Skip to main content
Secure AI
Back to Insights

Responsible AI

Using AI with personal data? Check the current ICO guidance

A practical privacy check for businesses considering AI tools that may handle information about customers, staff or other identifiable people.

3 min readUpdated Secure AI editorial team

Know what information the tool will handle

Before staff put personal information into an AI service, identify what data is involved, why it is needed and who can access it. Check the provider’s terms and settings for retention, reuse, access and deletion, and use the minimum information needed for the task.

A tool being easy to access does not automatically make it suitable for customer or staff information. Set clear rules for approved services and give people a safe alternative when a task cannot use AI.

Check risks and responsibilities early

Consider whether the AI use could affect people’s rights or make decisions about them. Decide who is accountable, how outputs will be checked and how someone can challenge or correct an error. For uses likely to create higher risks to people, obtain appropriate privacy advice before proceeding.

  • Define the purpose and the information needed.
  • Check the provider, account controls and data terms.
  • Restrict access and set a retention approach.
  • Keep human review for outputs that could affect a person.

Use the ICO’s live pages

The ICO notes that parts of its AI and data protection guidance are under review following the Data (Use and Access) Act. Check the ICO’s current pages before relying on a checklist or making a compliance decision, as guidance may change.

Authoritative sources

This guidance is informed by the following primary sources and Secure AI's practical, security-first delivery approach.

Continue reading

Put the insight into practice

Make your next AI decision with confidence.

Talk through your use case, risks and practical next step with Secure AI.