Edition 03 · Free PDF · Nurture

Your Data, Your Rules

AI and privacy in plain English — what's safe to type into ChatGPT, what the ICO expects, and how to keep your data yours.

10 pages 10 min read A4 print-ready Free PDF

Get the free guide.

Can you put customer data into ChatGPT? What does the ICO say about AI? Is it safe to use AI with business documents? This 10-page guide answers those questions in plain English, with a four-tier data classification model and a practical checklist you can use before typing anything into an AI tool.

We'll email you the download link. No spam, no newsletter — just the guide.

What's inside

6 sections, 10 pages.

  1. The question everyone's afraid to askCan I put customer data into ChatGPT? Short answer: it depends. Long answer: a four-tier model that tells you exactly what's safe and what isn't.
  2. Four tiers of data sensitivityPublic, internal, sensitive, regulated. Most businesses only need to worry about the top two tiers — but the bottom two are where the ICO gets interested.
  3. What the ICO actually saysThe ICO's guidance on AI is 40 pages of legal language. This chapter translates it into six rules you can pin above your desk.
  4. The safe-to-type checklistFive questions to ask before you paste anything into an AI tool. Takes 30 seconds. Prevents a data breach.
  5. Self-hosted vs cloud: what changesRunning AI on your own machine means your data never leaves the building. The guide explains what you gain, what you lose, and when the trade-off is worth it.
  6. A policy you can write in an afternoonA one-page AI usage policy your team can actually follow. Not a 20-page legal document — six rules, printed, signed, done.
Common questions

Questions this guide answers.

Can I put business data into ChatGPT?
It depends on the data. Public information (your website copy, published pricing) is fine. Internal but non-sensitive information (meeting notes without customer names) is usually fine with a paid plan that excludes training. Customer personal data, financial records, and health information should never go into a public AI tool. The guide gives you a four-tier classification model so you can sort your data before you type.
Is it safe to use AI with customer data?
Not with public AI tools. Customer personal data falls under UK GDPR and the Data Protection Act 2018. If you process it through a third-party AI service, that service becomes a data processor and you need a data processing agreement. The guide explains what the ICO expects and gives you a practical checklist for staying compliant.
What does the ICO say about AI?
The ICO's guidance on AI and data protection covers four areas: lawfulness and fairness, transparency, accuracy, and data minimisation. In practice, this means you need to tell people when AI is involved in decisions about them, you need to be able to explain the AI's output, and you should only feed the AI the minimum data it needs. The guide translates the ICO's guidance into plain English with examples.
How do I keep my data private when using AI?
Three approaches, from simplest to most secure: use AI tools that explicitly exclude your data from training (paid tiers of ChatGPT, Claude); self-host an open-weight model on your own machine or server; or use a UK-hosted AI service with a data processing agreement. The guide explains the trade-offs and helps you pick the right level for your data sensitivity.

Read the guide. Then talk to us if you want to.

We'll tell you on the first call if the guide is all you need.

Book a chat