GDPR compliant AI tools: what a UK business has to check
· Updated · Written and maintained by Joaquín Trapero, Nonimo
There is no AI tool that is GDPR compliant, and there is no list anywhere that could honestly name one. The UK GDPR does not regulate software. It regulates organisations that decide why and how personal data gets processed, and in the chat window on your desk that organisation is yours. The tool is a supplier. Compliance is something your use of it either achieves or does not.
That is not a dodge, and it is not bad news. It means the question of GDPR and AI has an answer you can actually work through, rather than a brand you have to trust. There are eight things that decide whether a British firm can put client material near a general assistant, and every one of them has a document behind it that you can read in an afternoon.
This guide sets out those eight, then measures ChatGPT, Claude, Gemini and Microsoft Copilot against them using each company’s own published pages. It is not a ranking and it does not end with a recommendation, because the answer changes with the plan you are on and the work you do.
It ends with the paperwork instead, because that is what the Information Commissioner’s Office will ask for if anyone ever asks. If what you are actually worried about is something a colleague has already pasted, start with our guide on whether client data in ChatGPT is a data breach instead, and come back here afterwards.
Is there such a thing as a GDPR compliant AI tool?
No, and the phrase quietly swaps the subject of the sentence. A processor can offer terms that make it possible for you to comply. It cannot comply on your behalf, because most of the obligations concern your purpose, your lawful basis, your retention, your staff and what those staff type, not the software.
The practical consequence is that you can reach a defensible position with almost any of the mainstream assistants, and an indefensible one with all of them. It depends on decisions your firm makes, and the same decisions recur whichever product wins the procurement. It is also why the guides on AI and client data start from the question rather than the vendor.
Those three numbers are the reason this question arrives late. Some 55 per cent of employees say they already use AI for work or education, while only 35 per cent of businesses report using any AI technology, and 11 per cent have trained most of their people.
The gap between the first and second figures is staff acting alone. The third is what nobody got round to. By the time a partner asks which tool is allowed, the answer is usually that several are already in use, on accounts the firm did not choose. For a chartered accountant that gap is now an ethics question, since ICAEW’s code makes the accountant answerable for what trainees and clerks paste.
The ONS also breaks that use down by size, and the shape of it matters for everything below. Some 28 per cent of businesses with nine or fewer employees report using at least one AI technology, against 35 per cent across those with ten or more, and 49 per cent of those with 250 or more staff.
The smallest firms are not far behind the largest, and they are the ones least likely to have a data protection officer, a procurement process or anyone whose job it is to read a processor contract. That is the reader this guide is written for.
Who the UK GDPR actually puts the duty on
The UK GDPR works through roles. A controller decides the purposes and the means. A processor acts on the controller’s documented instructions. When your firm decides that summarising attendance notes is a good use of an assistant, your firm is the controller, and the obligations to have a lawful basis, to minimise, to inform people and to keep records land on you.
The ICO has been explicit that a contract does not settle this. In its fifth call for evidence on generative AI, on allocating controllership across the supply chain, it wrote that “whether an organisation is a controller, joint controller or processor is not necessarily determined by a contract”. So a vendor page describing itself as a processor is a starting point for your analysis, not the end of it.
What “compliant” is doing in a supplier’s sentence
Read the claim closely and it usually turns out to be narrower than it looks. It might mean the company has a data processing addendum available. It might mean it holds ISO 27001. It might mean it publishes a transfer mechanism. Those are all useful, and none of them is a statement about whether your firm’s particular use of the product is lawful.
We hold ourselves to the same rule, which is why nothing on this site says our own software makes you compliant. It cannot. The most any tool can do is reduce what leaves the building, and we come back to that, with its limits, further down.
The eight questions that decide whether your use is lawful
Here is the frame the rest of this guide uses. None of it is our invention: each row maps to a duty in the UK GDPR and to guidance the ICO has published. Work down it with one specific use in mind, such as “drafting client correspondence”, rather than “AI” in general, because the answers change with the task.
The first four are settled before anyone opens the application, by whoever signs the contract.
| The question, before you sign | Where it comes from |
|---|---|
| Who is the controller, and who is the processor? | Articles 4, 24 and 28 |
| Is there a written contract that binds the processor? | Article 28(3) |
| What is your lawful basis, and is there an Article 9 condition? | Articles 6 and 9 |
| Where is it processed, and is that a restricted transfer? | Chapter V, Articles 44 to 49 |
The second four are settled afterwards, by the settings you choose and the people who type.
| The question, once it is in use | Where it comes from |
|---|---|
| Does the provider train on what you send, and can you stop it? | Purpose limitation, Article 5(1)(b) |
| How long is it kept, and who inside the company can read it? | Articles 5(1)(e) and 32 |
| Have your people been told what may and may not be entered? | Articles 5(2), 24 and 32 |
| Can you show all of the above on paper? | Articles 30 and 35 |
Notice what is not on that list: the model, the benchmark scores and the interface. They matter to whether the tool is any good. They do not move a single one of these rows. A firm that has answered all eight for a modest product is in better shape than a firm that bought the best one and answered none, and that is the practical case for writing an AI policy before choosing anything at all.
Why the same tool gives different answers
The eight questions are stable. The answers are not, because they change with the plan, the account and the setting. The identical application, opened with a personal login instead of a work login, can flip the training question, the retention question and the reading question at once. That is the single most common reason a firm believes it has answered this question when it has not, and it is why this guide has a whole section on free and business accounts.
The four assistants, measured against the same questions
What follows is drawn from the four companies’ own documentation as it stood on 19 September 2026, when we read it for the guide on each product. Each name links to that guide, which sets out the detail and the exact source. Nothing here is a view about which is better.
Training and retention
| Product | Trains on your content | Retention on the consumer product |
|---|---|---|
| ChatGPT | Consumer yes, unless switched off; business no by default | Deleted content removed within 30 days |
| Claude | Consumer no by default, needs an explicit choice; business no by contract | 30 days after deletion, up to 5 years if you allow improvement |
| Gemini | Consumer yes with Keep activity on; Workspace no outside your domain | 18 months by default, 72 hours with activity off |
| Copilot | Consumer yes unless you opt out; work account no | 18 months by default on the consumer product |
Two things in that table are worth saying out loud. The first is that “does not train” is the row that gets all the attention and the least important of the four. It answers what happens to model weights. It says nothing about whether the text was stored, read or reachable by a court order, which are the three things a client would actually ask about.
The second is that the business answer is genuinely different from the consumer answer in all four cases, and that in each of them the difference rests on terms published with the business product rather than on a setting a user can flip. A contractual promise survives a menu redesign. A toggle does not.
Who can read it, and where it is processed
| Product | Who else can read a conversation | Where the data sits |
|---|---|---|
| ChatGPT | Business admins, and contractors reviewing for abuse | UK storage on eligible plans, no UK inference residency |
| Claude | Flagged content goes to safety review | Stored in the United States |
| Gemini | A subset is reviewed by human reviewers | No published region for Gemini processing |
| Copilot | Consumer: Microsoft states an opt-out is not available | EU Data Boundary named for EU customers only |
The Gemini row carries the bluntest line any of the four has published. Google’s privacy hub asks users not to enter confidential information they would not want a reviewer to see. That is a clear instruction from the supplier, and a firm that hands staff a consumer account and then puts client papers through it is acting against it.
The Copilot row carries the sharpest internal contrast. Microsoft says its Copilot services have opted out of the human abuse monitoring available in Azure OpenAI, while its consumer privacy FAQ says an opt-out of human review is not available. Same brand, opposite answers, and the only variable is which account somebody signed in with.
One last word about the table itself. Every cell in it has a date attached in the guide it links to, because every cell is a summary of a page the supplier can rewrite next month without telling anyone. Treat the table as a worked example of the method rather than a source of truth: the useful skill is knowing which four questions to ask, and where on a supplier’s site the answers live.
Free account, business account: the line that changes everything
If you take one operational thing from this guide, take this. The line that matters runs through the middle of each product rather than between them, and it is drawn by the account, not by the logo on the screen.
A consumer account is a contract between the provider and the individual. Your firm is not a party to it. There is no processor obligation owed to you, no instruction you can give, no audit right, no deletion commitment you can enforce and, when a client exercises a subject access request, nothing you can require the provider to do. The person typing has, in effect, engaged a supplier on your behalf without your firm’s knowledge.
A business or enterprise account changes the legal shape. Now there is a relationship between controller and processor, terms that can meet Article 28, administrative control over the workspace, and a route to delete. It also introduces something firms are often surprised by: your own administrators can generally see what staff typed, which is a feature rather than a fault, and one worth telling people about before they find out.
| The account someone signed in with | Is your firm a party to anything? |
|---|---|
| Free personal account | No. Consumer terms between the provider and the individual |
| Paid personal subscription | No. The same consumer terms, with a receipt |
| Business or enterprise account | Yes. Processor terms, admin control and a deletion route |
Nothing on the screen tells you which of those three you are looking at, and that is the whole difficulty. The window looks identical, the model answers identically, and the legal position is not remotely the same.
The awkward middle case
Someone expenses a paid personal subscription on the consumer tier, and because money changed hands everyone assumes the protections came with it. They did not.
The Solicitors Regulation Authority put this plainly in its warning notice of 17 August 2026: both free to use and paid for AI systems may pose risks to client confidentiality. Paying does not settle the question, and we set out the rest of that notice in our guide to client data and the breach test.
Microsoft adds one more wrinkle worth knowing about, because it catches people in the opposite direction: it lists users of Copilot inside Microsoft 365 on a Personal or Family subscription among those it does not train on, and says they will not even see the training setting. The detail is in the Copilot guide.
The contract: what Article 28 requires, and who gives you one
Article 28(3) says a processor must act under a contract that is binding in writing, and it lists what that contract has to cover. This is not a formality you can wave away with a purchase order, and it is the first document an insurer or a regulator will ask to see.
Four of the required terms constrain what the processor may do with the data.
| The required term | What you are looking for in the document |
|---|---|
| Documented instructions | The processor acts only on yours, transfers included |
| Duty of confidence | Everyone it authorises is bound to confidentiality |
| Security | The measures required by Article 32 |
| Subprocessors | None added without your authorisation, terms flowing down |
The other four are obligations it owes you when something is asked of you.
| The required term | What you are looking for in the document |
|---|---|
| Assisting with rights | Help answering subject access, erasure and the rest |
| Assisting with duties | Help with breach notification, DPIAs and prior consultation |
| End of contract | Deletion or return of the data, at your choice |
| Audits and information | Whatever you need to demonstrate compliance, and audits |
All four providers publish terms of this shape, and all four publish them with the business products rather than the consumer ones. That is the whole of the answer to “do we have a DPA”. You have one if you are on a plan that comes with one, and you do not if you are not, regardless of how careful your staff are being.
The clause people forget
Subprocessors is the term that bites in practice. Generative AI supply chains are layered, and a provider can add a model supplier without you noticing. Microsoft’s own documentation is a useful example of why this matters rather than an accusation: it states that models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary. Read your subprocessor list, and read it again when the product ships something new.
Reading a DPA in twenty minutes
You do not need a lawyer for a first pass. Search the document for the eight items above, in order, and write one line next to each saying where you found it. Then search for the words “transfer”, “subprocessor”, “retention” and “audit”, and read every paragraph that comes back. Keep the notes on retention and transfer, because the same answers fill the blanks in a client care clause that names the provider.
If any of the eight is missing, that is the question to send the supplier, and the answer belongs in your file whether or not you like it. The insurer’s version of this same exercise is covered in our guide to the AI questions on a cyber insurance questionnaire, which is worth reading first if a renewal is closer than an audit.
Transfers: the UK Extension, and who was on the list today
This is the section where UK answers and EU answers part company, and it is the section most pages on this topic get wrong by assuming they are the same.
The three step test, applied to a chat window
The ICO published a brief guide to international transfers on 15 January 2026, and it reduces the question to three steps. Does the UK GDPR apply to the processing you are sending? Are you initiating the transfer to an organisation outside the UK? Is the recipient a separate legal entity from you? Three yeses make it a restricted transfer, and the ICO adds that the rules apply to all restricted transfers, “even small, infrequent ones”.
Every restricted transfer must be covered by one of three things: UK adequacy regulations, appropriate safeguards under Article 46, or an exception under Article 49. The comfortable answer is adequacy, because nothing else has to be done. All the EEA states have full adequacy, which is why the entity you contract with matters so much.
Who you are actually contracting with
Each company’s own policy names a controller, and the answers split in a way that only shows up if you read them as a UK reader, because the UK is not in the EEA and each clause handles that differently.
| Product | Named controller for a UK user | What that means for transfers |
|---|---|---|
| ChatGPT | OpenAI OpCo, LLC, San Francisco | A restricted transfer to the United States |
| Claude | Anthropic Ireland, Limited, Dublin | Ireland has full adequacy; the US leg is Anthropic’s own |
| Gemini | Google LLC, Mountain View | A restricted transfer to the United States |
| Copilot | Microsoft Ireland Operations Limited | Ireland has full adequacy; onward legs are Microsoft’s |
Google’s policy is the one that says it in so many words, naming Google LLC for users of Google services based in the United Kingdom, with the Irish entity responsible only for the EEA and Switzerland.
What was on the Data Privacy Framework list on 20 September 2026
Where the transfer is to the United States, the UK has a partial adequacy finding called the UK Extension to the EU-US Data Privacy Framework. The Secretary of State laid the regulations under section 17A of the Data Protection Act 2018 on 21 September 2023, and they came into force on 12 October 2023.
The ICO states the condition in one line: you must only make a restricted transfer to a US business that has an active status on the Data Privacy Framework list. So we searched it, on 20 September 2026, across all 3,664 participants then on it.
Searching for Microsoft returns Microsoft Corporation of Redmond, active under the UK Extension while its certification is being renewed. Searching for Google returns Google LLC of Mountain View, active under the UK Extension. Searching for OpenAI returns nothing, and so does searching for Anthropic. The search matches covered entities as well as parent names, so a subsidiary listing would have shown up.
That is a checkable fact with a date on it, not a criticism, and anyone can repeat it in a minute. It has one practical consequence, and the ICO spells it out.
Where the US business is not on the list, you must put in place appropriate safeguards or rely on an exception, and if you use an Article 46 safeguard you must first complete a transfer risk assessment. OpenAI’s own Europe policy names the UK International Data Transfer Addendum, which is exactly that route. The mechanism exists. The work of adopting it and recording why it is adequate is yours.
Where this leaves a small firm
Two of the four route you through a Dublin entity, and Ireland has full adequacy, so the first hop is not a restricted transfer at all. Two route you to a US entity, one of which is on the list and one of which is not.
None of that makes a product unusable, and none of it is a reason to change supplier on its own. It changes which paragraph you have to be able to produce. It also changes how often, because the ICO asks you to carry out periodic checks on a recipient’s self-certification, and to act if it lapses by making sure the data already sent is still protected or returned.
What the ICO has said about GDPR and AI, and what it has not
The UK has no AI Act. It has a regulator applying existing data protection law, and, in short, the ICO has said a great deal about generative AI in consultations and rather less in finished guidance.
Its main Guidance on AI and data protection was last updated on 15 March 2023, which is before most of the products in this guide existed in their current form. It now carries a banner saying it is under review because of the Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025 and whose data protection provisions are in force.
That banner is not unique to the AI guidance. It sits on the pages below too, and anyone telling you the UK position is settled has not opened them.
| ICO guidance | Status on 20 September 2026 |
|---|---|
| AI and data protection | Updated 15 March 2023, under review |
| Contracts and liabilities between controllers and processors | Under review |
| Documentation, including the record of processing | Under review |
| Innovation advice, previously asked questions | Updated 16 December 2025, under review |
The answer on legitimate interests, and the Article 9 trap
The most useful published thing the ICO has for a firm in this position is buried in its innovation advice page of previously asked questions, updated on 16 December 2025. Someone asked whether legitimate interests would work as a lawful basis for using generative AI to draft responses to clients, where some of those emails contain special category data.
The ICO’s answer does two jobs. It says legitimate interests can work, but only if you can demonstrate the use is necessary and proportionate, and that it is not overridden by the rights of the people concerned.
Then it adds what catches firms out. Where special category data is involved you need a second condition under Article 9, and in that scenario the ICO suggests explicit consent. A medical report in an email attachment is special category data, and explicit consent from the person it concerns is a far harder thing to obtain than a lawful basis you can assert for yourself. An NHS clinic letter is special category data from its first line.
What is still missing
There is no ICO list of approved tools, and there is not going to be one, because a list like that would have to be rewritten every time a supplier changed a default. There is also no finished guidance written for a firm of eleven people using a general assistant.
What there is, and it is worth an hour, is the AI and data protection risk toolkit, which walks the same ground as our eight questions in the regulator’s own words. Public sector readers have considerably more to work with, and we have collected it in our guide to AI in local government.
What should never go into a chat window, whatever the plan says
Every section above is about the container. This one is about the contents, and it is the only part your staff will actually remember. The ICO’s position is that minimisation comes first, whatever your contract says: in the same innovation advice page it writes that if an organisation is able to anonymise the information, or remove identifiable information from the documents shared, then they should do so.
Elsewhere on the same page it goes further, and the sentence is worth having on a wall. Transfers should only be used where necessary, and if there is a way of achieving the same outcome without transferring personal information, that is what should be done. Applied to a chat window, that means the first question is not which tool, but whether the name needed to be in the prompt at all.
The categories worth naming in your own policy
| What must not go in | Why it is on the list |
|---|---|
| Names, references or addresses of a client or patient | Inside a small sector the case reference alone identifies |
| Special category data | Health, ethnicity, religion, politics, union membership, sex life, biometrics, genetics, plus Article 10 offence data |
| Anything privileged or under a duty of confidence | That duty exists outside data protection law and no lawful basis overrides it |
| Other people’s confidential material | Counterparty papers, drafts under an NDA, anything shared for one purpose |
| Credentials and keys | Not personal data, but worse, and the thing most often left in a chat history |
None of this means a firm can never use AI on real work: every one of those categories has a version with the identifying detail taken out, and the version with it taken out usually produces the same answer. Our guide on whether a paste is a breach covers what to do in the hour after this rule gets broken, which it will be.
The paperwork: the record, the policy and the DPIA
Accountability under Article 5(2) means being able to demonstrate compliance, and in practice that means having it on paper. Three pieces of paper cover almost all of it, and two of them are shorter than people fear.
| Document | Where it comes from | When you need it | What goes in |
|---|---|---|---|
| Record of processing | Article 30 | Use that is not occasional, is likely to risk people’s rights, or involves special category or criminal offence data | Six lines: the tool, whose data, why, lawful basis, retention, destination |
| DPIA | Article 35 | AI combined with any criterion from the European guidelines, such as sensitive data or vulnerable data subjects | An assessment of the high risk the processing is likely to create |
| AI policy | Article 5(2), accountability | Before anyone uses a tool on client work | Approved tools and accounts, what may not be entered, who to tell, acknowledged by everyone |
The record of processing, and the 250 employee trap
Article 30 requires a record of processing activities, and there is a widely misread exemption for organisations with fewer than 250 employees. The ICO sets out what it actually says: below that threshold you still have to document processing that is not occasional, or that is likely to result in a risk to people’s rights and freedoms, or that involves special category or criminal offence data.
Run an AI assistant across client correspondence every day and it is not occasional by any reading. Use it on files that contain health or criminal offence information and the third limb catches it too. The exemption does not apply to the thing you most want it to apply to, and the entry itself is a short paragraph: what the tool is, whose data goes in, why, on what basis, how long it is kept, and where it goes.
When a DPIA stops being optional
Article 35 requires a DPIA where processing is likely to result in a high risk. The ICO publishes a list under Article 35(4), and the first entry on it is innovative technology, defined as innovative technologies or the novel application of existing ones, including AI. A DPIA is required where that is combined with any criterion from the European guidelines.
Those criteria include sensitive data or data of a highly personal nature, processing on a large scale, matching or combining datasets, and data concerning vulnerable data subjects. The ICO notes that employees can count as vulnerable, because the power imbalance means they cannot easily object to processing by an employer. For most firms handling client files, the combination is met on the first criterion they look at.
The policy
The third document is the one that makes the other two true. It names which tools and which accounts are approved, says what may not be entered, says who to tell when something goes in that should not have, and gets acknowledged by everyone. Ours is free to take and adapt, in our AI policy template, and if you write your own, keep it to two pages, because a policy nobody finishes reading protects nobody.
What a masking tool does here, and what it does not, including ours
Everything above concerns the relationship with the supplier. There is a separate lever, and it sits earlier in the sequence: reduce what leaves the building in the first place. That is the job Nonimo does.
Nonimo is a Mac and Windows app that hides identifiers on their way out and puts the real names back when the answer comes home. It works on the machine itself, and the policy is set by IT rather than by each user.
What the British layer actually detects
Its UK layer covers NHS numbers, Unique Taxpayer References and driving licence numbers written after their label, National Insurance numbers with or without one, and postcodes.
It masks each of them in front of you, and you can undo any change. What it keeps is set out on Nonimo’s security page.
Where it does not help
Removing direct identifiers such as a name or an identification number is insufficient to ensure effective anonymisation, in the ICO’s own words. So a masked file is not anonymous, and what the regulator calls it instead decides whether the UK GDPR still applies to it.
Reduces the volume of identifying material you transfer, which is the step the ICO asks for where you can take it.
Makes the rule about what never goes into a chat window enforceable.
Give you a lawful basis, a contract, a transfer route or a record.
Take a pseudonymised document outside the UK GDPR: it is still personal data.
A pseudonymised document is still personal data, and every duty in this guide still applies to it. For a fit note or a payslip with a union line, that includes the extra condition special categories need.
Team deployment is on our organisations page, resellers and advisers are on the partners page, and the terms are on the licence page.
The two questions that arrive from outside
Two other parties will ask about this before your regulator does, and both have shorter deadlines.
The first is your insurer. Cyber proposal and renewal forms now carry AI questions, and they are worded in a way that turns a casual yes into something closer to a promise about how your firm operates. Under the UK rule on fair presentation of the risk, a wrong answer there can cost you a claim later, long after everyone has forgotten who filled the form in.
Answering those questions well needs exactly the three documents set out under the paperwork above, which is the practical argument for producing them even if you think the regulator will never call. We set out the questions and how to answer them without overstating in our guide to the AI questions on a cyber questionnaire, and the market itself in the UK cyber insurance comparison.
The second is the EU AI Act, which reaches some British businesses despite the name. It does not replace anything in this guide, because it regulates AI systems and their risk, not personal data. If you place output on the EU market or have users there, our guide on whether the EU AI Act applies outside the EU sets out who is caught and when.
If you buy nothing at all, do these five things
- Decide which accounts are allowed and say so in writing. One line naming the approved product and the work login closes the largest gap in this guide, and it costs nothing. The policy template has the wording.
- Find the processor terms for the plan you are actually on. Not the plan on the marketing page. Save the PDF with the date you downloaded it.
- Write the record entry. Six lines: the tool, whose data, why, lawful basis, retention, destination. Most firms will find they needed it under the “not occasional” limb.
- Check the transfer route once and diarise the recheck. If the recipient is a US entity, look it up on the Data Privacy Framework list and note the status and date. If it is not there, find the Article 46 safeguard the provider offers and record your transfer risk assessment.
- Tell people what never goes in. Five categories, one page, acknowledged. The other four things fail without this one, because the rules in the guides on ChatGPT and Gemini only bind what people actually type.
Two things you will read elsewhere that are wrong today
Both of these were in circulation on pages about UK firms when this guide was written, and both are answered by the regulator in its own words.
- “The provider is certified, so the tool is compliant.” Data Privacy Framework participation is a US self-certification about receiving transfers, renewed annually, and the ICO could hardly be clearer about its scope: the UK Extension is only a transfer mechanism, and you must also comply with all the UK data protection principles and all the other applicable requirements when you transfer personal information. It answers one of the eight questions in this guide and is silent on the other seven.
- “The EU decision on the United States covers our transfers too.” It does not. The ICO updated its adequacy guidance on 30 July 2026 specifically to say so, adding that this has always been the case. The UK Extension is a separate arrangement, made by a UK Secretary of State under UK legislation, and a US business can be certified under the EU-US framework without being covered by the UK Extension.
If you are copying a transfer analysis from an Irish or a German source, that second line is the one to check before you file it. The Claude guide shows how differently the same company’s policy reads from the two sides of that border, and the Gemini guide does the same for a provider whose policy names the United Kingdom explicitly.
Sources
Checked 20 September 2026.
- ICO, A brief guide to international transfers, last updated 15 January 2026. The test in three steps, the definition of a restricted transfer, the statement that the rules apply to small and infrequent transfers, and the three routes of adequacy, appropriate safeguards and exceptions.
- ICO, How does the UK Extension to the EU-US Data Privacy Framework work?, last updated 30 July 2026. The requirement to transfer only to a US business with active status on the Data Privacy Framework list, the periodic check duty, the line that the UK Extension is only a transfer mechanism, and what to do when the recipient is not on the list.
- ICO, Adequacy regulations, last updated 30 July 2026. The list of countries with full adequacy, including every EEA state, and the clarification that the UK’s adequacy regulations for the US are independent of the EU’s finding.
- Data Privacy Framework list, US Department of Commerce. Searched on 20 September 2026: 3,664 participants in total, Microsoft Corporation and Google LLC both active under the UK Extension, and no results for OpenAI or for Anthropic. The search matches covered entities as well as parent names, checked with two positive controls.
- UK-US data bridge: explainer, Department for Science, Innovation and Technology, 21 September 2023. The decision under section 17A of the Data Protection Act 2018, the regulations in force from 12 October 2023, and the statement that data bridges are not reciprocal.
- ICO, Innovation advice: previously asked questions, last updated 16 December 2025. The legitimate interests answer for generative AI drafting and the Article 9 condition that follows it; that organisations should anonymise or remove identifiable information from documents shared where they can; that transfers should only be used where necessary; and that removing direct identifiers is insufficient for effective anonymisation.
- ICO, Generative AI fifth call for evidence: allocating controllership across the generative AI supply chain. The line that whether an organisation is a controller, joint controller or processor is not necessarily determined by a contract.
- ICO, Guidance on AI and data protection, updated 15 March 2023 and currently under review because of the Data (Use and Access) Act.
- ICO, AI and data protection risk toolkit. The regulator’s own walkthrough of the same ground as the eight questions above.
- ICO, When do we need to do a DPIA?. Innovative technology including AI as the first entry on the Article 35(4) list, the requirement to combine it with a criterion from the European guidelines, the nine WP29 criteria, and employees as vulnerable data subjects.
- ICO, Who needs to document their processing activities?. The threshold of 250 employees and the three limbs that survive it: not occasional, likely to result in a risk, or involving special category or criminal offence data.
- ICO, Contracts and liabilities between controllers and processors. The minimum required terms under Article 28(3), in the order used above.
- UK GDPR, Article 28, Article 30 and Article 35, legislation.gov.uk. The processor contract, the record of processing activities and the data protection impact assessment.
- Data Protection Act 2018, section 17A, legislation.gov.uk. The power under which the UK adequacy regulations for the US were made.
- ICO, Data (Use and Access) Act 2025. Royal Assent on 19 June 2025, and that all the provisions affecting data protection law are now in force.
- SRA, warning notice Misuse of AI, 17 August 2026. The line that both free to use and paid for AI systems may pose risks to client confidentiality.
- ONS, Artificial intelligence in UK businesses: 2023 to 2026, released 20 July 2026. Business use of at least one AI technology rising from around 12 per cent to around 35 per cent since late 2023; 28, 35 and 49 per cent by size band; 55 per cent of employees reporting AI use for work or education; and 11 per cent of businesses with ten or more employees reporting that more than half the workforce has had training related to AI.
- The four providers’ own documentation, read on 19 September 2026 for the guide on each product, which carry the exact citations: OpenAI’s Europe privacy policy and enterprise privacy pages, Anthropic’s privacy policy and commercial terms, Google’s Gemini Apps privacy hub and privacy policy, and Microsoft’s Copilot privacy and enterprise data protection documentation.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Is any AI tool GDPR compliant?
No tool is compliant on its own. The UK GDPR places the duties on the controller, which is your organisation, and the ICO states that whether an organisation is a controller is not necessarily determined by a contract. Compliance describes a use, not a product.
Is ChatGPT GDPR compliant for a UK business?
The question is whether your use of it is. On a business plan OpenAI states it does not use your business data for training by default, but its Europe policy names OpenAI OpCo, LLC in San Francisco as the controller for UK users.
What do I need in place before staff use AI on client files?
A written processor contract that meets Article 28, a lawful basis, a record of the processing, and a written rule about what may be entered. Add a DPIA where the ICO's triggers are met, and a transfer route for data leaving the UK.
Does the UK-US data bridge cover ChatGPT?
Not on the face of the list. The ICO says you may only rely on the UK Extension for a US business with active status on the Data Privacy Framework list, and a search of that list for OpenAI on 20 September 2026 returned no results.
Do I need a DPIA to use AI at work?
Often, yes. The ICO lists innovative technology including AI as requiring a DPIA when combined with any criterion from the European guidelines, such as sensitive data, processing on a large scale or vulnerable data subjects. Employees can count as vulnerable.
Does a free account come with a data processing agreement?
Generally not. Article 28 requires a written contract binding the processor, and the four providers publish those terms with their business and enterprise products. A personal account has consumer terms of use, which are a different thing.
Does a small firm need a record of processing activities?
Probably. The ICO says organisations with fewer than 250 employees need only document processing that is not occasional, is likely to risk people's rights, or involves special category data. Daily use of an AI tool on client files is not occasional.
Does removing names from a document make it safe to paste?
It helps, and the ICO encourages it, but no. The ICO states that removing direct identifiers such as a name or an identification number is insufficient to ensure effective anonymisation. What you are left with is usually still personal data.
Is there a certification that makes an AI tool GDPR compliant?
No badge does that job. Data Privacy Framework certification is a US self-certification about transfers, and the ICO states plainly that the UK Extension is only a transfer mechanism, so all the other UK requirements still apply to you.