Is Your Cloud Software GDPR Compliant? A Vendor Checklist
Why GDPR Still Matters for Your AI Tools in 2024
If you're a UK small business using AI software, GDPR compliance isn't optional — it's a legal obligation that survived Brexit through the UK GDPR framework. The Information Commissioner's Office (ICO) can issue fines of up to £17.5 million or 4% of annual global turnover, whichever is higher. With AI tools now handling customer conversations, marketing data, and behavioural insights, the stakes have never been higher.
Many small business owners assume that because a vendor is a large, reputable company, compliance is automatically handled. That assumption can be costly. You, as the data controller, remain responsible for how your vendors — acting as data processors — handle personal data on your behalf.
Understanding the Data Processor Relationship
When you plug an AI chatbot or content tool into your website or marketing stack, you're sharing personal data with a third party. Under UK GDPR, you must have a signed Data Processing Agreement (DPA) with every vendor that processes personal data on your behalf. Without one, you're already in breach, regardless of how the vendor markets itself.
AI tools are particularly sensitive because they may ingest customer queries, email addresses, browsing behaviour, or even financial information. Before signing up for any AI platform, request their DPA and read it carefully — or have your solicitor review it.
Your GDPR Vendor Checklist for AI Software
Use the following checklist when evaluating any AI tool for your small business. If a vendor cannot answer these questions clearly, treat that as a serious warning sign.
- Does the vendor provide a signed Data Processing Agreement (DPA)?
- Where is your data stored — specifically, is it held within the UK or EEA, or transferred to a third country such as the USA?
- If data is transferred internationally, what transfer mechanism is in place (e.g., UK International Data Transfer Agreement)?
- Does the vendor maintain a clear data retention policy and allow you to request deletion?
- Is there a published privacy policy that explains how your customers' data is used, including whether it trains AI models?
- Does the vendor provide a point of contact for data breach notifications within 72 hours as required?
- Are sub-processors listed and updated transparently?
- Does the vendor support your ability to respond to Subject Access Requests (SARs)?
Checking the Two Most Popular AI Tools for UK Small Businesses
Tidio AI
Tidio AI is a popular AI chatbot tool with a free tier that makes it accessible for small businesses just getting started. It automatically answers repetitive customer questions on your website, which means it will inevitably collect names, email addresses, and enquiry details from your visitors. Before activating Tidio, ensure you update your website's privacy policy to disclose chatbot data collection, and review Tidio's DPA — available from their website — to confirm data handling arrangements meet UK GDPR standards.
Tidio is straightforward to set up without technical skills, which is a genuine advantage. However, ease of use should never lead you to skip the compliance groundwork, particularly if your customers are members of the public rather than other businesses.
Jasper AI
Jasper AI, priced at £49 per month, is a content generation platform designed to save time on marketing copy whilst keeping your Brand Voice consistent across channels. Because Jasper processes the text you input — which could include customer personas, campaign briefs, or business-sensitive information — you should verify whether that content is used to train Jasper's underlying AI models. Review their enterprise data privacy settings and opt out of model training if that option is available.
Jasper publishes a DPA and sub-processor list, which is a positive sign. Ensure you document your legal basis for any personal data you input, and avoid pasting raw customer data into the platform unless you have confirmed it is compliant to do so.
Practical Steps to Stay Compliant Right Now
Start by auditing every AI tool currently connected to your business — including free tiers, which are just as legally binding as paid subscriptions. Create a simple data processing register (also called a Record of Processing Activities or ROPA) that lists each vendor, what data they receive, and where it is stored. The ICO offers free templates to help small businesses get started.
Update your website's privacy policy to reflect all AI tools in use, and ensure your cookie consent mechanism covers any tracking those tools perform. If you're already using accounting software such as Xero, FreeAgent, or Sage — all of which have UK GDPR-compliant frameworks — use their approach as a benchmark for how your AI vendors should be behaving.
Final Thoughts
UK GDPR compliance is not a one-time task — it requires regular reviews as your software stack evolves. AI tools are advancing rapidly, and vendors update their data practices frequently, sometimes without prominent announcements. Schedule a quarterly review of your vendor DPAs and sub-processor lists to stay ahead of any changes.
The good news is that compliant AI tools do exist, and the effort to verify them properly is far less costly than an ICO investigation. Treat your vendor checklist as a standard part of onboarding any new software, and your business will be well-positioned to use AI confidently and legally.