AI GovernanceData

Can You Put Customer or Employee Information Into AI?

11 minutes to readLast checked: 4 August 2026

IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.

The honest answer is: sometimes, under the right conditions — and the conditions matter more than the tool. UK data protection law does not ban AI, but it does treat sending personal data to an AI service as processing and disclosure that needs the same justification, care and paperwork as any other. This guide explains what changes the answer.

What counts as personal data

Personal data is any information relating to an identifiable living person — names, contact details, but also job titles, complaint histories, opinions about a person, and combinations of details that identify someone even without a name. Special-category data (health, ethnicity, religion, sexual orientation, trade-union membership, biometrics and genetics) carries extra conditions, and criminal-offence data has its own rules. Confidential business information is a separate category with its own guide: information can be highly sensitive without being personal data at all.

Roles: who is responsible for what

When your business decides to put customer or employee information into an AI service, your business is normally acting as a controller — it decides the purpose and means. The AI provider may act as your processor (processing only on your instructions, under a contract with data-protection terms) or as a separate controller for some purposes, depending on the service and settings. The distinction is not academic: it determines whose obligations apply and what the contract must say. Do not assume every AI tool is a processor in every relationship — check the service terms and data-processing agreement for the specific product and plan you use.

The questions that decide whether a use is acceptable

  1. 1Lawful basis — which of the UK GDPR lawful bases covers this use? Consent is only one of six; legitimate interests or contract performance are often more realistic, but each has conditions. Not every use of client data requires consent, and consent is not a magic fix where it cannot be freely given (for example, from employees).
  2. 2Transparency — would the people concerned be surprised? Privacy information should reflect what actually happens, including AI processing where it is material.
  3. 3Data minimisation — does the task need the personal data at all? Placeholders, redaction or summaries often work just as well.
  4. 4Retention — what does the provider keep, for how long, and can you delete it?
  5. 5International transfers — where is the data processed? Transfers outside the UK need an appropriate mechanism, and different services rely on different mechanisms; check the provider's current terms rather than assuming one rule fits all.
  6. 6Subprocessors — who else touches the data on the provider's behalf?
  7. 7Individual rights — could you still honour access, rectification and erasure requests for data sent to the tool?
  8. 8Security — does the service meet the standard you would demand of any other supplier handling this data?

Training settings are not the whole story

Switching off model training does not automatically make unrestricted personal-data use lawful or safe. Training is one risk among several — retention, access, transfers, security and your own lawful basis all remain. The relevant question is not simply whether the AI remembers the data. It is whether the organisation is permitted to disclose and process the data through that service.

Not all AI services are alike

Blanket rules like “never enter any personal data into any AI system” are neither accurate nor helpful. The risk profile differs enormously between a free public consumer account, a business subscription with a data-processing agreement, an enterprise platform with admin controls and contractual commitments, and a private deployment where data never leaves your environment. Anonymised information (where nobody can be identified) falls outside data protection law entirely; pseudonymised data (identifiers replaced but re-identifiable) is still personal data. An approved system designed for a specific processing purpose, used within a documented boundary, is a very different proposition from pasting a customer file into a free chatbot.

When a DPIA is needed

A data protection impact assessment is required for processing likely to result in high risk to individuals — and the ICO's examples include innovative technology, large-scale profiling and automated decision-making with significant effects. Screening candidates, monitoring employees or profiling customers with AI will often meet that bar. Even where a DPIA is not strictly required, a short written assessment is the cheapest insurance available: it forces the questions above to be answered before the data moves, not after.

Recruitment and employee monitoring deserve extra care

Employees and job applicants have less genuine choice than customers, which weakens consent and raises the transparency bar. The ICO has published specific guidance and audit findings on AI recruitment tools, and expectations around monitoring at work are detailed and firm. The dedicated recruitment guide in this hub covers this in depth.

Plain-English Takeaway

There is no blanket yes or no. Personal data can enter an AI service only when the business has a lawful basis, has told people what it does, has chosen a service whose terms and safeguards fit the data, and can still honour people's rights afterwards. If any of those fail, redact, anonymise or use a different tool.

Unsure whether your business is using AI safely?

Ask the IT Club Advisor about AI tools, data handling, staff use, supplier checks, prompting or human review.

Ask Your IT Question

Free to ask. No credit card. No sales pressure. Fair usage applies.

IT Club cannot provide legal advice. Questions requiring legal interpretation may be redirected to an appropriate qualified adviser.