Here is the answer nobody puts at the top of the page. No AI tool is GDPR compliant by itself. Compliance depends on what data goes in, the agreement you are on and how your team actually uses it. We help you get those three things right.
Why the tool alone is not the answer
The same product can be perfectly defensible in one business and a serious problem in the next. The use decides, not the logo.
What goes in
What data will be entered, and does it need to be? Often the job can be done with far less than gets pasted.
Would your clients expect it?
Why the data is being processed matters as much as where. If a client would be surprised to learn about it, stop and think.
Who can see it
Access inside your firm and at the supplier. Accounts, permissions, and what happens when a member of staff leaves.
Training and retention
Does the supplier use your data to train their models? How long is it kept, and can you actually delete it?
Where it lives
Storage and transfers. Whether your data leaves the UK or EU, and under what safeguards if it does.
The use decides
A tool that passes all of this for general admin may still be the wrong place for medical notes or a client’s financial file.
Consumer accounts are not business arrangements
Free and personal-tier AI accounts usually come with different terms, different data handling and no agreement that protects your clients. Business tiers can offer contractual commitments, admin controls and training opt-outs that the consumer product does not. Can, not do. The terms have to be read and the settings have to be set. We do this with you, in plain English.
Your staff are probably already using AI
In most small firms, someone is already pasting work into a free AI tool because it saves them an hour. The realistic response is not a ban. It is clear rules. Which tools are approved. What must never be entered. When a human has to check the output. How accounts and permissions are controlled. A one-page policy your team will actually read beats a fifty-page one they won’t.
Where this experience comes from
Carl Swift has spent 20 years running his own client-facing businesses. Client files, medical details, financial records, all handled under GDPR and the duty of care that comes with them. The judgement calls on this page are ones he has had to make for real, in his own businesses, with his own clients’ data. He now applies the same discipline to AI tools, including in the software he builds and runs today.
Verified on Credly · click the badge to check
What a review covers
On an Advice Call or a Technology Review Day we look at how you plan to use AI, or already do. Current and proposed tools. What data is involved and whether it needs to be. Supplier terms and settings. Practical controls and staff rules. And a clear flag on anything that needs a data protection specialist or a solicitor rather than a technology adviser. You leave with a written recommendation you own. See a sample.
The boundary, stated plainly: we provide practical guidance on choosing, configuring and using technology. We do not provide legal advice and we do not certify GDPR compliance. A review gives you guidance rather than a formal audit. We show you the direction and the practical steps, and where it helps we get hands-on, from setting up tools to building the missing piece. The day-to-day running stays with your business. Responsibility for compliance stays with your business, and where legal input is needed we will tell you.

