GDPR and AI tools: a four-rule policy for Irish SMEs
Your team is already pasting company and client data into AI tools. Here's the short, memorable data policy that fixes the actual GDPR exposure — without banning anything.
What this means for you
- Banning AI doesn't work — it moves the same behaviour onto personal accounts.
- Business and enterprise tiers carry data agreements; free consumer tiers generally don't.
- Four written rules your team can remember beat a fifteen-page policy nobody reads.
Here is the situation in most Irish small businesses, stated plainly: someone on your team has pasted customer information into a free AI account this month. They weren't being reckless — they were being efficient, and nobody ever told them not to. That gap between what's actually happening and what anyone has written down is the whole of your GDPR-and-AI problem.
The fix is not a policy document. It's four rules that people remember on a Tuesday afternoon under deadline pressure.
Why this is a GDPR question at all
When an employee pastes a customer's name, email, invoice history, or a chunk of a contract into an AI tool, personal data has been transferred to a processor your business may never have assessed, under terms nobody read, possibly outside the EEA, and potentially into a system that uses inputs to improve its models.
That's a processing activity. It needs a lawful basis, an appropriate agreement with the processor, a record, and — where data leaves the EEA — a valid transfer mechanism. None of those things are hard to satisfy. They're just impossible to satisfy accidentally, which is what happens when there's no policy.
The distinction that matters commercially: consumer tiers and business tiers of the same AI product are not the same product from a data protection point of view. The paid business and enterprise tiers of the major AI tools generally offer a data processing agreement, contractual commitments not to train on your inputs, EU data residency options, and admin controls. The free personal tiers generally offer none of that. Same interface, entirely different legal position.
That single fact does more work than any policy paragraph: the fix for most businesses is buying the right tier and telling people to use it.
The four rules
Rule 1 — Approved tools only, and there's a short list.
Name the specific tools and the specific tier your business has approved, and write them down where people will see them. Two or three tools is plenty. Anything not on the list doesn't get company or customer data, no matter how good the demo looked. The rule works because it's a positive instruction — use this — rather than a vague warning about being careful.
Rule 2 — No special category data, ever.
Health information, trade union membership, ethnicity, religious belief, sexual orientation, biometric or genetic data, criminal offence data. These carry heightened obligations under GDPR and there is essentially no routine SME AI use case that justifies putting them into a general-purpose AI tool. Make this an absolute rule with no exceptions clause — exceptions clauses are what get used.
Rule 3 — Minimise before you paste.
If you're asking AI to redraft a client email, you rarely need the client's name, address, and account number in the prompt. Strip identifiers, use placeholders, put them back afterwards. This takes fifteen seconds and it converts most day-to-day AI use from a personal-data processing activity into something that isn't one at all. It's the highest-leverage habit on this list.
Rule 4 — AI output is a draft until a person has checked it.
Partly a quality rule, partly a compliance one. GDPR gives people rights around decisions made about them by automated means, and separately, AI tools produce confident, plausible, occasionally fabricated content. Anything going to a customer, a regulator, or into a formal record gets read by a competent human first. Nothing is sent because the machine wrote it.
What else to put in place, briefly
Update your privacy notice if AI processing meaningfully changes how you handle personal data — people are entitled to know.
Record it in your Article 30 records. A line per AI tool: what it processes, why, on what basis, where the data goes. This is the paperwork that turns a good practice into a demonstrable one.
Check your transfer position. Most major AI providers now offer EU data residency on business tiers. If yours doesn't, know which transfer mechanism you're relying on.
Do a DPIA where the risk warrants it — anything involving large-scale processing, systematic monitoring, or decisions with legal or similarly significant effects on people. Recruitment screening is the common SME trigger.
The part most people get wrong
The instinct after reading something like this is to ban AI tools outright until a proper policy exists. It's understandable and it reliably makes the problem worse: use doesn't stop, it moves onto personal phones and personal accounts, where you have no visibility, no agreement, and no logs. You've traded a manageable risk for an invisible one.
Approve something good, make it easy to use, and be specific about the four rules. A team that has a sanctioned tool that works will use it.
Not sure whether your current setup is compliant? Take the free AI Scorecard — it takes five minutes and gives you a written read on your data exposure and the next step to fix it.
A realistic first week
Ask your team, without blame, what AI tools they're actually using and what they've put into them. Buy the business tier of whichever one is doing the most useful work. Write the four rules on one page and walk through them in a twenty-minute session. Record that session happened — that's also your AI Act literacy evidence, covered in our EU AI Act guide.
That's it. It's a smaller job than the compliance industry suggests, and doing it properly puts you ahead of most businesses your size in Ireland.
For the specific question of what can go into ChatGPT, the companion piece Can I put client data into ChatGPT? walks through the same test in practice.
If you'd like an honest read on where your business currently sits, the free Scorecard takes five minutes.
Not sure where your business stands?
The free AI Scorecard takes five minutes and gives you a written read on where AI would genuinely help — and where it wouldn't.
Take the free scorecard