All terms

Regulation & Policy

AI privacy

Also known as: privacy in AI, AI data privacy

AI privacy is the set of practices, rights and obligations that govern how personal data is collected, used, stored and exposed when building or using AI systems. It covers training data, prompts and outputs, retention by AI vendors, and the transparency and control offered to the people whose data is involved. For marketing teams it shapes what customer data can safely be put into AI tools and what must be disclosed.

What it is

AI privacy concerns the handling of personal information across the whole AI lifecycle, from the datasets used to train or fine tune a model, to the prompts staff type into an assistant, to the logs and outputs a vendor retains. It sits at the intersection of data protection law, information security and vendor management. In the UK and EU it is largely governed by existing data protection rules such as the UK GDPR and EU GDPR, alongside newer AI specific regulation.

Why it matters

Marketing and search teams now push customer lists, support transcripts, CRM notes and site analytics through AI tools, which can move personal data to new processors and new countries without anyone noticing. Getting this wrong risks regulatory action, contract breaches with clients, and loss of trust that is hard to rebuild. Privacy choices also shape what you can publish and personalise, which in turn affects how your brand is represented in AI assistants and search results.

How it works

Practitioners map which AI tools touch personal data, check vendor terms for training use, retention periods and sub processors, and choose settings or enterprise plans that exclude your inputs from model training. They apply data minimisation by stripping identifiers before prompting, restrict sensitive categories entirely, and record the reasoning in a data protection impact assessment where the processing is high risk. Policies are then paired with training, approved tool lists and monitoring so staff know what may be pasted into a chat window.

When it applies

It applies whenever an AI system processes information relating to identifiable people, including customers, prospects, employees and site visitors. It becomes especially pressing when adopting new AI tools, building agents that read internal systems, or personalising content and ads using behavioural data.

Examples

  • A retailer blocks staff from pasting customer email lists into a public chatbot and provides an enterprise account with training on inputs disabled instead.
  • An agency runs a data protection impact assessment before using an AI tool that summarises call recordings, and updates its privacy notice to mention AI assisted analysis.
  • A SaaS firm redacts names and account numbers from support tickets before feeding them into a model that drafts help centre articles.

How it is measured

  • Share of AI tools in use that have been reviewed and approved against a privacy checklist
  • Number of data protection impact assessments completed for AI use cases, and outstanding ones
  • Volume or rate of blocked or flagged prompts containing personal or sensitive data, via data loss prevention tooling
  • Percentage of AI vendor contracts with documented retention limits and no training on customer inputs

Related terms in Regulation & Policy

Primary research · August 2026

How ChatGPT Shortlists Software Brands

An audit across 10 categories and 60 buying questions. I recorded what ChatGPT reads, throws away and links to when a buyer asks it which software to buy, and what that decides.

60
Questions asked
10
Software markets
2,680
Results read
367
Links shown
Free35 pages · PDF · 536 KBDiscovery Digest every Friday

Free download

Get the full report

35 pages · PDF · 536 KB. Enter your details and it downloads straight away.

How ChatGPT Shortlists Software Brands downloads straight away. No spam, unsubscribe anytime.