How AI affects your privacy policy and terms

How AI affects your privacy policy and terms – what UK businesses need to change | Better AI Decisions

Home / AI for Small Business

AI FOR SMALL BUSINESS

How AI affects your privacy policy and terms — what UK businesses need to change

You may have started using AI without changing a word of your website’s privacy policy or terms and conditions. That’s worth reviewing. If AI changes what you do with customer, employee or website visitor information, your existing documents may no longer tell the whole story.

You don’t need to put “AI” into every paragraph. But you do need to make sure your privacy information and terms accurately describe what your business actually does.

The short answer

If your business uses AI to collect, analyse, create, profile or make decisions using personal information, review your privacy policy and, where relevant, your terms and conditions. UK GDPR still applies, and your customers should be told clearly how their information is being used, who it is shared with and whether AI or automated decision-making is involved.

We’ll send a password for the resource area and regular UK-focused AI updates. Unsubscribe anytime.

Why AI can change your privacy policy

Let’s start with something simple.

A privacy policy isn’t supposed to be a document you write once and forget about.

It’s there to explain to people what you do with their personal information.

If the way you use that information changes, your privacy information may need to change too.

The ICO says people have a right to be informed about how their personal information is collected and used. Privacy information should be concise, transparent, understandable, accessible and written in clear language.

AI can change what happens to that information without you necessarily noticing.

For example, you might already collect a customer’s:

  • Name
  • Email address
  • Telephone number
  • Address
  • Order history
  • Enquiry
  • Preferences
  • Website activity

Then you introduce an AI tool.

Perhaps it summarises customer enquiries.

Perhaps it analyses buying patterns.

Perhaps it decides which customers should receive a particular marketing message.

Perhaps it powers a chatbot.

Perhaps your customer service software starts using AI automatically.

You’ve changed how personal information is being processed.

That doesn’t automatically mean you’ve broken UK GDPR.

But it does mean you should ask whether your privacy information still accurately describes what you’re doing.

AI doesn’t create a special “AI privacy law”

This is an important point.

There isn’t a separate UK GDPR rule that says:

“If you use AI, you must add an AI paragraph to your privacy policy.”

It’s more practical than that.

The existing data protection rules apply to what you’re doing with personal information.

AI is simply another way of processing information.

The ICO says that when organisations use AI with personal data, they still need to consider the usual data protection principles, including lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy and security.

So don’t ask:

“Where should I put the AI clause?”

Ask:

“What does AI actually do with people’s information?”

That’s the question that determines what your privacy policy needs to explain.

What should your privacy policy say about AI?

There’s no single paragraph that works for every business.

Your privacy policy should reflect your actual use of AI.

For example, suppose you run a small online retailer.

You use AI to:

  • Answer customer questions through a chatbot.
  • Summarise customer service enquiries.
  • Analyse sales patterns.
  • Personalise product recommendations.
  • Help detect potentially fraudulent transactions.

Those are four quite different uses.

They may involve different information, different purposes and different levels of risk.

Your privacy information should make the relevant uses understandable.

For example, a plain-English explanation might say:

“We use automated tools to help us respond to customer enquiries and improve our services. These tools may process information you provide to us, such as your name, contact details and details of your enquiry.”

That’s much better than writing:

“We use artificial intelligence and machine learning technologies to enhance our data processing capabilities.”

The second sentence sounds impressive.

It doesn’t tell your customer much.

Tip

Write for the customer, not a lawyer

Your privacy policy needs to be legally appropriate.

But it also needs to be understandable.

If a customer can’t work out what you’re actually doing with their information, you’ve probably made it too complicated.

The ICO says privacy information should be clear, plain and easy to understand.

Ask someone who knows nothing about your AI system to read the relevant section.

Then ask:

“What do you think happens to your information?”

If their answer is completely different from reality, rewrite it.

Do you need to name the AI company?

Sometimes you should.

The answer depends on the role the supplier plays and the information being processed.

Suppose your website uses an AI chatbot supplied by another company.

Your customer may be providing personal information through that chatbot.

If the AI supplier processes that information on your behalf, it may be a processor.

If it uses the information for its own purposes, the relationship may be different.

The ICO specifically warns organisations to establish whether an AI provider is acting as a controller, processor or potentially a joint controller.

That distinction matters.

Don’t simply assume:

“It’s our AI supplier, so they’re a processor.”

Find out what they actually do with the information.

If a supplier is acting as your processor, UK GDPR generally requires a written contract containing specific provisions about how the personal data is handled.

Those provisions cover things such as:

  • What information is being processed.
  • Why it is being processed.
  • How long it will be processed.
  • Confidentiality.
  • Security.
  • Sub-processors.
  • Helping with individuals’ rights.
  • Data breaches.
  • End-of-contract deletion or return of information.

What if your AI supplier uses other AI suppliers?

This is becoming increasingly important.

You might buy an AI customer service system from Company A.

Company A might use Company B to provide its underlying AI model.

Company B might use another provider for hosting.

You don’t necessarily need to understand every technical detail.

But you should understand the supply chain sufficiently to know who is handling personal information and under what arrangements.

The ICO’s AI audit framework specifically recommends considering controller and processor relationships across the whole AI supply chain and making responsibilities clear in contracts.

This is one reason you shouldn’t choose an AI service purely because it looks clever or inexpensive.

Your privacy policy needs to match your actual AI use

Here’s a common problem.

A business privacy policy says:

“We only use your information to process your order and provide customer service.”

But the business is also using customer information to:

  • Train or improve internal systems.
  • Build customer profiles.
  • Personalise marketing.
  • Analyse behaviour.
  • Detect fraud.
  • Make automated decisions.
  • Feed information into an AI service.

The wording may no longer accurately describe what is happening.

The ICO says that if you start using personal information for a new purpose, you need to consider whether you can do so lawfully and whether you need to provide additional information to people.

This is where AI can expose weaknesses in an old privacy policy.

You haven’t necessarily started collecting more information.

You may simply have started doing more with the information you already had.

Can you use customer data to train AI?

This is one of the questions businesses need to ask before they start.

Suppose you have ten years of customer emails.

You think:

“We’ve got loads of useful information here. Let’s use AI to learn what our customers want.”

Stop there.

You need to work out:

  • What personal information is contained in the emails?
  • What exactly do you want to do with it?
  • What’s your lawful basis?
  • Is the new use compatible with why you collected it?
  • Who will process it?
  • Will it leave your organisation?
  • Will the supplier use it for its own purposes?
  • How long will it be retained?
  • Do you need to tell customers about the new use?
  • Does the activity create a higher risk for individuals?

Don’t assume that because you already hold information, you can use it for anything you like.

The ICO specifically warns that applying AI to personal information can create new uses for data. If information originally collected for one purpose is going to be used for another, you need to consider whether people need to be told and whether the new processing is lawful.

What about automated decision-making?

This is where things become more serious.

There is a big difference between:

“AI helps me draft an answer.”

and:

“AI decides what happens to this person.”

Imagine a small business uses AI to score job applicants.

Or decide which customers receive credit.

Or automatically reject refund requests.

Or decide which customers are considered high risk.

Or assess employee performance.

Those uses can involve much greater risks.

The UK GDPR contains specific rules around solely automated individual decision-making, including profiling, where decisions have legal or similarly significant effects on individuals. The rules include safeguards and information requirements.

The ICO says that where these rules apply, people may need meaningful information about the logic involved, the significance of the processing and its likely consequences. They may also have rights to human intervention and to challenge the decision.

This is not something to hide in a vague sentence saying:

“We may use AI to improve our services.”

If AI is making an important decision about someone, you need to deal with that properly.

AI-assisted decisions are not the same as fully automated decisions

This distinction is worth understanding.

Suppose AI reviews 100 job applications and highlights ten that appear to match your requirements.

You then read those ten applications yourself and make the hiring decision.

That’s different from an AI system automatically rejecting 90 applicants without meaningful human involvement.

But don’t assume that adding a human automatically makes every issue disappear.

The ICO says that even where a decision is AI-assisted rather than solely automated, the normal UK GDPR principles still apply when personal information is being used. Fairness, transparency and accountability remain relevant.

The human needs to be genuinely involved.

Not:

“AI made the decision and I clicked approve.”

What should you put in your terms and conditions?

Your terms and conditions are different from your privacy policy.

This distinction matters.

Your privacy policy explains how you handle personal information.

Your terms and conditions set out the agreement between you and your customer.

AI can affect both, but in different ways.

For example, if you use an AI chatbot to answer customer questions, that is mainly a privacy and consumer transparency issue.

But if you use an AI system to provide part of the service you’re selling, your terms may need to reflect how that service actually works.

Imagine you sell a subscription service that includes AI-generated reports.

Your terms might need to explain:

  • What the customer is actually buying.
  • What the service includes.
  • Any important limitations.
  • What happens if the AI produces an error.
  • What level of human checking is provided.
  • What happens if the service is unavailable.
  • How customers can complain.
  • What happens if the AI provider changes or stops its service.

Don’t use your terms to try to avoid every possible responsibility.

That can create another problem.

You can’t just write “AI errors are your responsibility”

Suppose your terms say:

“All AI-generated information is provided without warranty and the customer accepts full responsibility for any errors.”

That might sound like a useful protection.

It isn’t necessarily one.

If you’re selling to consumers, the Consumer Rights Act 2015 places limits on unfair contract terms and notices. The CMA’s current guidance says consumer contract terms and notices need to be fair and transparent.

And where your business uses AI to interact with customers or perform tasks such as processing refunds, the CMA’s 2026 guidance makes the position very clear: the same consumer protection rules apply whether the customer is dealing with an AI agent or a human, and the business remains responsible for its obligations.

So don’t try to solve AI risk by putting an enormous disclaimer at the bottom of your terms.

Make the service clear.

Make the limitations fair.

And keep responsibility where it belongs.

Caution

Your terms don’t override the law

This is particularly important for small businesses.

A clause in your terms doesn’t automatically make something legal.

You can’t simply write:

“Customers agree that we can use their personal information for any purpose.”

That doesn’t replace the requirements of UK data protection law.

You can’t necessarily write:

“We aren’t responsible for anything our AI does.”

That doesn’t automatically remove consumer rights.

You can’t write:

“AI decisions are final and cannot be challenged.”

That doesn’t override applicable data protection rights.

Your terms need to work within the law.

They don’t sit above it.

What about AI chatbots on your website?

This is one of the easiest AI uses to overlook.

A chatbot might appear to be nothing more than a helpful little box saying:

“How can I help?”

But customers may type personal information into it.

They may provide:

  • Names
  • Email addresses
  • Order numbers
  • Addresses
  • Details of complaints
  • Payment information
  • Health information
  • Information about other people

That’s personal information processing.

Your privacy information should reflect what happens.

And if the chatbot is effectively acting as your customer service agent, you also need to make sure it doesn’t give customers misleading information or make promises your business can’t keep.

The CMA’s 2026 guidance says businesses using AI agents to engage with consumers need to tell customers when they are interacting with an AI agent and make sure the system complies with consumer law.

That’s a good practical rule even where a particular use doesn’t trigger a specific legal disclosure requirement.

Be open.

Don’t pretend the customer is talking to a person when they’re not.

Your terms should also deal with AI-generated content where relevant

Suppose your business provides content, reports, designs or other creative work.

AI may now be part of how you produce it.

Your customer may reasonably want to know:

“Is this work created by a person, AI, or a mixture?”

The answer may affect what you promise.

For example, an agency might say:

“We create original written content for your business.”

If much of the content is generated by AI and then edited by a human, that statement may need more thought depending on what “original” means in context.

Copyright is another area where businesses should be careful.

The UK government published a report and impact assessment on copyright and AI in March 2026, showing that the legal and policy position around AI and copyright remains an active area of development.

Don’t put sweeping statements such as:

“You own everything AI creates.”

or:

“AI-generated material is always copyright-free.”

The position can depend on the work, how it was created and the rights involved.

If copyright is commercially important to what you’re selling, get specific advice rather than relying on an AI-generated explanation of copyright law.

What about marketing and emails?

AI can also affect your privacy policy and marketing practices.

You might use AI to:

  • Choose which customers to target.
  • Segment your mailing list.
  • Predict what products someone might like.
  • Personalise emails.
  • Generate marketing messages.
  • Analyse customer behaviour.

Some of these activities may simply involve ordinary marketing processing.

Others may involve profiling or more complicated processing.

Don’t assume:

“It’s only marketing, so it doesn’t matter.”

Your normal data protection and electronic marketing rules still apply.

The Data (Use and Access) Act 2025 has also changed parts of the UK’s data protection and electronic communications framework, with provisions coming into force in stages.

The ICO’s current guidance should therefore be your starting point when reviewing marketing-related processing rather than an old article about “UK GDPR and email marketing”.

What should you actually change?

For most small businesses, I wouldn’t recommend adding a huge section headed:

“OUR ARTIFICIAL INTELLIGENCE POLICY”

to the privacy policy.

Instead, review the existing sections.

Ask these questions.

1. What personal information do we collect?

List it.

Don’t guess.

2. What do we use it for?

Include any new AI-related purposes.

3. Who receives it?

Include relevant AI providers and other suppliers where appropriate.

4. Are any suppliers processing information for us?

If so, make sure the contractual arrangements are appropriate.

5. Are we profiling people?

If yes, understand what you’re doing and whether additional information is required.

6. Are we making automated decisions?

If yes, find out whether the UK GDPR rules on automated decision-making apply.

7. Are we using information for a new purpose?

If yes, review the purpose limitation and transparency requirements.

8. Is our privacy policy written in plain English?

If not, rewrite it.

9. Do our terms accurately describe our service?

Especially if AI is actually delivering part of what the customer is buying.

10. Are we making promises about AI that we can’t keep?

Remove them.

A simple AI privacy policy check

If you’ve introduced AI recently, take your privacy policy and look for these phrases:

  • “third parties”
  • “service providers”
  • “automated”
  • “profiling”
  • “analytics”
  • “personalisation”
  • “decision-making”
  • “customer service”
  • “marketing”
  • “data sharing”
  • “international transfers”
  • “sub-processors”
  • “machine learning”
  • “artificial intelligence”
  • “AI”

You don’t necessarily need to add every one.

But each should make you stop and ask:

“Does this apply to what we’re actually doing?”

A simple AI terms and conditions check

Now look at your terms.

Ask:

  • Does AI form part of the service I’m selling?
  • Does AI generate anything the customer receives?
  • Can AI make decisions that affect the customer?
  • Does an AI system communicate directly with customers?
  • Could AI produce an incorrect answer?
  • Who checks important AI-generated information?
  • What happens if the AI service is unavailable?
  • What happens if an AI supplier changes its service?
  • Are our limitations fair?
  • Are our refund and cancellation terms still accurate?
  • Are we making claims about AI that customers could misunderstand?

If your answer to several of these is “yes”, your terms deserve a proper review.

What your privacy policy might say

There is no universal wording you should copy.

But if you’re using AI for straightforward customer service, your privacy policy might explain the position in plain English along these lines:

“We use automated tools, including AI-based software, to help us manage customer enquiries, improve our services and carry out certain administrative tasks. Where these tools process personal information, we take steps to ensure that the information is handled securely and in accordance with applicable data protection law.

Some of our service providers may process personal information on our behalf. We require appropriate contractual and security arrangements where required by law.

We do not use automated decision-making to make decisions about you that have legal or similarly significant effects unless we have a lawful basis to do so and the required safeguards are in place.”

That is an example of the sort of plain-English explanation you might use.

It is not a drop-in legal clause.

Your actual wording needs to reflect what your business really does.

What your terms might say

Again, don’t copy this blindly.

If AI is part of the service you provide, you might need wording along the lines of:

“Some parts of our service may use automated tools, including AI-based software. We remain responsible for the services we provide and will take reasonable steps to review information produced by these systems where appropriate.

AI-generated information may occasionally contain errors. Where information is important to your legal, financial, safety or other significant decisions, you should not rely on it without appropriate verification.

Nothing in these terms limits any rights or remedies you have under applicable consumer law.”

The last sentence matters.

Your terms should complement your legal obligations, not pretend they don’t exist.

The biggest mistake is writing a policy for AI you don’t actually use

This happens surprisingly often.

A business asks AI:

“Write me an AI privacy policy.”

AI produces five pages.

The owner publishes it.

It talks about:

  • Facial recognition
  • Automated credit scoring
  • Biometric data
  • AI training
  • International data transfers
  • Predictive analytics
  • Profiling
  • Automated decisions

But the business uses AI to write Facebook posts.

You’ve just made your privacy policy longer without necessarily making it more accurate.

Worse, you may have told customers that you’re doing things you aren’t doing.

That’s not good transparency.

Your privacy policy should describe your business.

Not every possible thing AI can do.

Your 30-minute AI policy review

You don’t need a solicitor sitting beside you for the first review.

Start with this.

1. Write down every AI tool you use

Include AI hidden inside software you already use.

2. Write down what each tool does

One sentence per tool.

3. Identify the information it receives

Customer data?

Employee data?

Website information?

Business information?

No personal data?

4. Identify the supplier

Who provides it?

5. Find out whether it uses your information for its own purposes

Read the current privacy and business terms.

6. Check your contracts

If a supplier is processing personal data on your behalf, make sure the required contractual arrangements are in place.

7. Check your privacy policy

Does it accurately describe the processing?

8. Check your terms

Does the service you’re selling still match what your terms say?

9. Check customer-facing AI

If a chatbot or AI agent deals directly with customers, make sure customers aren’t being misled and that the system is monitored.

10. Put a date in the diary

Review everything again when your AI use changes.

That’s much more useful than writing a giant policy once and forgetting about it.

AI doesn’t mean you need a new set of terms

This is perhaps the most important point in the article.

Sometimes the correct answer is:

“Nothing needs changing.”

If you use AI to help rewrite an email containing no personal information, you may not need to rewrite your privacy policy.

If you use AI to brainstorm names for new products, your terms probably don’t need an AI clause.

If you use Microsoft 365 Copilot to help draft internal documents, the privacy implications may be very different from running an AI chatbot that collects information directly from customers.

Start with what the AI actually does.

Then work out what, if anything, needs to change.

The golden rule

Your privacy policy should tell people what you actually do with their information.

Your terms should accurately describe the service and the agreement between you and your customer.

AI doesn’t change those basic principles.

It simply means you need to check whether your business has started doing something new with information, or delivering its services in a new way.

“Don’t write an AI policy because AI exists. Update your documents because your business has changed.”

AI and UK GDPR Privacy Policy Terms and Conditions Small Business UK Business

AI FAQs

Questions people ask about AI, privacy policies and terms

These are the practical questions UK business owners are asking about updating their documents for AI use.

Do I need to add AI to my privacy policy?

Not automatically. If you use AI to process personal information, you should review your privacy information to make sure it accurately explains what you do with that information. The ICO says people have a right to be informed about how their personal data is used.

You don’t necessarily need a separate section called “AI”.

Can I use ChatGPT with customer information?

That depends on the particular ChatGPT service, your account, the information involved and how the service handles that information.

Don’t assume every AI service has the same privacy arrangements. Check the current terms and data-handling information for the specific service before using personal or confidential business information.

Do I need to tell customers that I use AI?

Sometimes you may need to, particularly where AI changes how you process their personal information or where AI is being used to make decisions about them.

The ICO says transparency is particularly important when AI is used to make decisions or profile people.

The CMA’s 2026 guidance also says businesses using AI agents to engage with consumers should tell customers when they are interacting with an AI agent.

Do I need an AI clause in my terms and conditions?

Not necessarily.

If AI is simply helping you write an internal email, it may have little or no effect on your customer contract.

If AI is part of the service you provide, communicates directly with customers, makes decisions or creates material the customer is paying for, your terms may need reviewing.

Can I say in my terms that I’m not responsible for AI mistakes?

Don’t assume that a disclaimer will protect you.

Consumer contracts and notices must be fair and transparent, and businesses can’t simply contract out of legal rights that apply to consumers.

If AI forms part of your service, explain its limitations honestly and make sure your terms work with applicable consumer law.

Does UK GDPR apply if an AI company processes my customer data?

Yes, where the processing falls within the scope of UK data protection law.

The important question is what role the AI company has.

If it processes personal data on your behalf, you will generally need an appropriate processor contract. If it uses the information for its own purposes, its legal role may be different.

Don’t assume the answer. Establish what the supplier actually does.

Sources

  1. Information Commissioner’s Office — What privacy information should we provide? ★★★★★ UK regulator
    Explains what organisations need to tell people about how their personal information is collected and used, including information about automated decision-making where applicable.
  2. Information Commissioner’s Office — AI and data protection guidance ★★★★★ UK regulator
    Explains how existing UK data protection principles apply when organisations use AI with personal information.
  3. Information Commissioner’s Office — Contracts and third parties in AI ★★★★★ UK regulator
    Provides specific guidance on assessing controller, processor and joint-controller relationships in AI supply chains.
  4. Information Commissioner’s Office — Contracts and liabilities between controllers and processors ★★★★★ UK regulator
    Explains when a processor contract is required and the terms that need to be included under UK GDPR Article 28.
  5. Information Commissioner’s Office — The right to be informed ★★★★★ UK regulator
    Explains privacy notices, transparency and what organisations should tell people when AI creates new uses for personal information.
  6. Information Commissioner’s Office — Automated decision-making and profiling ★★★★★ UK regulator
    Explains the UK GDPR rules and safeguards applying to solely automated individual decision-making and profiling.
  7. Information Commissioner’s Office — Explaining AI-assisted decisions ★★★★★ UK regulator
    Explains why fairness, transparency and accountability remain relevant even where a human is involved in an AI-assisted decision.
  8. Competition and Markets Authority — Unfair contracts ★★★★★ UK regulator
    Guidance on fair and transparent consumer contract terms and notices under the Consumer Rights Act 2015.
  9. Competition and Markets Authority — Using AI agents: complying with consumer law ★★★★★ UK regulator
    2026 guidance explaining that consumer protection obligations continue to apply when businesses use AI agents and that customers should be told when they are interacting with an AI agent.
  10. Department for Science, Innovation and Technology, Department for Culture, Media and Sport and Intellectual Property Office — Report and impact assessment on Copyright and Artificial Intelligence ★★★★★ UK government / intellectual property guidance
    Published in March 2026 and provides current UK policy and legal context around copyright and AI.
  11. UK Government — Data (Use and Access) Act 2025: data protection and privacy changes ★★★★★ UK government
    Explains changes made to UK data protection and privacy legislation by the Data (Use and Access) Act 2025, including changes affecting automated decision-making, international transfers, complaints and electronic communications.

⚠️ Evidence note: This article deliberately doesn’t provide a single “AI clause” for every business.

That’s because the correct wording depends on what your business actually does with AI, what personal information is involved, which suppliers you use and whether you’re dealing with consumers or businesses.

The UK GDPR doesn’t require businesses to add a generic AI paragraph simply because they use AI. The important issue is whether your processing of personal information has changed and whether your existing privacy information remains accurate and transparent.

Similarly, consumer law doesn’t give businesses a blanket right to exclude responsibility for AI-generated mistakes. The CMA’s guidance confirms that businesses remain responsible for complying with consumer protection law when using AI agents.

The Data (Use and Access) Act 2025 has also changed parts of the UK’s data protection and privacy framework. All of its data protection provisions are now in force as of 19 June 2026, according to the ICO, although some ICO guidance is still being reviewed and updated.

This article is practical guidance for UK small businesses, not legal advice. If you are using AI for high-risk processing, automated decisions, sensitive personal information or an important customer-facing service, check the current ICO and CMA guidance and consider getting appropriate professional advice.

Check what your customers are being told

If you’ve introduced AI into your business, don’t automatically rewrite everything. Start by listing what AI actually does with customer, employee and website information, then check whether your privacy policy and terms still describe reality.

Your documents don’t need to be full of AI jargon. They need to be accurate, clear and honest.

Explore more practical guidance →