Somebody in your business has already pasted a customer's email into ChatGPT. I'd put money on it. The real question in 2026 isn't whether AI touches your customer data, it's whether you've noticed, and whether what you're doing with it would survive a complaint to the ICO.
Here's the short version before I go deep. There is no separate AI law in Britain. AI and customer privacy laws for small businesses come down to UK GDPR, the Data Protection Act 2018 and the marketing rules in PECR, all of which were reshaped on 5 February 2026 by the Data (Use and Access) Act 2025. The Information Commissioner's Office, the ICO, is the regulator that matters. If you sort out four things, which tools you use, what data goes into them, whether a machine is making decisions about people, and what you tell customers, you'll be in better shape than most of your competitors.
I've spent the last few years helping owners of ten person firms, and plenty of one person firms, put AI into daily work without creating a mess. This is what I've learned.
Why This Landed On Your Desk This Year
Two things changed in 2026 and they pull in opposite directions. The law got more permissive about some AI uses, and the penalties for getting marketing and data handling wrong got much larger.
On the permissive side, the Data (Use and Access) Act, which everyone shortens to the DUAA, opened up the lawful bases you can rely on for significant automated decisions and relaxed cookie consent for analytics and functionality cookies. On the punitive side, the maximum fine under PECR, the Privacy and Electronic Communications Regulations that govern email and text marketing, jumped from £500,000 to £17.5 million or four percent of global turnover, whichever is higher. As the solicitors at Bratby Law put it, the old cap let some firms treat a PECR fine as a cost of doing business, and that calculation no longer works.
Adoption is no longer fringe. The ONS Business Insights and Conditions Survey for June 2026 found 29 percent of UK businesses using at least one AI technology, and among the smallest firms with zero to nine employees the figure was 28 percent, so this is not a big company story. The government's own UK Business Data Survey 2026 put AI use at 40 percent among sole traders and 41 percent among micro businesses that handle digitised data. Whatever number you trust, a lot of small firms are doing this, and most of them have never read a line of the ICO's guidance.
According to the compilation of UK adoption research by Whito, 49 percent of small firms that haven't adopted AI cite data privacy as their worry. I'd rather you understood the rules than avoided the tools.
The Rules That Actually Apply In Britain
Half the articles ranking for this topic are American and quietly assume you're in California, so let me clear that up first.
You are governed by UK GDPR, which is our retained version of the European regulation, and by the Data Protection Act 2018 which sits alongside it. PECR covers electronic marketing and cookies. The DUAA amends all three but replaces none of them, which is good news: if you were broadly compliant last year you are not starting from scratch. The EU AI Act only bites if you're selling AI powered products or services into the EU, and even then most of its high risk obligations were pushed back to December 2027 in May 2026. For a Bristol accountancy practice or a Leeds plumbing firm, it's a footnote.
Your regulator is the ICO, currently being reconstituted as the Information Commission, though you don't need to re-register. It has published dedicated guidance on AI and data protection, and its Explaining Decisions Made with AI guidance is the operating standard for anything that makes automated decisions about people. It's readable and free.
Three principles from that guidance matter most. First, you need a lawful basis for any personal data an AI tool processes, and for most internal small business use that basis is legitimate interests, which means writing a short Legitimate Interests Assessment, an LIA, explaining why your interest outweighs any risk to the customer. Second, data minimisation: the tool should get the least personal data that still does the job. Third, accountability: you have to be able to show what you did and why, on paper, if someone asks.
What Changed On 5 February 2026
The DUAA's core data protection changes came into force on 5 February 2026, with the remaining pieces following by June. Here's what matters for a small business using AI.
Automated decision-making has been rewritten. The old Article 22 of UK GDPR, which was a near ban on decisions made solely by a machine with legal or similarly significant effects, has been replaced by Articles 22A to 22D. As Travers Smith describe it, the regime has moved from a prohibition to a right of challenge with safeguards. You can now use legitimate interests, not just consent or contract, for significant automated decisions. The catch is that the safeguards are not optional: you must tell people a machine made the decision, let them contest it, and provide a human review on request. And if the decision uses special category data, meaning health, ethnicity, religion, sexual orientation, biometrics and the like, the old strict rules still apply.
The ICO launched a consultation on updated automated decision-making guidance on 31 March 2026 and the final version was expected over the summer. Check the ICO site for the current text before you rely on any of this for something that affects a person's credit, job, tenancy or access to a service.
Complaints handling is now a legal duty. Since 19 June 2026 every controller, which includes you, must run a formal data protection complaints procedure and acknowledge each complaint within 30 days. If a customer emails to ask why your chatbot gave them a wrong answer about their account, that may now be a data protection complaint and the clock starts.
Subject access requests, where a customer asks for everything you hold on them, now come with a statutory "reasonable and proportionate" search standard and a stop the clock provision while you seek clarification. That matters for AI because chat logs, transcripts and prompt histories are personal data too. If your AI note taker recorded a customer call, that recording is disclosable.
Cookie rules relaxed a little. Analytics and functionality cookies no longer need consent, though marketing cookies still do. And the ICO got sharper teeth: it can now demand specific documents, require an approved person to report on a breach, and interview staff.
The Mistake Nearly Every Small Business Makes
The biggest risk I see isn't sophisticated. It's the free tier of an AI chatbot being used for business data.
Consumer ChatGPT, consumer Gemini, the free tier of pretty much anything, may use your conversations to improve the model unless you find and flip the right setting, and even then you have no data processing agreement with the provider. A DPA is the contract UK GDPR requires between you, as the controller, and any supplier who processes personal data on your behalf. Without one, you cannot show a lawful arrangement exists. As the compliance consultants at TESS Group note, consumer ChatGPT processing personal data is almost always a UK GDPR problem because of lawful basis, transfer and minimisation issues all at once.
The fix is cheap. Business tiers exist, they don't train on your data by default, and they come with the paperwork. At OpenAI's UK checkout on 18 September 2026, ChatGPT Business Standard seats were £15 per user per month billed annually or £18 billed monthly, excluding VAT, with a two seat minimum. Claude Team from Anthropic is priced at 20 US dollars per user per month annually or 25 dollars monthly, roughly £15 to £19, and I'll say once here that Anthropic bills in dollars so the sterling figure moves with the exchange rate. Microsoft 365 Copilot Business is an add-on at £16.10 per user per month paid yearly, excluding VAT, with a promotional £13.80 available until 31 December 2026, and it sits on top of a base Microsoft 365 plan which since 1 July 2026 costs £5.40 for Business Basic, £10.80 for Business Standard or £16.90 for Business Premium.
For a five person firm, that's roughly £75 to £100 a month to move from an unlawful setup to a defensible one. I have not found a cheaper compliance win anywhere in small business.
A word on Copilot specifically, because it's the one many owners already half own. Its data handling is strong on paper: prompts and documents accessed through Microsoft Graph aren't used to train models, and UK data residency has been available since late 2025. But the review at Expertsure flags a real caveat: Anthropic models were added as a Copilot subprocessor in January 2026 and are excluded from the in-country processing commitment, so UK only processing can't be guaranteed on every request. There's also a permissions trap. Copilot will surface anything a user already has access to, so if your SharePoint permissions are a decade of accumulated mess, it will cheerfully show the receptionist last year's redundancy spreadsheet. Fix the permissions before you switch it on.
Where Your Data Goes When It Leaves The Building
Most AI providers are American. Owners often panic about this. They shouldn't, but they do need to check one thing.
Sending personal data to the US is a restricted international transfer under UK GDPR. Since 12 October 2023 the UK to US data bridge, an extension of the EU to US Data Privacy Framework, has allowed transfers to US organisations that have self certified under that framework and opted into the UK extension, with no separate transfer agreement or risk assessment needed. As Michelmores explained when it went live, this is a partial adequacy decision, so it only covers certified companies. The major AI providers are on the list, but check the Data Privacy Framework register yourself rather than assume, and look for the UK extension specifically.
If a supplier isn't certified, you need the ICO's International Data Transfer Agreement, the IDTA, plus a transfer risk assessment. That's real work and a good reason to pick mainstream providers over the exciting startup with the clever demo.
For anyone with EU customers, the European Commission renewed the UK's adequacy decision on 19 December 2025, running to 27 December 2031, so data keeps flowing from the EU to your UK systems without extra paperwork.
Building A Chatbot Or Assistant That Talks To Customers
A customer facing chatbot on your website is processing personal data the moment someone types their name or order number. That means your privacy notice needs to say the chatbot exists, what provider powers it, and what happens to the transcript. Buried on page four of a policy isn't enough; the ICO's whole emphasis under the transparency principle is that people should actually know.
The moment your assistant can look up a customer's booking, balance or address, you've built something that can leak. I insist on three things: the bot only sees the data it needs for the task, it verifies identity before revealing anything account specific, and every conversation is logged where you can retrieve it for a subject access request or a complaint.
Then there's the decision question. A chatbot that answers questions is fine. A chatbot that decides whether to refund you, approve you, or escalate you is making a decision, and if the effect is significant and no human is involved, the Articles 22A to 22D safeguards apply. The ICO's line is that human involvement has to be meaningful, not nominal. Someone rubber stamping a hundred machine outputs an hour isn't a human review.
Accuracy is a data protection principle too, and generative AI makes things up. If your bot tells a customer their appointment is on Tuesday when it's Thursday, that's an accuracy failure with personal data attached. Ground the bot in your actual documents and test it with the awkward questions real customers ask.
Training AI On Your Own Customer Data
Some owners want to fine tune a model on years of customer emails. Slow down.
The ICO's position, set out in its response to the generative AI consultation series, is that legitimate interests is the only realistic lawful basis for using scraped personal data to train generative AI, and that the balancing test is hard to pass because people don't know it's happening and can't exercise their rights. Osborne Clarke's summary of the same report notes the ICO's blunt view that transparency in this area needs to significantly improve.
Even your own lawfully collected customer data runs into purpose limitation. You gathered those emails to serve customers, not to train a model. The DUAA gave organisations more latitude to repurpose data for AI development, but you still need to assess compatibility, tell people in your privacy notice, and consider whether anonymised data would do the job. And note the ICO's warning that an output filter is not the same as deleting someone's data from a model. If a customer asks you to erase them and they're baked into a model you trained, you have a problem you can't fix.
My honest advice for a business under fifty staff: don't train models. Use retrieval, where the AI looks things up in your documents at the moment of the question, rather than baking data in. It's cheaper, more accurate, and you can delete a record and it's gone.
What A Data Protection Impact Assessment Really Involves
A DPIA, a Data Protection Impact Assessment, is required under UK GDPR whenever processing is likely to result in high risk to people, and the ICO has said this covers most new AI uses involving personal data. Owners hear this and picture a forty page document written by a lawyer. It isn't.
A small business DPIA is a two or three page record answering plain questions. What are we doing? What data is involved, and is any of it special category? Why is this necessary and what's the lawful basis? What could go wrong for the people whose data this is? What are we doing to reduce that risk? Who signed it off and when will we review it?
I write these with clients in about ninety minutes. The value is the conversation, because that's where somebody says "oh, the bot can see everyone's phone numbers" and you fix it before launch.
The Enforcement Picture For Businesses Your Size
Owners are either terrified of the ICO or convinced it only chases the big fish. Both are wrong.
The headline fines go to large organisations. Capita was fined £14 million in October 2025 for security failings after a cyber attack, and Reddit £14.47 million in 2026 over age assurance failures. You will not be fined £14 million. But according to the enforcement analysis published by Naq, DPP Law, a legal SME, was fined £60,000 in April 2025 after a ransomware attack exfiltrated 32.4 gigabytes of data, and the ICO explicitly named late breach notification as an aggravating factor. That is a firm your size, and the breach was ordinary. Poxell Ltd was fined £150,000 for unlawful marketing calls, Skean Homes £100,000, LADH Limited £50,000 for around 31,000 unsolicited texts. Marketing enforcement against small firms is routine, and the cap on those fines has just multiplied by thirty five.
The ICO's own priorities for 2026 are AI and biometrics, children's data, and its new procedural powers. AI is on the list by name.
Then the boring one everyone forgets. Almost every business handling personal data must pay the annual data protection fee: £52 for micro organisations with ten or fewer staff or turnover at or below £632,000, £78 for organisations up to 250 staff or £36 million turnover, and £3,763 above that, with £5 off each tier by direct debit. Fail to pay when you should and you can be fined up to £4,000 and listed publicly. Sole traders with no employees are not exempt. Paying it isn't compliance, it's registration, but not paying it makes you look like you don't care.
A Realistic Setup For A Small Firm
Here's the workflow I actually recommend, in order.
Start with an inventory. Ask every member of staff which AI tools they use for work, including the ones on their phone. Write down the tool, the tier, what data goes in, and whether it has a DPA. This register takes an afternoon and underpins everything else.
Kill the consumer tiers for anything involving customer data. Move to business seats with training off and a DPA in place, budgeting £15 to £18 per person per month for ChatGPT Business or £16.10 plus the base licence for Copilot.
Write a one page AI use policy: which tools are approved, what may never go into them (I list bank details, health information, anything about children, and full customer records), and the rule that AI output touching a customer gets checked by a human first. Get everyone to sign it. This is the document that saves you when a member of staff does something daft.
Anonymise by default. "Draft a reply to a customer whose delivery arrived damaged" works just as well as pasting the whole complaint with the address in, and it's better prompting anyway.
Update your privacy notice to name the categories of AI tools you use, what they're for, any automated decisions and how to challenge them, and that US providers are used under the UK to US data bridge. Then set up the complaints procedure the DUAA now requires, even if it's a dedicated email address and a spreadsheet with dates.
Do a short DPIA for anything customer facing or anything that decides. File it. Review it in twelve months or when the tool changes materially.
Check your breach plan. Reportable breaches must reach the ICO within 72 hours, and as the DPP Law case shows, being late is worse than being breached.
Questions To Ask Before You Buy Any AI Tool
I use these on every purchase, and they've stopped several bad ones. Does the provider offer a data processing agreement I can actually read? Is training on my data off by default on the tier I'm buying, in writing? Where is the data processed, and if it's the US, is the company certified under the Data Privacy Framework with the UK extension?
Then the ones people forget. Can I delete my data, and how long are prompts and outputs retained? Can I export conversation logs for a subject access request? And does the tool decide about people, or just assist a person who does? If it decides, do I have notice, contest and human review built in?
Where The Popular Advice Is Wrong
"Just get consent for everything." No. Consent under UK GDPR must be freely given, specific and withdrawable, and if you rely on it and someone withdraws, you must stop. For internal AI use, legitimate interests with a written LIA is almost always the better basis. Consent is for marketing and for special category data.
"The DUAA means automated decisions are now allowed." Partly true and dangerously incomplete. The prohibition went; the safeguards didn't. Deploy a tool that auto rejects job applicants or auto declines refunds with no human route and you are exposed, and recruitment is an area the ICO has been actively investigating.
"Our provider is GDPR compliant so we're fine." Your provider being compliant as a processor does nothing about your obligations as a controller. You still need the lawful basis, the notice, the DPIA and the register. Compliance doesn't transfer with the invoice.
The Reality Check
Generative AI tools change their terms and subprocessors more often than any other software category I've worked with. The Copilot subprocessor change in January 2026 is a good example: an assessment done in December was stale a month later. Re-check your main providers twice a year.
The ICO's automated decision-making guidance was still being finalised when I wrote this, and guidance on agentic AI, where tools take actions rather than just answering, is planned for the ICO's 2026 to 2027 work programme. If your use of AI involves tools booking, buying, emailing or changing records on their own initiative, you are ahead of the guidance, which means you're carrying the risk.
And if your work involves special category data, meaning anything medical, anything about children, anything with biometrics, the relaxed rules largely don't apply to you. A physiotherapy clinic using an AI note taker on patient sessions is in a different league from a garage using it on service bookings.
I'm not a lawyer. This is a practitioner's reading of the law and the ICO's published position. For anything that decides about people, touches health data or involves marketing at scale, spend a few hundred pounds on an hour with a data protection solicitor.
What To Do This Week
If you do nothing else this week, run the inventory and find out where your customer data is actually going. Then move the worst offender, usually a free chatbot with a customer email history in it, onto a business seat with a DPA.
That single change puts you on the right side of AI and customer privacy laws for most small business use, and it costs less than a round of coffees. The rest can wait for next month. The inventory can't.