One principle carries most of the weight
Your customers gave you their information for a reason. Sending it to a third party is a decision you are making on their behalf, and they are not in the room.
Almost every rule below is a version of that sentence.
Four practical habits
Minimise. Before you paste, ask what the tool actually needs. Rewriting a complaint response does not need the customer's surname, address or order history. Strip it to the question. Most of the risk in most small businesses disappears here, at no cost.
Check the training setting, and date it. Consumer free tiers have historically been more likely to use your conversations to improve models; business, team and API tiers generally state they do not train on your inputs by default. The specifics differ by vendor and change with policy updates, so do not trust a summary — including this one. Open the settings, find the toggle, screenshot it with the date. That screenshot is what you show a client who asks.
Know where it goes. Some regimes care which country the servers are in. Business tiers often let you choose a region; consumer tiers usually do not.
Treat special categories differently. Health, biometrics, children's data, religion, sexual orientation, criminal history, trade union membership. A bakery pasting an order note and a clinic pasting a patient note are not the same act, and the law does not treat them as the same act.
The law, honestly sketched
The details differ; the shape does not.
- EU and UK: GDPR. You need a lawful basis, a record of what you process, and a privacy notice that tells people you use processors. There is no small-business exemption from the principles — being small reduces some record-keeping duties, not the rules.
- EU: the AI Act. Adds transparency duties as it phases in through 2025–2027: people should be told when they are talking to a machine, and synthetic media should be marked.
- India: DPDP Act 2023. Consent-led, with rules and enforcement phasing in. Notice and purpose limitation are central.
- Brazil: LGPD. Nigeria: NDPA 2023. South Africa: POPIA. Kenya: DPA 2019. California: CCPA/CPRA. Different words, same instincts.
The common core, true nearly everywhere: tell people what you do, collect the minimum, use it only for what you said, keep it only as long as you need it, be able to delete it on request, and stay responsible when you hand it to someone else.
That last clause is the one people get wrong. Your vendor's certifications cover the vendor. You are still the one who decided to send the data. Their compliance is necessary and not sufficient.
Two things that cover most of it
For a business of one to ten people, two artefacts do most of the work.
One sentence in your privacy notice. Something like: "We use third-party AI tools to help draft replies and organise enquiries. Personal details are minimised before use." Plain, true, findable.
A one-page tool list. Which AI tools touch customer data, what data, which account tier, training setting on or off, checked on what date. Keep it in a document, not in your head.
That page is what a regulator asks for, what an enterprise client's procurement form asks for, and what you will be very glad to have if anything ever goes wrong.
Where to get an hour of advice
If you work in health, law, financial advice, insurance, or with children, sector rules sit on top of data law and are stricter. Clinical notes in the US bring HIPAA. Legal work brings privilege, which a careless paste can waive. One hour with a local adviser costs less than the smallest fine in any of these regimes, and you will know within that hour whether you have a problem.
The question a customer will eventually ask
"Did a machine write this?"
Say yes. Say it in one plain sentence: "I use a tool to draft, and I read and edit everything before it goes." That answer has never lost anyone a customer worth keeping.
The alternative — denying it and being wrong — is a different kind of conversation entirely.
Before you move on