YOUR GUIDE TO:

How AI uses your personal data

From chatbots to photos, emails and online activity, AI processes huge amounts of information about us. But what happens to your data, and what rights do you have?

Join the Claim is not a law firm. This information is for general guidance only and does not constitute legal advice. While every effort has been made to ensure the information is accurate, regulations, details, and legal proceedings may change. 

Your data in the age of AI

Artificial intelligence (AI) is already built into everyday services.

It can recommend what you watch, flag suspicious payments, screen job applications, personalise adverts, and analyse images.

But AI runs on data. Lots of it. And you don’t even need to use AI directly for it to use yours.

So, what happens when your personal information becomes part of the system?

This guide looks at where AI gets personal data from, how that information may be used, and the protections UK data law gives you.

Key takeaways

Explore the latest AI-related claims

Here are some of the AI claims and investigations we are spotlighting.

Why does AI need so much data?

AI systems learn by finding patterns in data.

Depending on the type of system, developers may use enormous datasets containing text, images, audio, video, code and other information. 

Here are some of the ways that data is used: 

AI can also generate new information about people. For example, a system might analyse existing information to make a prediction or inference about someone’s interests or behaviour.

What counts as personal data?

When people hear “personal data”, they often think of obvious details such as their name, home address or phone number. But it can be much broader than that. Personal data is information relating to an identified or identifiable person.

Depending on the circumstances, that could include:

Whether particular information counts as personal data depends on whether someone can be identified from it, either on its own or when combined with other information.

That means an AI system doesn’t necessarily need to know your name to be processing personal data about you.

Where does AI get personal information from?

There is no single source of AI data. Different systems are developed and operated in different ways. 

Personal information could potentially come from:

This can make it difficult for consumers to understand when their information is being processed and why.

The Information Commissioner’s Office (ICO) is the UK’s data protection regulator. It has highlighted transparency as a particular concern around generative AI. 

Learn more about what the ICO has to say about AI on its website. 

Does public data mean fair game?

It’s easy to think that once something is posted publicly online, anyone can use it however they like. But that isn’t always the case.

AI companies often collect large amounts of information from public websites automatically. This is often called web scraping.

That information can include personal data, such as names, photos, posts or other details linked to identifiable people.

Even if that information is publicly available, UK data protection law can still apply.

The ICO has warned that using personal data scraped from the web to train generative AI can carry significant risks, especially if people do not realise their information is being used.

Companies still need a valid reason for using personal data, must use it fairly, and should be clear about what they are doing.

So, just because your information is public does not mean companies can use it however they want.

What happens to information you give an AI chatbot or search tool?

Tools such as ChatGPT, Google’s AI features, Microsoft Copilot and other AI assistants can feel like private conversations or ordinary search tools. That can make it easy to forget how much personal information we sometimes share with them.

People may use AI to:

What happens to that information depends on the tool you use, its settings and its privacy terms. Different providers have different rules on how prompts, uploads and conversations are stored, processed and whether they may be used to improve their services.

Before entering sensitive or confidential information, it’s worth asking whether the tool really needs it.

Removing names, identifying details or confidential information before submitting something is a simple way to reduce how much personal data you share.

What about sensitive personal information?

Some personal information is especially sensitive and gets extra protection under UK data protection law. This is called “special category data”.

It can include information about:

This matters because people can reveal very personal information to AI without really thinking of it as “data”.

A conversation about symptoms, for example, could reveal health information. A photograph might reveal details about someone’s ethnicity or religious beliefs. A document uploaded for summarising could contain sensitive information about several other people.

Companies have to meet stricter rules when handling this type of information. And for users, it’s worth being especially careful about sharing sensitive details with AI tools unless they are genuinely needed.

Can companies use your data to train AI without your consent?

When it comes to using personal data, consent is only one part of the picture.

Under UK data protection law, companies need a valid reason to use personal data. That reason will depend on what they are doing with the information and why.

In some cases, companies may rely on what is known as “legitimate interests” rather than asking for consent. But that does not give them a free pass.

They still need to show that using the data is necessary, fair and balanced against the rights of the people whose information is involved. They also need to be open about what they are doing.

If people have no realistic way of knowing their data is being collected or used, that can make it much harder for a company to justify the processing.

What about AI and data breaches?

AI can also create new data security risks. These tools can process huge amounts of information, including personal, financial and sensitive data, making it important that companies have strong safeguards in place.

A data breach could happen if personal information used by an AI service is accidentally exposed, accessed by someone who shouldn’t have it or shared inappropriately. The use of AI can also make existing security risks more complicated, particularly when information moves between different tools, systems and providers.

Companies remain responsible for protecting personal data when they use AI. If that information is exposed because appropriate safeguards were not in place, those affected may be able to seek compensation.

What rights do you have over your personal data?

AI doesn’t remove your existing data protection rights. Depending on the circumstances, UK data protection law gives you the ability to:

These rights are not absolute, and whether they apply will depend on the circumstances.

Can you ask an AI company to delete your information?

Potentially. The right to erasure – sometimes called the “right to be forgotten” – allows people to request deletion of their personal data in certain circumstances.

But it does not mean every company has to delete every piece of information whenever someone asks. Whether the right applies depends on why the information is being used and whether the company still has a valid reason to keep it.

With AI, things can be a little more complicated because your information may have been used in different ways or stored in different places.

The ICO says AI companies need to make sure people can still exercise their data rights, even when their information has been used as part of an AI service.

AI companies using your personal data should make it clear how you can exercise your rights, including how to ask for your information to be deleted where that right applies.

If that information isn’t clear or you’re struggling to exercise your rights, you can contact the company directly. If you’re still unhappy with its response, you can raise a complaint with the ICO.

How can you protect your information when using AI?

You shouldn’t need to avoid AI altogether to protect your privacy. But as these tools become part of everyday life, it helps to understand what you’re sharing, where it may go and whether it could become visible to other people.

Before using an AI tool:

Recent concerns about ChatGPT conversations appearing in Google search results show why this matters. There is no evidence that private ChatGPT chats are automatically being published to Google. But conversations that have been deliberately shared through public links may potentially become accessible to search engines.

The aim isn’t to make people wary of AI. It’s to help people use it with a clearer understanding of where their information may end up.

What can you do if you're concerned about how your data has been used?

If you think an organisation may be using your personal information inappropriately, start by finding out what is actually happening.

Read its privacy notice and look for information about AI, automated processing, model training or how your information is shared.

You can also contact the organisation and exercise relevant data protection rights, such as asking what information it holds about you –  this is called making a subject access request.

If you’re unhappy with how an organisation has handled your personal information, you can raise a complaint with it. You may also be able to complain to the Information Commissioner’s Office.

In some circumstances, misuse of personal data may also lead to legal action. Whether you have a claim will depend on the facts of your individual situation.

How Join the Claim can help

For years, protecting your personal information largely meant thinking about passwords, cookies, scams and what you posted publicly.

AI adds another layer.

Information can now be collected and analysed on an enormous scale, combined with other data, and used to train systems capable of generating entirely new content or making predictions about people.

That doesn’t mean every use of personal data by AI is harmful or unlawful. But it does make transparency increasingly important.

People should be able to understand when their information is being used, why it is being used, and what choices they have.

And as AI becomes part of more everyday products and services, understanding those rights will become increasingly important.

If you believe your data or rights may have been misused through AI, Join the Claim can help you explore whether there is a relevant claim or investigation and, where appropriate, connect you with a regulated UK law firm.

FAQs about AI and your personal data

Potentially. AI companies can process personal data where they comply with UK data protection law, including having an appropriate lawful basis for the processing. Whether a particular use is lawful will depend on the circumstances.

Publicly available personal information can still be protected by UK data protection law. An organisation cannot assume that personal data is exempt from data protection requirements simply because it can be found online.

AI systems can process photographs, and an identifiable photograph may constitute personal data. Whether a particular use is lawful depends on factors including how the image was obtained, why it is being processed and the legal basis relied upon.

It depends on the provider and service. AI companies have different policies and settings covering how conversations are stored and used. Check the privacy information for the particular service you’re using.

Think carefully before doing so. If an AI tool usually doesn’t need confidential or identifying information to complete the task, removing it can reduce unnecessary privacy risks. You should also follow any workplace policies when handling company or client information.

You may have rights to object to certain processing, depending on the circumstances and the lawful basis being used. Some AI providers also offer controls relating to how user content is used. Check the provider’s privacy information and settings.

You may have a right of access to personal data an organisation holds about you. How that applies to information within complex AI systems can depend on the circumstances.

You have a right to request erasure of personal data in certain circumstances, but the right is not absolute. An organisation may sometimes have a lawful reason to continue processing or retaining information.

Yes, where an AI system processes personal data. UK data protection law is technology-neutral, so organisations using AI to process personal information still need to comply with relevant data protection requirements.

The Information Commissioner’s Office regulates UK data protection law, including where organisations use AI to process personal information.

Possibly. If your personal data was used to train an AI system without your knowledge or permission, and it breaches UK GDPR or data protection laws, you may be entitled to compensation.

AI in the news

Did you know we have a newsletter?

Sign up for our newsletter to stay up to date.