Using AI with customer data: a founder's privacy-first checklist
Before you pipe customer records into a model: lawful basis, transparency, minimisation, vendor handling, retention and when a DPIA is the right call.
Adding an AI feature to a product that holds customer data is a data protection decision before it is a technical one. The ICO's guidance is unusually readable, and working through it early is far cheaper than retrofitting.
Key takeaways
- Identify your lawful basis for each use of personal data, including model inputs and any training.
- Tell people plainly what happens to their data; buried terms are not transparency.
- Minimise: send the fields the feature needs, not the whole record.
- Check what your AI vendor does with inputs, where they are processed and for how long they are retained.
- Consider a DPIA where processing is likely to be high risk, and do it before you build.
Lawful basis and purpose
Start by writing the purpose in one sentence. Then identify the lawful basis for that purpose. If you are reusing data collected for something else, check whether the new purpose is compatible. Training a model on customer data is a distinct purpose from using a model to serve that customer.
Transparency and minimisation
People should be able to find out, without effort, that AI processing is involved and what it means for them. Alongside that, reduce what you send: a summarisation feature rarely needs full identifiers, and stripping them before the API call removes whole categories of risk.
Vendors, security and retention
Most of the real exposure sits with the third parties in your pipeline.
- What does the provider do with prompt and output data? Is it used for training?
- Where is it processed, and what contractual terms cover it?
- How long is anything retained, by you and by them?
- Who on your team can see inputs and outputs, and is that access logged?
- How would you honour an erasure request across logs, caches and vector stores?
Design it in
The ICO's AI and data protection risk toolkit is a good structured self-assessment, and its data protection by design and by default guidance is the practical framing: decisions made at design time are cheap, and the same decisions made after launch are a migration. Where processing is likely to result in high risk, complete a DPIA before building.
What to ask other founders
Guidance tells you the rules. Other founders tell you what actually happened. These are worth asking as a structured Advice or Critique request.
- What did your first enterprise security review ask about AI vendors?
- How do you handle erasure requests across logs and vector stores?
- Did you complete a DPIA before launch, or after someone asked?
Sources & further reading
General information only, not legal advice. Some ICO AI material is under review following the Data (Use and Access) Act 2025, so check the ICO pages for the current position. Data protection obligations depend on your specific processing, take advice where the risk is material.
Read next
Stuck on one of these?
NoNetwork is where founders ask for practical help and give it. Free for founders.
Join free