Dark teal cover with a document-and-clock motif and the Good Transformer wordmark, for an article on what UK data protection law asks of a firm using AI on client data.
Data protectionAI regulationComplianceLeadership

GDPR and AI: what the law actually asks of your firm

On a paid business plan the main AI tools do not train on your client data. They store it, and some keep it indefinitely by default.

Good Transformer18 min read

On a paid business plan, the main AI tools do not train on your client data. Microsoft, Google, OpenAI and Anthropic all say so in their own documentation, on pages you can read today.

What they do is store it. Some of them keep it indefinitely by default, and there is a good chance nobody in your firm has ever looked at the setting.

This is worth an hour of your attention because UK data protection law changed twice this year and the official guidance has not caught up. The main reforms in the Data (Use and Access) Act 2025 took effect on 5 February 2026, and more followed on 19 June.

Meanwhile the ICO's own guidance on AI and data protection is still dated 15 March 2023 and carries a banner saying it "is under review and may be subject to change" because of that same Act.

One note before we go on: this is general information, not legal advice.

The rule about AI training on your data is out of date

The rule most firms were given is that you must never put client personal data into an AI tool, because the tool will train on it. On business and enterprise plans, that is no longer the position. Each of the four major providers has published the commitment:

Several qualifications come with that claim, and without them it turns into a new myth.

It is a promise about training, not about storage. Those are help pages rather than the contract, so the wording that binds your firm is in the data processing agreement it signed. Each vendor also chose its words carefully: Anthropic's promise opens with "By default", Microsoft's covers foundation models, and Google's rests on your own permission.

Not training is also not the same as nobody ever reading. OpenAI and Anthropic keep content for safety review and legal reasons, and if a member of staff rates a conversation, Anthropic stores the whole exchange for up to five years. Microsoft and Google hold the data inside your firm's tenant, where your retention policies and legal holds govern it. And none of it applies on a free or personal account.

The promises also say nothing about who else handles the data. Every one of these providers uses subprocessors and publishes a list of them, and where the data is held is a separate question again.

Google tells consumer users plainly that "A subset of chats are reviewed by human reviewers (including Google's trained service providers) to help improve Google services", and asks them not to enter "confidential information that you wouldn't want a reviewer to see".

So on the training question, the exposure does not come from the tools the firm licenses. It comes from the person doing client work on a personal login at nine in the evening. Our one-page rule on whether staff can put client data in ChatGPT covers the personal-account side.

A firm that refuses AI because of the training claim is protecting itself against the one thing the vendor has already ruled out in writing. If you want to check your own tools rather than take this on trust, our guide to the four things to check before you buy an AI tool shows where to find each answer.

The real issue is storage, not training

The defaults were not set with your retention schedule in mind.

Anthropic's own documentation is the most direct example: for Claude, "By default, data is retained indefinitely unless a custom retention period is set." The control that changes it is an Enterprise-plan feature, so a firm on the Team plan has no retention setting to change, only manual deletion of individual chats.

Google's privacy hub puts Gemini in Workspace at "90 days to indefinite, as determined by admins". For ChatGPT there is no single number: OpenAI says retention and deletion "are governed by the ChatGPT workspace plan, administrative settings, and the capabilities in use", which means somebody in your firm has to go and look at the setting.

Microsoft 365 Copilot is the one worth understanding properly, because there is no number of days to point to. Prompts and responses are stored in a hidden folder in the user's own mailbox, and Microsoft says that "In most scenarios, these messages aren't removed".

Deleting them is slower than it looks: even under a retention policy set to delete after one day, it "could take 16 days before the message is permanently deleted", and permanent deletion "is always suspended" where another retention policy or a legal hold applies.

Those Copilot interactions also "remain searchable by eDiscovery tools". A subject access request, a regulator's request or a piece of litigation now reaches your AI conversations as well as your email. If your retention schedule predates Copilot, it will not mention them.

Your published retention schedule says one thing and your AI tool is set to another, and the tool's setting is the one that applies.

What the law actually asks of you

The obligation is not about AI at all. It is about the ordinary questions you already have to answer for any supplier: what is your basis for using the information, who receives it, how long do you keep it, and where does it go.

Start with your lawful basis. Article 6 gives you three realistic options, and most firms need more than one.

Contract covers processing that is "necessary for the performance of a contract to which the data subject is party". In plain terms, it covers the person you have the contract with, or are about to sign one with, and nobody else. So where your client is a company, the individuals you deal with are not covered by it. That is narrower than most firms assume.

Legal obligation covers the checks you are required to run, including client due diligence under the money laundering rules, and the records you are required to keep.

Most firms rely on legitimate interests for the rest: the contacts at a corporate client, candidate data, and the personal data of third parties inside a client file.

Legitimate interests does not let you do whatever you like, and it is not difficult either. The ICO calls the assessment "a type of light-touch risk assessment" and sets out three parts: "identify a legitimate interest; show that the use of personal information is necessary to achieve it; and balance it against the interests, rights and freedoms of the person whose information you want to use."

Two of its lines bear directly on AI. If you can reasonably get the same result in a less intrusive way, this basis does not apply. And legitimate interests "is often not appropriate for using personal information in a way which is unexpected or high risk". In practice that covers any use your clients would be surprised by.

One requirement here is mandatory rather than advisory: "You must include details of your legitimate interests in your privacy information." If you rely on it and your notice does not say so, that is a gap you can close this week.

Which basis applies is your firm's decision, and you have to record it. Getting that decision checked once by a data protection adviser is worth more than guessing at it every time.

Then find the contract. Article 28 requires a written contract with anyone processing personal data on your behalf, setting out what they may do with it and on whose instructions. Your AI provider is one of those. Each of the major vendors publishes a data processing agreement, and on a business plan it usually applies automatically.

The work is to find yours, keep a copy, and read what it says about subprocessors and where data is held. That document, not a help page, is also what settles the training question for your firm.

Where a use is genuinely high risk, a lawful basis is not the end of it, and you may need an assessment before you start. We covered when a firm needs a DPIA separately.

Do you have to tell people you used AI?

This is the question we are asked most often, and the answer is narrower than either a flat yes or a flat no.

The words "artificial intelligence" appear nowhere in Article 13 or Article 14, the articles that say what a privacy notice must contain.

What they require is an accurate account of the processing: your purposes and legal basis, your legitimate interests where you rely on them, "the recipients or categories of recipients of the personal data", the position on transfers out of the UK, how long you keep the data, and for data you did not collect directly, where it came from.

Read that list again with your AI tools in mind. You probably do have new things to say. They are "who we share your information with" and "where it is held", not "we use AI".

Note the wording on recipients: categories are allowed, so the law does not force you to name your AI provider. Naming it is clearer, and we would name it, but that is a choice and not a duty.

There is one duty in those articles that does bear on AI, and the February reforms reset its trigger. Articles 13(2)(f) and 14(2)(g) require you to disclose the existence of automated decision-making "which is subject to the requirement to provide safeguards under Article 22C", and meaningful information about the logic in those cases.

That duty applies only where a decision is made with no meaningful human involvement and has a serious effect on someone. Drafting, summarising and research are below that threshold.

A first pass that a person signs off is below it only if the sign-off is real. The ICO's 2026 review of automated hiring found that it often is not: employers described their tools as decision support, and the evidence showed the tool doing the deciding while the human check amounted to a rubber stamp.

A privacy notice is owed to the person the data is about, not to the client paying your invoice. Where the personal data belongs to candidates, or to third parties inside a client file, the duty runs to them.

The conduct rules are a different matter. Data protection law does not make you announce AI use. Your own professional body may.

  • RICS has made it mandatory. Its professional standard, effective from 9 March 2026, says members and regulated firms using AI with a material impact on service delivery "must … make clear to clients, in writing and in advance of using those AI systems, when and for what purpose AI is to be used", with terms of engagement covering opt-out and redress.
  • The Bar Standards Board, in guidance valid from 18 May 2026, requires transparency where AI materially impacts the nature or scope of the service. It also says something unusually candid for a regulator: "In many circumstances, such disclosure may not be strictly required under UK law (e.g. GDPR)".
  • ICAEW recommends rather than requires. Its 2026 guidance for tax work says members should consider how much transparency to give, and its engagement-letter guidance, updated in March 2026, suggests stating whether AI tools will be used.
  • The SRA has no rule on it. Its 2023 risk report suggested firms tell clients when AI will be used on their case, and its compliance tips, updated in February 2026, say "It should always be made clear to clients where they are interfacing with AI". Both are guidance, not rules in the Standards and Regulations.

Put those together and you do not need a legal analysis. One accurate line in your privacy notice and one sentence in your engagement letter cover what the law generally requires, and cost you nothing.

If you are RICS-regulated, read the standard rather than borrowing that sentence. It asks for more: notice in writing and in advance of when and for what purpose the AI will be used, plus terms of engagement that cover opting out and redress.

ICAEW also asks members to think about what to say when the work is delivered, not only when it is taken on, and the Bar Standards Board expects a barrister to answer honestly if the client, the court or the Board asks.

While you are in the privacy notice, there is a recent change that is easy to have missed. Since 19 June 2026 the notice has had to tell people about their right to complain to you directly.

That right came with duties attached, and they are more than a line of text. Section 164A of the Data Protection Act 2018 requires you to make complaints easy to bring, "by taking steps such as providing a complaint form which can be completed electronically and by other means", to "acknowledge receipt of the complaint within the period of 30 days", and then without undue delay to respond and tell the person the outcome.

So the privacy notice line takes a minute. The route behind it takes an afternoon, and it applies to your firm whether or not you use AI.

The one place the rules bite hard

There is a narrow case where the duties are specific and testable, and you should know whether you are in it.

Where a significant decision about a person is made with no meaningful human involvement, Article 22C requires four safeguards. You must give the person information about the decision, let them make representations, let them obtain human intervention, and let them contest it.

The February reforms added a new lawful basis, recognised legitimate interests, covering a short list of pre-approved public-interest purposes such as emergencies and crime prevention. That new basis cannot support an automated decision of the kind described above.

So if you run an onboarding check that declines a prospective client with no human review, look at which basis your record names. Few small firms will have recorded the new one, so for most this is a quick check rather than real work.

Having those four safeguards in place does not by itself make the decision lawful. Special category data, the law's most sensitive tier, which includes health data, is restricted separately by Article 22B, and that is an area to take specialist advice on rather than work from a checklist.

The Equality Act still applies to anything that sorts people, regardless of what changed in February.

If any of this describes your firm, the mechanics are in our piece on the UK rules on automated decisions, which covers what counts as real human involvement.

What you can and cannot do with client data

Here are four everyday actions, with the honest position on each.

Action You can You must first You must not
Draft a client document with an AI assistant Use a licensed business account for client material, including personal data in the file Have a lawful basis recorded, and account for the provider in your privacy notice, by name or by category Use a personal or free account for client work; on those accounts conversations can be reviewed by people to improve the product
Record and transcribe a client meeting Record and transcribe with a business tool, and keep the transcript as a firm record Tell the people in the meeting before you start, and set how long transcripts are kept Leave the tool's default retention setting in place, or leave a transcript in a tool with no deletion date
Screen or rank CVs Use AI to summarise and to help you shortlist Make sure a person genuinely makes the decision, and give candidates the information Article 13 or 14 requires, depending on whether they applied to you directly Let the tool reject anyone with no real human involvement, unless you have all four Article 22C safeguards in place and the decision does not rest on the most sensitive data
Paste a CRM export into a chatbot Move client data into a tool your firm licenses and controls Check what the tool can reach, and confirm the export is no larger than the job needs Paste a bulk export into a consumer chatbot, which puts a copy outside every control you have

Two rows have a fuller post behind them: the meeting row on AI notetakers in client meetings, and the CV row on the automated-decisions piece above.

Nobody has been fined for using AI on client data

It is worth being straight about the level of risk, because most writing on this subject is not.

The ICO has issued no fine, no reprimand and no concluded enforcement action against any organisation for its use of generative AI. The closest it has come was a preliminary enforcement notice to Snap in October 2023, and that was about the risk assessment behind its AI chatbot rather than the chatbot itself. The ICO closed the case in May 2024, once Snap had produced an assessment the regulator was satisfied with.

Instead it has worked with employers directly: its 2026 review of automated hiring looked at more than thirty of them and ended in letters to sixteen organisations, all of which agreed to act.

That is not a reason to relax, because the regulator is not where the first consequence comes from. The sharpest UK consequences so far have fallen on solicitors and barristers referred to their regulators by the courts for putting unchecked AI output before a tribunal, and on parties whose cases were struck out or who paid costs for the same thing. None of it involved a complaint, a data breach, or any personal data.

In practice, expect the first hard question to come from a client, then your professional body, and only after that the regulator. A client asking where their data sits and getting a vague answer puts the relationship at risk, and it happens long before any enforcement process would.

For scale, the Cyber Security Breaches Survey 2025/2026, published on 30 April 2026 by the Department for Science, Innovation and Technology and the Home Office, found that of the businesses using AI, adopting it or considering it, 31% have no plans to put security practices in place to manage the risks. If that is you, you are not behind the field.

What to do this week

Three things, and none of them needs a lawyer.

Set a retention period wherever your plan gives you the control, matched to the periods you already tell clients about. In a ChatGPT workspace and in Google Workspace that is an admin setting. For Microsoft 365 Copilot it means a Purview retention policy, because there is no simple number to set. On Claude there is no control below the Enterprise plan, so record that in your retention note and be careful what staff put into Claude.

Close off personal and free accounts for client work, because that is where the real risk is.

Then update two documents: your privacy notice, which should account for the provider as a recipient and carry the right-to-complain wording, and your engagement letter, which needs one sentence about AI.

If you would rather map this properly, book a short call and we will go through where AI touches personal data in your firm and what each use needs.

Common questions

Does ChatGPT or Copilot train on our client data?

Not on a paid business or enterprise plan. Microsoft states that Copilot prompts and responses are not used to train its foundation models, and OpenAI states there is no training on business data by default. Both commitments are on their own documentation pages. The position is different on free and personal accounts, which is why client work belongs on the licensed account.

Do we have to tell clients we used AI?

Under data protection law, not as such. Your privacy notice has to say who receives the information and how long you keep it, which does mean accounting for your AI provider, by name or by category, but nothing requires the words "we used AI".

Your professional body is the tighter constraint: where AI has a material impact on the service, RICS requires written notice in advance, covering purpose, opt-out and redress; the Bar Standards Board requires transparency where AI materially impacts the service; and ICAEW recommends a line in the engagement letter. Outside RICS, one accurate sentence covers it.

Usually not, and reaching for consent often makes things harder. Consent has to be freely given and can be withdrawn, which is a poor fit for work you have been engaged to do. Most professional-services use rests on contract, legal obligation or legitimate interests instead. Where you do rely on legitimate interests, record the three-part assessment and say so in your privacy notice.


This is general information, not legal advice. Where personal data is sensitive, where a decision about a person is automated, or where you are unsure of your basis, take advice from a data protection specialist.

Work with Good Transformer

Turn this thinking into working practice.

Explore team advisory

Newsletter

Get new Insights by email

Practical notes on using AI with judgement, and the AI news leaders actually need. No hype, no spam, unsubscribe anytime.

Choose how often you want the digest

Keep reading