Your team is using AI tools. Almost certainly. ChatGPT for drafting emails, Copilot for summarising documents, Claude for customer comms, some combination of AI-powered CRM, helpdesk, or marketing tools. Probably a few tools the IT lead doesn’t know about yet too, if we’re being honest.

Here’s the thing: most small businesses have thought a bit about the obvious GDPR question (“does the AI see my customer data?”) and not much about the less obvious ones. Data minimisation — the principle that you should only process the data you actually need for the purpose at hand — is one of the most commonly ignored principles once AI tools enter the picture. And it’s one the ICO has been increasingly focused on in its guidance on AI and data protection.

What Data Minimisation Actually Means

The UK GDPR’s data minimisation principle is in Article 5(1)(c): personal data must be “adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.” That phrase “limited to what is necessary” is doing a lot of work.

In traditional business processes, minimisation is relatively straightforward. You don’t collect fields you don’t need, you don’t share data with third parties unnecessarily, and you don’t retain it longer than you need to. Fine, understood.

With AI tools, the friction point is different. The issue isn’t usually that you’re collecting data you don’t need — it’s that you’re processing personal data through AI tools in ways that weren’t originally contemplated when you collected it, and with a much broader scope than strictly necessary.

Consider the common scenario: your customer service team uses a large language model tool to summarise complaint emails. The AI is processing customer names, complaint details, potentially account numbers, maybe health information if it’s a medical business. Is that processing necessary? Does the AI need all that context, or just the key facts? Is the AI provider a processor under GDPR (have you signed a Data Processing Agreement)? Does the AI provider retain input data to train future models?

These are the questions data minimisation forces you to ask.

The Main Risks for SMEs Using AI Tools

Inputting more data than necessary. People using AI tools tend to paste in whole documents, full email threads, or complete customer records when they only need to pull out specific information. Training your team to provide only the relevant excerpt — rather than the whole customer record — reduces the data being processed without reducing the AI’s ability to help.

Using personal AI accounts rather than business accounts. Personal ChatGPT accounts (on the free or Plus plan) have different data handling terms than business accounts. On a personal plan, OpenAI may use your inputs to improve models by default. On ChatGPT Enterprise or Teams, data isn’t used for training by default. If employees are using personal accounts to process customer data, you likely don’t have a valid legal basis for that processing, and you definitely don’t have a Data Processing Agreement in place.

Not treating AI providers as data processors. If an AI tool processes personal data on your behalf, the provider is a data processor under UK GDPR. That means you need a Data Processing Agreement (DPA) in place. Microsoft, Google, OpenAI, and Anthropic all provide DPAs for their business products — if your team is using the consumer versions without a DPA, you’re processing personal data without the required legal safeguard.

Logging and retention. Some AI tools retain conversation history, logs of queries, or outputs. Check your AI tool’s data retention settings and ensure they’re compatible with your GDPR records retention schedule. If customers have the right to erasure (and under GDPR they generally do for personal data), you need to be able to act on that request across all systems where that data exists, including AI tool logs.

Practical Steps to Get This Right

Start with an audit of which AI tools your team uses and what data goes into them. This doesn’t need to be formal — just ask your team. You’ll probably discover more tools than you expected. For each tool: is there a business account with DPA? Is it appropriate for personal data? Does it have a Data Retention policy you’ve reviewed?

For the tools you want to keep using, get on the right plan. Microsoft 365 Copilot, Google Workspace with Gemini, and the business tiers of ChatGPT and Claude all come with DPAs and stronger data protection terms than consumer equivalents. The cost uplift is usually modest compared to the compliance risk.

Set input guidelines for your team. Simple practical rules: don’t paste entire customer records into AI tools when you only need to process one element, anonymise or pseudonymise data before processing where practical, and never put special category data (health, financial, biometric) into AI tools unless you have specific compliance checks in place.

Review your privacy policy and records of processing activities (ROPA). If your ROPA doesn’t mention AI tools and you’re using them with personal data, it’s out of date. The ICO expects businesses to keep ROPA current.

The ICO published guidance on generative AI and data protection in 2024 and updated it in early 2026. It’s practical, not just regulatory boilerplate — worth reading if this is new territory for you. The key message from ICO is that GDPR applies to AI processing in exactly the same way it applies to any other processing, and data minimisation is non-negotiable.

What the ICO Is Actually Looking For

The ICO’s enforcement focus for AI and SMEs so far has been on data transfers (is the AI provider processing data outside the UK/EEA without adequate safeguards?) and lack of transparency (are customers aware their data is processed by AI?). Data minimisation hasn’t yet driven high-profile enforcement action against small businesses, but it’s a principle the ICO regularly flags in audit recommendations.

To be practical about it: a small business that has reviewed its AI tools, moved to business-tier accounts with DPAs, and has a brief written policy about what data can be input into AI tools is in a defensible position if the ICO ever asks. A business where employees are using personal AI accounts to process customer data, with no oversight or policy, is not.

This isn’t about being perfect. It’s about being able to demonstrate you’ve thought about it and taken reasonable steps. That’s what the ICO is looking for from SMEs, and it’s achievable without a dedicated data protection officer or legal counsel.

Action Fraud saw a notable increase in 2025 in social engineering attacks that specifically targeted businesses using AI tools — particularly attackers who used AI-generated content to look like legitimate business communications. Good AI hygiene, including careful data handling, also reduces your exposure to this type of attack. It’s connected.

If you’re unsure where to start, the ICO’s self-assessment toolkit for small businesses is free and takes about an hour. It’ll identify the highest-priority gaps for your specific situation.