Fundamentals6 min read

AI Privacy for Small Business: A Practical Playbook

Being small doesn't exempt you from the GDPR. A practical 5-step playbook so your small business can use AI without exposing its data.

By Pierre de ONYRI
Worried about your data? Anonymize it before AI

Yes, a small business can use AI safely. But size exempts no one. The GDPR applies to every organisation, from a sole trader to a global group. Paste a customer, an employee or a financial figure into a consumer ChatGPT, and you expose personal data. The good news: this is manageable. It takes a simple playbook. Write a usage rule. Map what is sensitive. Prefer a business tier. Anonymise before you send. Train the team. The ICO puts it plainly: compliance is often common sense.

Small does not mean exempt

“We're too small to matter.” That's false. Data protection law applies the moment you collect personal data. The ICO, the UK data protection regulator, tells small organisations this plainly. If you hold customer or staff details, the rules almost certainly apply to you.

The GDPR does offer relief under 250 employees. But it is narrow. Article 30(5) only relaxes one duty: keeping formal records of processing activities. And even that relief falls away for processing that is regular, risky, or involves special-category data. In practice, a CRM, payroll or a web shop processes data all the time. So the carve-out rarely applies. It never touches the core obligations.

US law is no different. The CCPA, California's privacy law, applies to for-profit businesses once they cross a threshold. For example, annual revenue around USD 25m, adjusted upward for inflation. Or the data of 100,000 Californians a year. Or half of revenue from selling personal information. Many very small firms stay under these thresholds. The point isn't “the CCPA covers everyone.” It's “small doesn't mean exempt.”

The ICO adds a reassuring point. Compliance is achievable, not overwhelming. Many small firms already do the basics: strong passwords, shredding sensitive documents. In the UK, most only pay a modest annual fee to the ICO, around GBP 52 to 78. Large organisations pay GBP 3,763. That's a UK fee, not a GDPR fine or threshold.

The 5-step playbook

Here is the backbone. Five steps, in order, even with no dedicated privacy officer. Each one fits in an afternoon.

  1. 1Write a short AI usage policy: what may be pasted, and what may not.
  2. 2Map what counts as sensitive in your business: customer data, staff records, financials, technical secrets.
  3. 3Prefer a business tier that contractually excludes training — but verify the terms, don't assume.
  4. 4Anonymise sensitive data before any prompt: the control that works with any tool.
  5. 5Train staff and make the safe path the easy path.

What counts as sensitive

Step 2 deserves a word. Everyday records are already personal data. Customer and staff names. Email and postal addresses. Phone numbers. Payment details. So the routine information you paste into AI for an email or a payroll question is squarely in scope. Each family below deserves its own care.

  • Customer data: names, emails, purchase history, support tickets.
  • Staff records: contracts, salaries, HR reviews.
  • Financials: invoices, statements, margins, forecasts.
  • Technical secrets: API keys, passwords, access tokens.
The assumptionThe reality
“We're too small for the GDPR”The GDPR applies at any size, from the first piece of personal data
“The under-250 relief covers us”Article 30(5) touches only a record, and falls away for regular processing
“A consumer tier is enough”The CNIL advises a business tier that won't reuse your inputs
“Anonymising is too technical”A tool does it at prompt time, with any AI
Small doesn't mean exempt — but getting compliant is well within your reach.

The control that works with any tool

Step 4 is the heart of the playbook. Anonymising applies a simple GDPR principle: minimisation. The ICO sums it up well. Minimisation doesn't mean “process no personal data.” It means process only the data you actually need. An AI explaining a contract doesn't need the customer's real name.

The ICO also states the obvious. GDPR duties apply fully to AI. Lawful basis, purpose limitation, accuracy, accountability. Nothing is waived just because AI is involved. Anonymising before you send honours these rules without slowing the team.

Hub diagram: on the left, a storefront feeds three amber streams — a customer card, an employee card, a finance card, all exposed. In the centre, an anonymiser node receives the three streams and converts them into a single cobalt stream. On the right, an AI card receives only stacked cobalt tokens and a checkmark. Three in, one anonymiser, safe out.
After the ICO's guidance for small organisations and on data minimisation in AI, and the CNIL's fact sheets for small businesses.

In practice, the method is four moves. Spot the sensitive data. Replace it with reversible tokens. Send only the anonymised text. Restore the real values in the reply, locally. The safe path becomes the easy path.

That's what ONYRI Sanitize is for. The engine detects sensitive data — customer, employee, financials, API keys — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. Your team keeps the speed of AI. And your sensitive data never leaves the browser, from the customer's name to the API key.

Frequently asked questions

Can a small business use AI safely for privacy?
Yes, with a simple framework. Size exempts no one: the GDPR applies from the first piece of personal data. Write a usage policy, map what's sensitive, prefer a business tier, anonymise before you send, train the team. The ICO notes that compliance is often common sense.
Does the GDPR really apply to small businesses?
Yes. The GDPR applies to every organisation, whatever its size. The under-250 relief in Article 30(5) is narrow. It only waives a formal record, and falls away for regular or risky processing. In practice, a CRM or payroll processes data all the time. The core obligations remain in full.
How can I use AI without exposing my customers' data?
Anonymise before you send. That's the data minimisation the ICO recommends, applied at prompt time. Replace names, emails, amounts and keys with reversible tokens. The AI reasons about the structure, without seeing the real values. You restore the data afterwards, locally.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next