Data Rights in AI: What UK Businesses Must Know
Table of Contents
Data rights in AI sit at the centre of how UK and Irish businesses collect customer information, run AI chatbots, and build automated marketing tools. Every SME using an AI-powered form, a recommendation engine, or an automated email sequence is processing personal data under rules that predate most of the tools it now relies on.
This guide sets out what those rights mean in practice, who they protect, and what your business needs to do to use AI responsibly under UK GDPR. It also looks at the position facing organisations in Northern Ireland, caught between UK and EU frameworks.
The Legal Framework Behind These Rights
UK GDPR and the Data Protection Act 2018 remain the foundation for data rights in AI across Great Britain and Northern Ireland. Both set out the same core principles: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and accountability. Any AI system that touches personal data, whether that’s a chatbot, a scoring model, or a content recommendation engine, needs a clear lawful basis before it processes a single record.
The UK has taken a different route to the EU. Rather than a single AI statute, existing regulators, including the Information Commissioner’s Office, oversee AI within their own sectors. The EU AI Act introduces risk categories and mandatory assessments for high-risk systems instead. Businesses trading across both markets, which describes a large share of ProfileTree’s clients in Northern Ireland and the Republic of Ireland, need to work to both frameworks at once. The ICO’s guidance on AI and data protection focuses on fairness and explainability rather than blanket prohibition, which is a more workable starting point than it first appears.
For Northern Ireland specifically, the picture is genuinely more layered than most guidance acknowledges. Businesses here sit at the intersection of UK domestic law and continued alignment with parts of EU market rules, and that matters when data moves between the UK and the EU as part of everyday marketing or ecommerce operations.
Lawful basis is worth pausing on, because it’s where most AI projects go wrong before they even launch. Consent, contract and legitimate interests are the three bases businesses reach for most often when an AI tool touches customer data. Consent has to be freely given, specific and easy to withdraw, which rules out the pre-ticked box or the buried clause in a terms and conditions page. Legitimate interests can work for many marketing uses of AI, but it requires a documented balancing test weighing the business benefit against the impact on the individual, not just an assumption that it’s fine because everyone else does it.
Where the UK and EU Approaches Diverge
The practical difference between the two frameworks matters more than the theory. The UK’s sector-led model means an AI tool used in recruitment, lending, or healthcare is governed by that sector’s regulator as much as by the ICO, so the rules a business follows depend heavily on what the tool actually does. The EU AI Act instead classifies systems by risk level upfront, with specific obligations attached to each tier before a system can be used at all.
For a Belfast or Dublin business selling into both markets, this means checking two things separately rather than assuming compliance in one covers the other. A recruitment screening tool built for the UK market, for example, may need a formal conformity assessment before it can be used on candidates based in the EU, even if it’s already operating lawfully under UK GDPR.
Your Core Rights as a Data Subject
Six rights sit at the heart of UK data protection law, and none of them disappears just because an algorithm made the decision rather than a person.
Right to be informed: you should know when an AI system is processing your data and why, set out clearly rather than buried in a long privacy policy.
Right of access: you can request a copy of everything an organisation holds about you, including AI-generated scores or profiles, not just raw contact details.
Right to rectification: inaccurate data feeding an AI system can be corrected on request.
Right to erasure: you can ask for your data to be deleted, though for AI systems this is often harder than it sounds. Personal information can become embedded within model weights rather than stored as a discrete, deletable record.
Right to object to automated decisions: under Article 22 of the UK GDPR, you can request a human review of any decision made solely by automated means that has a legal or similarly significant effect on you, such as a loan refusal or a recruitment rejection.
Right to data portability: where processing relies on consent or a contract, you can ask for your data in a portable format.
Response deadlines matter too. Most requests, including subject access requests and objections, must be answered within one month, extendable by two months for complex cases.
The erasure right causes the most friction in practice, and it’s worth understanding why before a customer or regulator raises it. Deleting a row from a customer database is straightforward. Removing the influence of that same record from a trained AI model is a different problem entirely, because the data has already shaped the model’s weights rather than sitting as a discrete, retrievable entry. This is sometimes called the machine unlearning problem, and it’s an active area of technical research rather than a solved one.
In practice, most businesses handle this by deleting the record from any live training pipeline going forward and documenting that the historical model version will be retired or retrained on a set schedule, rather than promising instant removal they can’t technically deliver.
What This Means for Your Business
For businesses building AI-powered marketing, chatbots, or content tools, data rights in AI translate into a handful of concrete jobs rather than an abstract compliance burden.
Start with an AI data audit. Map every AI tool in use across marketing, sales and customer service, and note what personal data each one touches and on what lawful basis. A useful audit log records the tool name, what it’s used for, what personal data flows through it, the lawful basis relied on, and who owns the relationship internally. Most SMEs are surprised by how long this list runs once chatbots, email personalisation tools, and analytics platforms are all counted rather than just the obvious customer relationship management system. If your website collects data through GDPR-compliant web forms, check that the same standard applies to any AI layer built on top of them, chatbots included.
Where an AI application is likely to create high risk, profiling customers at scale or monitoring staff, a Data Protection Impact Assessment should happen before the tool goes live, not after a complaint arrives. Our approach to data protection for online businesses covers this in more depth, and our GDPR training for teams is built around exactly this kind of practical decision-making rather than theory.
“Getting AI and data protection right is not just a legal necessity; it is a competitive advantage. Businesses that treat personal information properly build deeper trust with customers and are better placed as regulation tightens,” says Ciaran Connolly, founder of ProfileTree.
Staff training matters as much as policy. Anyone handling customer communications, recruitment, or AI-assisted decisions should understand what these rights mean in practice, which is where structured AI training for your team earns its keep well beyond the compliance box it ticks. Whether that training sits in-house or is outsourced depends on team size and how often the tools change, though most SMEs we work with benefit from a mix of both, alongside our wider digital training services.
Getting the Practical Steps Right
For individuals, the process is more straightforward than it feels. Identify which AI systems hold meaningful personal data about you, submit a subject access request through the provider’s privacy portal, and keep a written record of the date. If an automated decision affects you, request a human review in writing and cite Article 22 directly. Where a business fails to respond within a month, the ICO’s complaint form is the next step.
For businesses, ethics and legal requirements around AI extend well past data protection into fairness, bias and transparency more broadly, and the wider ethics and legalities of digital marketing sit alongside this. The same discipline that applies to compliance and security in online payments applies here: document your lawful basis, train your team, and treat data protection as part of how AI gets built rather than something bolted on afterwards. Our AI implementation and transformation work with clients usually starts at exactly this point, well before any content or automation goes live.
Frequently Asked Questions
A few questions come up more than most when businesses and individuals start working through data rights in AI.
Does GDPR apply to AI systems?
Yes. Training or running an AI system on personal data still requires a lawful basis under UK GDPR, regardless of whether a human or an algorithm makes the final decision.
Can I stop a company using my data to train its AI?
Sometimes. You can object where processing relies on legitimate interests, or withdraw consent where that’s the basis used.
What should I do if an AI system makes a wrong decision about me?
Request a human review in writing, cite Article 22 of the UK GDPR, and raise a complaint with the ICO if the response is inadequate.
Can personal data really be deleted from an AI model?
Not always easily. Data used to train a model can become embedded in its weights, which is harder to remove than deleting a database record.
Are data rights different in Northern Ireland?
Not in substance, but businesses here sit within both UK domestic law and continued EU market alignment, which affects how data can move across borders.
Do businesses need a Data Protection Impact Assessment for every AI tool?
Only for tools likely to create high risk, such as large-scale profiling or employee monitoring, but it’s worth checking early rather than assuming a tool is exempt.