GDPR and AI Automation: What UK Businesses Must Know
Automation moves personal data between more systems than ever. Here is what UK GDPR expects you to know about each one.

Short answer
Under UK GDPR, every automation that handles personal data needs a lawful basis, a mention in your privacy notice, a processing agreement with each tool provider, and a check on international transfers. Since 5 February 2026, significant decisions made solely by automation need safeguards, including a route to human review. Keep a person meaningfully involved in decisions that affect people.
GDPR and AI automation intersect at every step of a workflow that touches personal data: each tool it passes through, each AI model it is sent to, and each decision it makes about a person. UK businesses need a lawful basis for the processing, transparency in the privacy notice, proper contracts with every provider, a check on international transfers, and — since 5 February 2026 — specific safeguards for significant decisions made solely by automation.
This article explains each of those for a typical small-business setup. It is not legal advice; it is the checklist I work through before building anything, and it links to the ICO's guidance throughout. It sits within the wider guide to AI business automation.
Why automation raises the stakes
A manual process might keep customer details in an inbox and a spreadsheet. The automated version can pass the same details through a form tool, an automation platform, an AI provider, a CRM, an email platform and a messaging service. Each of those is a place the data now lives, a company processing it on your behalf, and possibly a country outside the UK.
None of that is prohibited. It just has to be known, documented and justified.
The checklist
1. Lawful basis
Every processing purpose needs a lawful basis under UK GDPR. For typical automation:
| Purpose | Common lawful basis |
|---|---|
| Processing an enquiry or booking | Contract, or steps before a contract |
| Sending invoices and reminders | Contract and legal obligation |
| Summarising enquiries with AI to respond faster | Legitimate interests, with a balancing test |
| Marketing emails | Consent, or the soft opt-in under PECR |
| Analytics and lead scoring | Legitimate interests, or consent where cookies are involved |
Write the basis down for each workflow. If you are relying on legitimate interests, record the short assessment of why the processing is necessary and does not override the person's interests.
2. Transparency
Your privacy notice should tell people what you do with their data in plain terms — including that you use automated tools and AI services to process enquiries, the categories of providers involved, and any international transfers. UK website legal requirements covers the privacy notice itself.
3. Processors and contracts
Every tool that handles personal data for you is a processor and needs a contract meeting Article 28 of UK GDPR. Most established providers — automation platforms, CRMs, AI API providers — publish a data processing agreement you accept with their business terms. Collect them, store them and list them.
Pay particular attention to AI providers:
- Use business or API offerings, not consumer chat apps, for customer data.
- Check whether inputs are used to train models, and how long they are retained.
- Check where processing takes place.
4. International transfers
Many automation and AI providers are based in the US. Transfers of personal data out of the UK need a lawful mechanism: an adequacy decision, such as the UK Extension to the EU-US Data Privacy Framework for certified US companies, or appropriate safeguards such as the International Data Transfer Agreement or the UK Addendum to EU standard contractual clauses. Providers usually say which they rely on in their data processing terms. Self-hosting a tool such as n8n on a UK server removes the transfer for that step — see n8n vs Make vs Zapier.
5. Data minimisation
Send each step only the data it needs. An AI step that classifies an enquiry by service needs the message text, not the customer's full CRM record. Strip phone numbers and addresses from prompts where they add nothing. This reduces risk and, usually, AI costs too.
6. Retention
Automation platforms keep execution logs, often containing full copies of the data that passed through. Set log retention to something sensible, and include those logs in your retention policy. The same applies to AI provider logs where you control them.
7. Security
Separate API keys per workflow, two-factor authentication on every platform account, accounts owned by the business rather than an individual, and access removed when people leave. Self-hosted tools need patching.
Automated decision-making: the rules since February 2026
The Data (Use and Access) Act 2025 replaced Article 22 of UK GDPR with new Articles 22A to 22D, in force from 5 February 2026.
In outline:
- A decision is solely automated if there is no meaningful human involvement in taking it.
- It is significant if it has a legal or similarly significant effect on the person — for example, access to a service, a job, credit or a price that materially disadvantages them.
- Significant, solely automated decisions are now generally permitted, but must come with safeguards: telling the person about the decision, letting them make representations, letting them obtain human intervention, and letting them contest it.
- Where special category data is involved — health, ethnicity, religion and so on — such decisions are much more restricted, generally requiring explicit consent or a specific legal basis.
The ICO has consulted on updated guidance reflecting these changes. Check the ICO's page on rights related to automated decision-making and its summary of the Data (Use and Access) Act changes for the current position.
What this means in practice
Most small-business automation does not make significant decisions. Summarising an enquiry, sending a reminder or routing a ticket affects nobody's rights. But some common builds do drift into this territory:
- Automatically rejecting job applicants based on a screening score
- Automatically declining customers for credit, finance or a service based on a risk score
- Automatically refusing refunds or banning accounts
The simplest compliant design is the one I recommend anyway: the automation recommends, a person decides — with the authority and information to decide differently, and actually considering each case. AI agents for small businesses describes the same principle from the reliability side.
A worked example
Say a lettings agency builds an automation that scores tenancy applications from the application form and referencing data. If the system automatically rejects anyone below a threshold, that is likely to be a significant, solely automated decision, and the safeguards apply. If instead the score and the reasons for it go to a member of staff, who reviews each application, can see the underlying information and regularly decides differently from the score, there is meaningful human involvement. The same software, designed two ways, sits on different sides of the line.
Individual rights still apply to automated data
Subject access requests cover data held in your automation platforms, CRM and logs, not just your inbox. Erasure requests need to reach every system the data flowed into. Keep a simple map of which workflows send personal data where, so you can answer these without guesswork.
Channel-specific rules
Marketing by email and text is governed by PECR as well as UK GDPR — email marketing automation for small businesses covers the soft opt-in. WhatsApp adds Meta's own opt-in requirements, covered in WhatsApp Business automation.
A one-page record for each workflow
For every automation that touches personal data, write down:
- What it does and why
- Which personal data it handles
- The lawful basis
- Every tool it passes through, with the processing agreement noted
- Where each tool processes data, and the transfer mechanism if outside the UK
- How long logs are kept
- Whether any decision affecting a person is made without meaningful human involvement
That page answers most of what the ICO, a customer or a future you would ask. The AI automation service produces this record alongside every build, though it does not replace advice from a data protection professional where your processing is high risk.
Related services
Related reading
AI & Automation
What Is AI Business Automation?
What it is, what it is not, and why the unglamorous first step is the one that determines whether any of it works.
AI & Automation
AI Agents for Small Businesses: What They Can Really Do
An agent is a model allowed to choose its own next step. That freedom is the feature and the risk.
AI & Automation
Email Marketing Automation for Small Businesses
Five automated emails do most of the work. The rest is consent, deliverability and not sending too much.
AI & Automation
WhatsApp Business Automation for UK Businesses
The free app covers more than people think. The API covers more again, with rules you need to know before building.