Using Generative AI at Work: A Data Protection Guide for Staff
What the Irish DPC and the UK ICO say about generative AI and personal data, and practical rules for staff using AI tools at work.
A manager pastes a spreadsheet of staff absence records into a free AI chatbot and asks it to spot patterns. A support worker asks a chatbot to tidy up a note about a resident. Both are quick, and both may have just sent personal data to a third party. Generative AI is now part of everyday work, which makes data protection a skill for everyone, not only for compliance teams.
This guide summarises what two regulators have said. The Irish Data Protection Commission (DPC) published a blog post, "AI, Large Language Models and Data Protection", dated 18 July 2024. The UK Information Commissioner's Office (ICO) published a page on misconceptions about generative AI and data protection, dated 4 September 2025. The DPC applies the EU General Data Protection Regulation in Ireland and the ICO applies UK GDPR, so check which applies to your organisation.
It is important to be clear about what these pages are. They are aimed mainly at organisations that build or deploy AI products. Neither one sets out rules for individual members of staff, and the DPC page does not say whether staff should enter personal data into AI tools. Where this guide gives rules for staff, we say so and present them as practical suggestions.
What counts as personal data
Personal data is any information about an identifiable person. The ICO says that focusing only on "personally identifiable information" is not enough, because UK law covers the broader legal concept of personal data. It also says that processing counts even if it is incidental or unintentional. So a name pasted into a prompt is personal data, and so can be a combination of details that point to one person even without a name.
What the DPC says organisations should consider
The DPC says an organisation that uses an AI product that relies on personal data could be a data controller, and if so a formal risk assessment should be considered. Before use, it says organisations should understand what personal data the system uses, how it is used, and whether the provider keeps or reuses it. The main issues it names are:
- Lawful basis: there must be a legal basis for the processing, including any sharing of data for training.
- Transparency: people should be told what processing takes place and how to exercise their rights, and vendor documentation should be understandable and accessible.
- Impact assessment: a data protection impact assessment may be required, especially for new technology, combined datasets, or data about children or vulnerable people. The DPC says it may be good practice in any case.
- Accuracy: AI products can produce inaccurate or biased information, and relying on outputs without human review can create risks of automated decision-making.
- Individual rights: organisations should be able to handle requests for access, correction and erasure, including for data held within an AI system.
- Security: personal data entered by staff or by the people the data is about can create security and data protection risks, particularly with third-party tools. Organisations need to understand how it is protected and where it goes.
The DPC also raises storage limitation, purpose limitation and "memorisation", where information used to train a model may be reproduced unintentionally.
The DPC's practical advice
For organisations thinking of using AI, the DPC suggests assessing the risks before adoption, and considering whether a non-AI alternative would carry less risk. It recommends checking the vendor's documentation on how data is used, who else is involved and how long it is kept. It also suggests having processes ready for data subject requests, keeping a retention schedule, and requiring human analysis of AI outputs, particularly where decisions affect individuals.
What the ICO says about common misconceptions
The ICO page, part of its response to a consultation on generative AI, corrects seven misconceptions. Among them:
- There are "no carve-outs or sweeping exemptions" for generative AI. Data protection law applies.
- Common practice does not equal meeting people's reasonable expectations, especially for new or hidden uses such as training.
- AI models can themselves contain personal data, and the ICO says it will explore the risk of that data being retrieved or disclosed.
- The ICO does not decide compliance with laws outside data protection, such as intellectual property law.
It also encourages organisations to take a data protection by design approach and to consider compliance before they start processing. Our guide to privacy by design and data protection impact assessments explains what that involves in practice.
Practical rules for staff
Because the regulators' pages are written for organisations, the following points are our suggestions, not their instructions. Your own organisation's AI and data protection policy comes first.
- Use only the AI tools your organisation has approved. Ask before trying a new one.
- Do not paste in personal data about colleagues, customers, patients or the people you support unless your organisation has approved the tool for that purpose.
- Where you can, remove names and other identifying details first, and remember that details in combination can still identify someone.
- Check what comes back. The DPC warns that AI can be inaccurate or biased, so treat an output as a draft that you are responsible for.
- Do not use AI alone to make decisions about a person, such as discipline, recruitment or care.
- Report mistakes, such as pasting the wrong file, straight away so the organisation can respond.
Our guide to AI literacy at work covers the wider skills staff need. For the employer's side of training, see GDPR staff training requirements for employers in the UK and Ireland.
Training and CPD
Rules and tools change, so data protection training should be refreshed regularly. Keep a record of what you learn for your own development, and browse professional development options on our CPD pages.
Key points to remember
- Data protection law applies to generative AI. The ICO says there is no AI exemption.
- Personal data entered into a third-party AI tool can create security and data protection risks.
- Organisations should assess risks, check vendors and consider a data protection impact assessment before using AI.
- AI outputs can be inaccurate or biased, so a person should review them.
- Neither regulator page sets rules for individual staff, so follow your organisation's policy.
Frequently asked questions
Can I put personal data into a chatbot?
The DPC page does not give a rule on this. It says that personal data entered by staff can create security and data protection risks, particularly with third-party tools. Check your organisation's policy and use only approved tools.
Does data protection law apply to AI?
Yes. The ICO says there are no carve-outs or sweeping exemptions for generative AI.
Do we always need a data protection impact assessment?
The DPC says one may be required, particularly for new technology, combined datasets or data about children or vulnerable people, and that it may be good practice in any case.
This guide is for general information and is not legal advice. Check with your data protection officer or legal adviser.
This page was last updated:
Learnsignal Healthcare Education Team
The Learnsignal Healthcare Education Team creates CPD and compliance training content for nurses, allied health professionals, and care providers, drawing on current regulatory guidance from bodies including NMBI and equivalent professional regulators.
View all posts by Learnsignal Healthcare Education Team


