Your staff are using ChatGPT at work. Here’s what that means for your customer data.

9–14 minutes
,

Someone in your business used ChatGPT this week. They did not ask you first, and they were not doing anything they thought was wrong.

They had a customer complaint to answer, or a quote to write, or a spreadsheet that would not behave. So they opened a chatbot, pasted in what they were working on, and got a decent answer in twenty seconds. Job done. Back to work.

That is not a discipline problem. It is a very sensible person using a very good tool. The problem is what went into the box along with the question.

This is far more common than most business owners think

Research carried out by Censuswide for Microsoft in October 2025, covering 2,003 UK employees, found that 71% had used unapproved consumer AI tools at work, and 51% were still doing it every week.

Seven in ten. Not seven in ten tech companies — seven in ten UK employees, across retail, finance, education, health and social care.

Meanwhile SAP reported in February 2026 that six in ten UK businesses say their staff have had no AI training at all. So most people are using these tools, and most of them have been told nothing about how to use them safely.

The industry has a name for this: shadow AI. Software being used to do real work, with real company data, that nobody signed off, nobody assessed, and nobody wrote down.

Why a chatbot is different from every other tool you use

You already run software that touches customer data. Your accounts package, your email, your CRM, your website. The difference is that at some point somebody agreed terms with those suppliers.

There is a specific document that matters here, called a data processing agreement. Under UK GDPR, if a supplier handles personal data on your behalf, you are supposed to have one. It sets out what they may do with the data, how long they keep it, who else sees it, and what happens if something goes wrong.

Your accountant has one. Your hosting company has one. (If you are with us, you have one — it is in your onboarding pack.)

The free chatbot your sales lead was using at half past four on a Tuesday does not.

That is the actual gap. Not that AI is dangerous, not that chatbots are evil — but that a supplier has quietly entered your business, is handling your customers’ information, and there is no agreement, no record, and no way to answer a straight question about where any of it went.

Three things that follow from that

  • You may not be able to get the data back or deleted. Consumer chatbot accounts are not built for a business asking “please remove everything my employee submitted on 14 March”.
  • On some free and consumer tiers, what gets typed in can be used to improve the model. Paid business and enterprise tiers usually change this, but the default on a personal account often does not.
  • You cannot answer the question a customer is entitled to ask. If someone asks who has had access to their information, “one of our team pasted it into a chatbot and we are not sure what happened next” is not an answer you want to give.

What this looks like in a normal business

None of these are hypothetical. They are the sort of thing that happens in an ordinary week.

The complaint reply. A customer sends a long, angry email. Your team member wants to reply politely rather than at 11pm in a temper, so they paste the whole thing into a chatbot and ask for a professional response. The email contains the customer’s name, address, order history and a description of a health condition explaining why they needed the delivery on time.

The spreadsheet. Someone cannot get a formula to work, so they paste a chunk of the sheet in to ask what is wrong. The chunk includes three hundred rows of customer names, emails and phone numbers.

The CV. A manager is hiring, has twelve applications, and asks a chatbot to summarise and rank them. Those are twelve people’s employment histories, contact details, and sometimes far more.

In every case the person did something reasonable and helpful. In every case personal data belonging to somebody else left the business without anyone deciding that it should.

The bit that catches business owners out

When your staff use a tool that handles customer data, you are the one responsible for it. In data protection language you are the “controller” and the tool provider is a “processor” — and checking that a processor is up to the job is the controller’s duty, not the processor’s.

It does not matter that you did not know. It does not matter that it was a free tool, or that it was on their own laptop, or that it took ten seconds. If it was in the course of their work, it is your responsibility.

That sounds harsh, but there is a reasonable logic to it: you are the one with the relationship with the customer, so you are the one who has to be able to account for what happened to their information.

What the rules actually say — without the scaremongering

A lot of writing on this subject is designed to frighten you into buying something. Here is the more measured version.

Using AI is not against the law. Sending personal data to a supplier outside the UK is not against the law either — there are perfectly ordinary mechanisms for it, and most reputable providers have them in place. Plenty of UK businesses use AI tools every day, properly, with the paperwork done.

The problem is narrower and more boring than “AI is illegal”. It is this: processing you did not know was happening cannot be lawful processing, because you cannot have assessed a risk you were unaware of, told anyone about it, or written it down.

Fix the visibility problem and most of the legal problem goes with it.

Worth knowing too: the ICO has generally been more interested in organisations that ignored an obvious problem than in ones that found it, took advice and sorted it out. Discovering this in your own business and acting is a good position to be in. Discovering it because a customer complained is not.

Banning it does not work

The instinctive response is an email saying nobody is to use AI tools. It feels decisive and it costs nothing.

It also does not work. The Microsoft research is a study of people using tools they were not supposed to use. A ban does not remove the tool, it removes your visibility of the tool — and it makes the person who used it anyway far less likely to tell you when something goes wrong.

You also give up a genuine advantage. These tools are useful. Your competitors are using them. The goal is not to stop your team working faster; it is to make sure they can do it without your customer list ending up somewhere you cannot follow.

Five things worth doing this week

  1. Ask, and mean it. Tell your team you are not looking to tell anyone off, you just want to know what is being used. You will get honest answers once, at the start, if you handle it right — and far fewer if you open with a policy.
  2. Write down what you find. A spreadsheet is fine. One row per tool: what it is, who uses it, what it is used for, and whether customer information can end up in it. Most businesses find between three and eight. Most are surprised by at least one.
  3. Draw a bright line about personal data. Not a fifteen-page policy nobody reads. One rule people can actually remember: if it names a real person, do not paste it into a chatbot. Names, emails, phone numbers, addresses, health details, anything about a job applicant. Give them the workaround at the same time — take the names out first, or use a tool you have approved.
  4. Approve something. This is the step people skip, and it is the one that makes the rest work. If there is no sanctioned option, staff go back to the free one. Pick a tool, check it offers business terms and a data processing agreement, pay for it if you need to, and tell everyone it is there.
  5. Put it in the induction. Two paragraphs. New starters find out on day one instead of guessing.

Half a day’s work for most small businesses. It is not a project.

Then there is the harder question: where does it actually go?

Sort the five things above and you have dealt with the visibility problem, which is the biggest one.

What remains is a question that comes up more and more, usually from a customer’s procurement team or a form you have to fill in to win a contract: where is our data actually processed?

For most AI tools the honest answer is the United States. That is lawful with the right paperwork in place, and it is how a great many perfectly compliant businesses operate. But it does generate work — assessments, supplier questionnaires, follow-up questions from whoever is reviewing you — and for some organisations, particularly in legal, healthcare, financial services and the public sector, it is simply not acceptable under their own rules.

using ChatGPT at work

This is a problem we kept running into with our own clients, and eventually did something about. We built dijitul.ai, a UK-hosted AI gateway. It runs Claude on Amazon’s London infrastructure, so the processing happens in the UK and does not leave it, and it strips out personal details like names, phone numbers and NHS numbers before the prompt reaches the model at all.

Two honest caveats, because we would rather you heard them from us:

  • If your requirement is European rather than specifically British, EU hosting is a perfectly lawful answer and other providers do it well. UK hosting earns its keep when a contract, a regulator or a procurement questionnaire asks for the UK by name.
  • If you have a developer who is comfortable with cloud infrastructure, you can build this yourself in an afternoon. What you would be paying us for is everything after that — the data stripping, the per-client reporting, invoices in pounds, and a written statement you can hand to a customer who asks.

If you want the technical detail, we have written it up properly over on the dijitul.ai insights section — including a piece on whether you actually need a transfer risk assessment, where the answer is often no, and we say so.

Common questions

Is it illegal for staff to use ChatGPT at work?

No. Using AI tools at work is not illegal. The issue arises when personal data — information about identifiable people such as customers, staff or job applicants — is entered into a tool with no data processing agreement, no record and no assessment. That is a data protection problem rather than a criminal one, and it is fixable.

What is shadow AI?

Shadow AI is the use of AI tools within a business that the business has not approved, assessed or documented. It is the AI version of shadow IT. It is usually well-intentioned, and it is very common: 71% of UK employees report having done it.

Does ChatGPT train on what my staff type in?

It depends entirely on the tier. Free and personal accounts have historically defaulted to allowing submitted content to be used for improving the model, while business and enterprise tiers generally do not. Terms change, so check the settings on the specific account being used rather than relying on a general answer — including this one.

Do I need a policy on AI use?

You need something written down, but it does not have to be long. A single clear rule about personal data, plus a named tool people are allowed to use, will do more good than a lengthy document nobody opens. Its real job is to make the safe option the easy option.

What if we have already put customer data into a chatbot?

Do not panic, and do not delete your way out of it. Establish what was submitted, when, and by whom. Check whether it can be removed from the account. Write down what you find. In most cases this is a housekeeping matter rather than a reportable incident — but that judgement depends on what the data was, and it is worth asking someone before deciding it is fine.

Where to start

Start with the question. Ask your team what they are using, make it genuinely safe to answer honestly, and write down what comes back. Everything else follows from that list, and you cannot do any of it until you have one.

If you would like a hand — with the audit, with picking a tool your team will actually use, or with the UK-hosted option — get in touch. We are in Mansfield, we work with businesses across Nottinghamshire and well beyond, and we will tell you plainly if you do not need anything from us.


This article is general information about how the rules work, not legal advice about your particular circumstances. dijitul Ltd is not a law firm. If a decision turns on it, take proper advice.

Leave a Reply

Your email address will not be published. Required fields are marked *