Can your agency put client data into an AI tool? A UK GDPR checklist
Before uploading a brief, contact list or support transcript, check the purpose, client instructions, supplier terms and safeguards—not just whether the tool is convenient.
HappyNoodle2 October 2026 4 min read

A client brief needs tightening, a contact list needs sorting and a batch of support transcripts needs summarising. Before anyone pastes them into an AI tool, your agency needs a clear decision about what can go in, for what purpose and under whose approval. The answer is not a blanket yes or no. UK GDPR still applies when personal data goes into AI, and the ICO says data protection must be built into processing from the start. This UK GDPR checklist for AI tools and client data turns that principle into practical questions for a small agency. Use it to review the proposed task, the supplier and your team’s working habits—not as proof that a particular upload is lawful. This is general information, not legal advice; check GOV.UK or a professional adviser where your position is unclear.
Key takeaways
- Approve a specific use, not just a tool. Record the task, client, account type and permitted data. Avoid treating approval for generic copywriting as approval to upload customer records.
- Check the whole file before uploading. Review attachments, comments, signatures and free-text fields for information about people, rather than checking only the main text.
- Resolve legal and contractual questions first. Check your role, the lawful basis and client instructions with an appropriate adviser where needed. Do not use a client’s informal approval as your entire assessment.
- Ask suppliers for usable answers. Review retention, training use, deletion, contract terms, processing locations and access for the exact service and account you intend to use.
- Give the team a safe route forward. Provide approved uses, a named decision-maker, human output checks and a clear reporting route for accidental uploads.
Check your role, lawful basis and client instructions
Write down the proposed task in plain English: for example, ‘summarise client-supplied support conversations to suggest help-centre topics’. Then ask who decides the purpose and how the information is used. Are you acting on the client’s instructions, deciding the use yourself, or facing a more complicated arrangement? Have an adviser confirm the relevant controller or processor roles and lawful-basis questions rather than choosing a label for convenience.
Read the client agreement and existing instructions before seeking approval for the task. Ask whether they address AI use, external suppliers or restrictions on sharing information. Treat client permission as one check, not a replacement for the wider review. If the instructions or legal position are unclear, pause the upload and ask a professional adviser what documentation, permissions or changes are needed. The supplied ICO questions page flags that its guidance is under review, so check current guidance rather than relying on an old checklist.
Review retention, training use and supplier contract terms
Review the exact service, subscription and account your team will use. Ask the supplier to explain what happens to prompts, uploaded files and outputs, including how long they are kept and whether they are used for model training or other purposes. Request answers in the relevant terms or documentation rather than relying only on a product headline.
Do not end the review when you find a training opt-out. Continue through deletion, support access, other suppliers involved and contractual responsibilities. Ask an adviser to confirm whether the supplier terms and any data-processing agreement are suitable for the proposed arrangement. Keep a dated record of the documents and settings you reviewed; if an important answer is missing, leave that use unapproved.
| Review area | Question to resolve |
|---|---|
| Retention | How long are prompts, files and outputs retained, and can your agency change that? |
| Training and reuse | Will this account’s data be used for training, evaluation or other purposes? |
| Deletion | What does deletion cover, and what happens to backups or retained records? |
| Contract terms | Which terms govern the proposed processing, and who else is involved? |
Check international transfers and access controls
Ask where the supplier stores and processes the information, and from where staff or other suppliers can access it. Include support and administration access in your questions. If the answers involve overseas processing or access, ask a professional adviser whether international-transfer requirements apply and what arrangements are needed. Do not treat a hosting-location answer as the whole assessment.
The ICO says appropriate technical and organisational measures must safeguard people’s rights. For your agency’s implementation, consider work-managed accounts, restricted workspace membership and a clear process for removing access when someone leaves a project. Before enabling a connection to a shared drive or inbox, review exactly which folders or messages you intend the tool to access. Approve the scope deliberately rather than connecting everything for convenience.
Minimise personal data and assess whether a DPIA is needed
Design a version of the task that uses less information. For a brief rewrite, try supplying the audience, tone, deliverables and constraints without stakeholder details. For help-centre planning, consider manually prepared issue summaries instead of full transcripts. For a contact-list task, first test the method with invented sample records. Treat removing names as an editing step, not automatic proof that the remaining material is anonymous.
Before approving the workflow, ask whether a data protection impact assessment, or DPIA, is needed. Record the purpose, information involved, people affected, proposed safeguards and unresolved risks for an adviser to review. The supplied research does not establish the detailed DPIA triggers or transfer rules, so check GOV.UK or a professional adviser for your circumstances. This early assessment follows the ICO’s emphasis on data protection by design and throughout the processing lifecycle.
Create an approved-tool policy and an incident response route
Turn the review into instructions a busy account manager or freelancer can follow. List approved tools and work accounts, permitted tasks, prohibited inputs and the person who approves exceptions. Make approvals specific: ‘draft generic campaign ideas without client records’ is clearer than ‘AI is allowed’. Include a human check before outputs are sent or relied on, because AI can be wrong.
Give accidental uploads a clear reporting route too. Ask staff to stop further sharing and promptly tell the named owner what went in, which tool and account were used, and when it happened. Have that owner coordinate containment and professional advice about any client, regulator or individual notifications. Do not invent your own legal reporting timetable: check current GOV.UK guidance or a professional adviser.
- 1Record the approved tool, account, task, client restrictions and permitted data.
- 2Name the person responsible for new-tool requests, exceptions and questions.
- 3Require a human review before an AI output reaches a client or informs an action.
- 4Document how staff report an accidental upload and who coordinates the response.
- 5Revisit approval when the task, supplier terms, settings or connected data changes.
Put this into practice
How Project delivery helps
Move accepted work into a practical delivery plan with milestones, tasks, progress and client approvals connected.
Explore Project deliveryCommon questions
Can we upload a client brief if we remove the names?
Do not use name removal as your only check. Review comments, attachments, contact details and descriptions that might still point to someone. Also check confidentiality restrictions and the approved use of the tool. If you are unsure whether the edited brief still contains personal data, get professional advice before uploading.
Is the client saying yes enough?
Use client approval as one part of the review, not your only decision point. Resolve the purpose, your role, lawful-basis questions, supplier arrangements and safeguards as well. Ask a professional adviser to confirm what is needed for that particular task.
Does switching off model training make an AI tool safe for client data?
Keep checking rather than approving solely on that setting. Ask about retention, deletion, access, processing locations and the applicable contract terms. Record what the setting covers for the exact account and service you plan to use.
Do we need a DPIA for every AI task?
This checklist does not establish a blanket requirement or exemption. Document the proposed processing and ask whether a DPIA is needed before approving client-data use. Check GOV.UK or a professional adviser for the applicable criteria.
What should we do if someone has already pasted client data into an unapproved tool?
Stop further sharing and use your incident reporting route. Record the material involved, tool, account and timing, then have the responsible owner coordinate containment and advice. Check any notification duties and deadlines promptly with a professional adviser rather than assuming that deleting the conversation resolves the issue.
Sources
- Data protection by design and by default | ICO
- Previously asked questions - ICO
- AI Policy for Small Businesses 2026 + Template Outline | ABCOM
General information only, not legal, tax or financial advice. Check GOV.UK or a qualified adviser for your situation.
Make the next upload a deliberate decision
Choose one proposed AI task and work through this checklist. Record what is approved, what must stay out and who owns unresolved questions. If a key answer is missing, use a generic or manually prepared input while you investigate.
Explore Project delivery