR-aware AI rules are easiest to follow when they are linked to real situations. The policy should give staff examples that match the work they do, not just abstract warnings about data protection.

Drafting an email

Use AI to improve a general draft, but remove names, account details, case history and anything that identifies a person unless the tool and use case are approved.

Summarising a complaint

A complaint may include personal data, opinions, health information or financial details. It should not be pasted into a public AI tool for summarising.

Analysing a spreadsheet

Check whether rows contain names, employee IDs, customer references, postcodes or other identifiers before uploading data to an AI service.

Using meeting transcripts

Meeting notes can include personal views, performance issues or confidential plans. Staff should use approved tools and review summaries before sharing them.

Lawful, fair and transparent use

A GDPR-aware AI policy should remind staff that AI use still needs a proper purpose. People should understand why AI is being used, what information is involved, whether the use is fair, and whether individuals need to be told about it.

This matters for everyday work as well as bigger AI projects. Even simple AI-assisted drafting can raise questions if staff include identifiable details that were not needed for the task.

The policy does not need to turn every staff member into a legal expert. It should give plain rules and a route for help, so people pause before using AI with information about customers, staff, pupils, patients, clients, volunteers or service users.

Before using AI with personal data

A simple pre-use checklist helps staff make better decisions before information is entered into an AI tool.

  • Is the AI tool approved for this type of work?
  • Is personal data actually needed, or can the task be done with anonymised or general information?
  • Does the information include special category data, safeguarding material, HR records or financial details?
  • Have access permissions, sharing settings and retention settings been considered?
  • Will the AI output be checked by a person before it is used?
  • Does the use case need data protection, security or leadership review first?

Employee responsibilities when using AI tools

Staff should not have to become data protection specialists to use AI sensibly, but they do need clear responsibilities. A policy should explain that staff must avoid unnecessary personal data, use approved tools, check outputs and ask for help when the use case is sensitive or unclear.

  • Use approved AI tools for work-related tasks
  • Do not enter personal data into public AI tools unless specifically approved
  • Remove identifying details where they are not needed
  • Check AI-assisted output before sharing or relying on it
  • Be transparent about AI use where the organisation requires it
  • Report accidental disclosures, unusual outputs or concerns promptly

What managers and policy owners should define

Staff rules work best when managers know what the organisation has actually approved. The policy owner should keep the rules connected to the approved tools list, training, incident reporting and review cycle.

  • Who owns the AI policy and approved tools list
  • Which AI tools can be used with no personal data, limited personal data or no personal data at all
  • Which uses need a DPIA or data protection review before launch
  • How staff should report accidental disclosure or unexpected AI behaviour
  • How updates will be communicated when tools, terms or working practices change

If you are separating policy rules from wider ownership and oversight, the AI policy vs AI governance guide explains how those layers fit together.

Human review and automated decision risks

AI output can be wrong, incomplete, biased or unsuitable. A policy should make clear that people remain responsible for checking AI-assisted work before it is used, shared or relied on.

If AI is used to support decisions about people, the organisation should take extra care. Higher-risk use may need a data protection impact assessment, clearer transparency wording and stronger human oversight before adoption.

Organisations working towards formal management systems may also want to connect this to information security controls. The AI policy for ISO 27001 guide explains how AI use can fit into approved services, risk assessment and accountability.

Example policy wording for personal data

A policy can include wording such as:

Staff must not enter personal data, special category data, confidential case information or identifiable customer, employee, pupil, patient, beneficiary or client material into public or unapproved AI tools. Personal data may only be used with AI tools where the tool, purpose and data protection controls have been approved by the organisation.

This wording should be reviewed and adapted to match the organisation's tools, risk appetite and legal obligations.

What to include in a GDPR-aware AI policy

  • Approved AI tools and whether personal data may be used with each one
  • Information that staff must not enter into public or unapproved AI tools
  • Rules for personal data, special category data and confidential information
  • Human review before AI-assisted work is used or shared
  • When to involve data protection, security, legal or senior leadership
  • Transparency expectations for staff, customers, service users or employees
  • How concerns, incidents, mistakes and unusual use cases should be raised
  • Review dates so the policy keeps pace with changing tools and guidance

FAQ

Common questions about AI policies and GDPR

Does every AI use involve personal data?

No. Some AI use may involve no personal data at all. The policy should help staff spot the difference and ask for review where personal data, sensitive information or decisions about people are involved.

Can anonymised information be used with AI tools?

Sometimes, but staff should be careful. Information is only truly anonymous if people cannot be identified from it, either directly or when combined with other information.

Does an AI policy replace a DPIA?

No. A policy gives staff everyday rules. Higher-risk AI projects may still need a data protection impact assessment and more detailed review before they are used.

Can AI tools be GDPR compliant?

They can be used in a GDPR-aware way where the organisation understands the tool, purpose, data involved, terms, security controls, transparency requirements and human review process.

Should we keep a list of approved AI tools?

Yes. An approved tools list helps staff understand which tools they can use, what each tool is approved for and what information must not be entered.

Should AI use be covered in staff training?

Yes. Training helps staff recognise personal data, avoid unnecessary disclosure, check AI outputs and understand when to ask for review before using a tool.

What should staff do if they are unsure?

The policy should give a clear route to ask for help, usually through a manager, data protection lead, security contact or another named owner.