AI & GDPR

Looking for GDPR compliant AI?

Straight answers on AI
and sensitive data

Here is the answer nobody puts at the top of the page. No AI tool is GDPR compliant by itself. Compliance depends on what data goes in, the agreement you are on and how your team actually uses it. We help you get those three things right.

Why the tool alone is not the answer

The same product can be perfectly defensible in one business and a serious problem in the next. The use decides, not the logo.

What goes in

What data will be entered, and does it need to be? Often the job can be done with far less than gets pasted.

Would your clients expect it?

Why the data is being processed matters as much as where. If a client would be surprised to learn about it, stop and think.

Who can see it

Access inside your firm and at the supplier. Accounts, permissions, and what happens when a member of staff leaves.

Training and retention

Does the supplier use your data to train their models? How long is it kept, and can you actually delete it?

Where it lives

Storage and transfers. Whether your data leaves the UK or EU, and under what safeguards if it does.

The use decides

A tool that passes all of this for general admin may still be the wrong place for medical notes or a client’s financial file.

Consumer accounts are not business arrangements

Free and personal-tier AI accounts usually come with different terms, different data handling and no agreement that protects your clients. Business tiers can offer contractual commitments, admin controls and training opt-outs that the consumer product does not. Can, not do. The terms have to be read and the settings have to be set. We do this with you, in plain English.

Your staff are probably already using AI

In most small firms, someone is already pasting work into a free AI tool because it saves them an hour. The realistic response is not a ban. It is clear rules. Which tools are approved. What must never be entered. When a human has to check the output. How accounts and permissions are controlled. A one-page policy your team will actually read beats a fifty-page one they won’t.

Where this experience comes from

Carl Swift has spent 20 years running his own client-facing businesses. Client files, medical details, financial records, all handled under GDPR and the duty of care that comes with them. The judgement calls on this page are ones he has had to make for real, in his own businesses, with his own clients’ data. He now applies the same discipline to AI tools, including in the software he builds and runs today.

Nebius Academy AI Performance Engineering Fellowship badge

Verified on Credly · click the badge to check

What a review covers

On an Advice Call or a Technology Review Day we look at how you plan to use AI, or already do. Current and proposed tools. What data is involved and whether it needs to be. Supplier terms and settings. Practical controls and staff rules. And a clear flag on anything that needs a data protection specialist or a solicitor rather than a technology adviser. You leave with a written recommendation you own. See a sample.

The boundary, stated plainly: we provide practical guidance on choosing, configuring and using technology. We do not provide legal advice and we do not certify GDPR compliance. A review gives you guidance rather than a formal audit. We show you the direction and the practical steps, and where it helps we get hands-on, from setting up tools to building the missing piece. The day-to-day running stays with your business. Responsibility for compliance stays with your business, and where legal input is needed we will tell you.

Before you switch it on, talk to us

Handling client, financial or medical information? Start with a free 20-minute fit call before you switch anything on.