UK GDPR and AI Automation: Why Client-Owned Accounts Matter
When you automate how enquiries are handled, you're handling more customer data, in more places, often through tools you didn't build. That's where data protection stops being a tick-box and starts being practical.
This guide explains, in plain English, what UK GDPR means for a small business using AI and automation, the questions to ask any provider, and why where the system lives matters. It is general information, not legal advice. For decisions about your own business, check the Information Commissioner's Office (ICO) guidance or speak to a qualified adviser.
What counts as personal data here?
If a system holds information that identifies a person, it's personal data. In an AI front desk, that usually means:
- Names, phone numbers and email addresses
- The messages people send you, on WhatsApp, by form or by email
- What the customer asked for, and when
- Booking details and notes about a job or appointment
For clinics, salons and other businesses, some of what customers tell you can be more sensitive still, such as health information. That calls for extra care.
Who is responsible?
Under UK GDPR there are two key roles:
- The controller decides why and how personal data is used. For your customers' data, that's you.
- The processor handles data on the controller's behalf and on their instructions. If someone builds and maintains your automation and can see customer data while doing so, they're usually acting as a processor.
When a processor handles personal data for you, the law expects a written contract, often called a data processing agreement (DPA), covering things like what they may do with the data, security, and what happens when the work ends. A provider who won't sign one is a warning sign.
Why "client-owned accounts" helps
Many AI tools are platforms you subscribe to. Your customer data lives on the provider's systems, and if you stop paying, you can lose both the tool and the data.
The approach we take at SGI Solutions is different. We build inside your own Google, WhatsApp and booking accounts. We configure them, and you own them. In practice that means:
- You decide who has access, and you can remove ours at any time
- Customer data stays in accounts you control, not on our servers
- If you stop working with us, the system keeps working
- It's easier to answer a customer who asks what data you hold on them, because it's in places you can see
This doesn't remove your responsibilities as a controller, but it keeps things simpler and more transparent.
Questions to ask any provider
- Will you sign a data processing agreement?
- Where is my customers' data stored, and in which country?
- Who at your company can see it, and how is access controlled?
- What happens to the data if I leave?
- Do you use my customers' data for anything else, such as training AI models?
- Which other companies (sub-processors) handle data as part of your service?
Good answers are specific and in writing. Vague answers aren't good enough.
Telling people what you do with their data
Under UK GDPR you need to be transparent. In practice:
- Have a privacy notice that explains what you collect, why and how long you keep it
- If you use automated replies, make it clear that they're automated, which also builds trust
- Don't use enquiry data for marketing unless you have a valid basis for it. For electronic marketing such as texts, WhatsApp messages and emails, the Privacy and Electronic Communications Regulations (PECR) also apply, and you generally need consent
- Let people opt out, and act on it promptly
Keeping the system tidy
Automation tends to create copies of data: in WhatsApp, in a spreadsheet, in a calendar, in an inbox. Make sure you can answer these:
- Do we know every place customer data ends up?
- Do we delete or archive enquiries after a sensible period?
- Who on our team has access, and do they still need it?
- Can we find and remove one person's data if asked?
Don't forget the ICO
Most organisations that handle personal data in the UK need to pay the ICO's data protection fee, unless they're exempt. The ICO website has a short self-assessment to check. It's worth doing before you roll out any new system that holds customer information.
A short checklist before you automate anything
- I know which customer data the system will hold and where
- Any provider handling data for me will sign a written agreement
- My privacy notice covers what the system does
- Automated messages are clearly identified as automated
- I can remove a provider's access and keep my data and the system
- I've checked whether I need to pay the ICO fee
For the bigger picture of what an AI front desk includes and costs, see our guide to how it works, what it costs and who it's for. If you're comparing options, the cost comparison shows what to ask beyond price.
Want to talk it through?
If you'd like to see how a build in your own accounts would work for your business, you can take our free growth check or book a short call.
SGI Solutions is a trading name of Shabbir Group of Industries Ltd · Registered in England & Wales · Company No. 17320561.
