Strategy · Risk

AI and GDPR for Small Businesses: What You Can (and Cannot) Put Into ChatGPT

A plain-English guide to using AI tools without breaching data protection law — which data is safe to paste, which is not, and the four settings to fix this week

B Biztrategy Published 16 September 2026 · 9 min read

Someone on your team has already pasted a customer’s email into ChatGPT. Possibly this morning. In most small businesses this happens long before anyone writes a policy about it, and the owner only finds out when a client asks an awkward question on a renewal call.

The instinct is either to ban AI outright or to shrug and hope nobody notices. Both are bad answers. Data protection law does not prohibit using AI tools — it prohibits using them carelessly with other people’s data. That distinction matters, because the compliant version of AI adoption is roughly ninety per cent as useful as the reckless version, and it takes about an afternoon to set up.

This guide covers what actually changes when personal data goes into an AI tool, which data is safe to paste, which is not, and the specific settings to put in place this week. Note that this is about the GDPR — how you handle people’s data. It is a separate regime from the EU AI Act, which governs which AI systems you may build and deploy. This is practical guidance rather than legal advice; if you handle health, financial or children’s data at any scale, have your approach reviewed by a data protection lawyer.

Why GDPR applies the moment someone pastes

Under the GDPR, “personal data” is any information relating to an identified or identifiable person. That is a far wider net than most owners assume. A name is personal data. So is an email address, a phone number, an IP address, a photograph, a customer reference number you can trace back to someone, and a sentence like “the chap who runs the bakery on Mill Street complained again.”

When an employee pastes that into an AI tool, your business has disclosed personal data to a third party. In GDPR terms you remain the controller — you decided the purpose — and the AI provider is typically acting as your processor. That triggers three obligations, whether or not anyone has thought about them:

  • A lawful basis for the processing (Article 6). For most SMB uses this will be legitimate interests, but you have to have actually considered and recorded it.
  • A data processing agreement with the provider (Article 28). No DPA, no lawful processing — and missing DPAs carry fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher.
  • Transparency (Articles 13 and 14). Your privacy notice should say that you use AI services to process customer data and what role those providers play.

Here is the part that catches small businesses out. If your team is working from personal ChatGPT, Claude or Gemini accounts, there is no DPA — because your business is not a party to anything. Your employee accepted consumer terms in their own name. From a regulator’s point of view, personal data left your organisation into a contract you do not hold and cannot enforce. That is the single most common data protection failure in AI-adopting SMBs, and it is also the easiest to fix.

Three questions that decide whether a paste is lawful

Rather than asking your team to memorise articles, train them on three questions. They take four seconds and cover most day-to-day decisions.

1. Could this text identify a living person?

Directly, through a name or email address, or indirectly, through a job title plus a company, or a postcode plus an age. If the answer is yes, it is personal data and the next two questions apply.

2. Is the account we are using covered by a business agreement?

Business and enterprise tiers of the major AI tools come with a data processing agreement, standard contractual clauses for transfers outside the EEA, and a contractual commitment not to train on your content. Consumer tiers generally do not. This one distinction — company account versus personal account — is the highest-leverage control available to you.

3. Would I be comfortable if the person concerned read this prompt?

Not a legal test, but a reliable proxy. If pasting a client’s medical note, salary or complaint into a chatbot would need explaining, that is your signal to redact first.

What is usually safe to put into a general AI tool

It is worth being precise about how much remains open to you. On a business-tier account with a DPA in place, all of the following is ordinarily fine:

  • Anything you wrote yourself that contains no third-party personal data — marketing copy, service descriptions, website text, job adverts, blog drafts, process documentation.
  • De-identified customer scenarios. “A customer on our €49-per-month plan wants to downgrade mid-contract; draft a reply offering two options” contains no personal data at all.
  • Aggregated numbers. Monthly revenue, churn percentages, stock levels, average order value, quote win rates. Analysis of aggregates is one of the highest-value AI use cases for a small business and carries close to zero data protection risk.
  • Public information. A competitor’s published pricing page, a public tender document, published standards and regulations.
  • Your own operating detail. Workflows, checklists, templates, pricing logic. Commercially sensitive, perhaps, but not a GDPR question.

Most of the AI value available to an SMB sits in that list. The teams getting real results are drafting, summarising, restructuring and analysing — and usually do not need anybody’s name to do it.

What should never go in

Some categories should stay out of a general-purpose chatbot regardless of which tier you pay for, because the consequences of getting it wrong are out of proportion to the time saved:

  • Special category data (Article 9): health, biometrics, ethnicity, religion, political opinions, trade union membership, sex life or sexual orientation. This needs a specific Article 9 condition on top of your lawful basis, and the bar is high. Sick notes, occupational health reports and accident records all land here.
  • Payment card details, bank account numbers and identity documents. Passport scans, driving licences, IBANs.
  • Children’s data. If you run a tutoring business, a nursery, a sports club or a paediatric practice, treat anything relating to a child as the strictest category you hold.
  • Anything covered by a client confidentiality clause — which for consultants, accountants, agencies and law firms often means most client material, quite separately from GDPR.
  • Credentials. API keys, passwords, internal system URLs. Not a data protection matter, but the fastest route from a convenience to an incident.

Where you genuinely need AI applied to sensitive material — clinical notes, HR case files, regulated client records — the answer is not a general chatbot but a tool built for that purpose, with a DPA that names the data category and hosting arrangements.

The four settings to fix this week

  1. Move everyone onto a company account. Business tiers at the major providers run at roughly €22 to €28 per user per month and include the DPA, admin controls and the no-training-by-default commitment. For a five-person team that is around €1,500 a year to remove your largest AI compliance exposure. Then rule out personal accounts for work — properly, in writing.
  2. Check the training toggle. Business, enterprise and API tiers at the main providers are opted out of model training by default; consumer tiers are typically opted in unless the user changes it themselves. Verify the current state in your admin console rather than assuming, because these defaults move between releases.
  3. Set a retention period. Admin consoles let you cap how long conversations are kept. The GDPR’s storage limitation principle expects you to justify the period you choose; thirty or ninety days is defensible for most SMBs and quietly shrinks the blast radius of any future incident.
  4. Add one line to your privacy notice. Something close to: “We use third-party AI services to help draft communications and analyse business data. These providers act as our processors under contract and do not use your data to train their models.” Ten minutes of work, and it is the first thing a regulator — or an enterprise client’s procurement team — will look for.

Then record the decision. A half-page note listing which tools you approved, which data categories are permitted in each, and who signed off is not bureaucracy; it is the evidence that the Article 6 assessment actually happened. If your stack has grown past three or four tools, it is worth auditing your AI tool stack at the same time.

A one-page rule your team will actually follow

Long policies do not change behaviour. One memorable rule does. The version that works in small teams is a traffic light:

Green — paste freely: your own content, aggregated numbers, anonymised scenarios, public information.
Amber — company account only, redact names first: customer emails, supplier correspondence, CVs, meeting notes.
Red — never paste: health data, payment or identity documents, children’s data, client-confidential files, credentials. Ask before you act.

Print it. Put it in the onboarding pack. Repeat it at the start of every AI training session. A rule that fits on a fridge magnet gets followed; a twelve-page policy gets filed. If you want the fuller structure behind it, our guide to writing an AI usage policy includes a template and the pitfalls to avoid.

One habit is worth building alongside it: redact before you paste. Replacing “Maria Delgado at Ferrovia SL” with “the client” costs three seconds and converts an amber paste into a green one. Teams that do this reflexively barely have a compliance problem left.

The bottom line

Enforcement in this area is genuinely unsettled, and it is worth being honest about that. The Italian regulator fined OpenAI €15 million in late 2024 over ChatGPT’s legal basis, transparency and age verification — and in March 2026 the Court of Rome annulled the fine. The European Data Protection Board’s Opinion 28/2024 set out how supervisory authorities should assess AI models, but left much of it to case-by-case judgement. Anyone telling you the rules here are settled is selling something.

None of that uncertainty helps you, though, because it concerns the providers’ obligations rather than yours. Your position is simpler and much older than AI: you control your customers’ data, you need a lawful basis and a contract before handing it to anyone, and you need to be able to show your reasoning. That was true when you signed up for your CRM. It is equally true for your AI tools.

In practice that means one company account instead of five personal ones, a retention period, a line in the privacy notice, and a traffic-light rule your team can recite from memory. An afternoon’s work — after which the question stops being “are we allowed to use this?” and becomes the one that actually creates value: where in the business is AI worth using at all. Our guide to creating an AI strategy for your small business picks up from there.

Where does your business stand on AI?

Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.

Take the Free Quiz →