AI Privacy for Small Business: A Practical Playbook
Being small doesn't exempt you from the GDPR. A practical 5-step playbook so your small business can use AI without exposing its data.
Yes, a small business can use AI safely. But size exempts no one. The GDPR applies to every organisation, from a sole trader to a global group. Paste a customer, an employee or a financial figure into a consumer ChatGPT, and you expose personal data. The good news: this is manageable. It takes a simple playbook. Write a usage rule. Map what is sensitive. Prefer a business tier. Anonymise before you send. Train the team. The ICO puts it plainly: compliance is often common sense.
Small does not mean exempt
“We're too small to matter.” That's false. Data protection law applies the moment you collect personal data. The ICO, the UK data protection regulator, tells small organisations this plainly. If you hold customer or staff details, the rules almost certainly apply to you.
The GDPR does offer relief under 250 employees. But it is narrow. Article 30(5) only relaxes one duty: keeping formal records of processing activities. And even that relief falls away for processing that is regular, risky, or involves special-category data. In practice, a CRM, payroll or a web shop processes data all the time. So the carve-out rarely applies. It never touches the core obligations.
US law is no different. The CCPA, California's privacy law, applies to for-profit businesses once they cross a threshold. For example, annual revenue around USD 25m, adjusted upward for inflation. Or the data of 100,000 Californians a year. Or half of revenue from selling personal information. Many very small firms stay under these thresholds. The point isn't “the CCPA covers everyone.” It's “small doesn't mean exempt.”
The ICO adds a reassuring point. Compliance is achievable, not overwhelming. Many small firms already do the basics: strong passwords, shredding sensitive documents. In the UK, most only pay a modest annual fee to the ICO, around GBP 52 to 78. Large organisations pay GBP 3,763. That's a UK fee, not a GDPR fine or threshold.
The 5-step playbook
Here is the backbone. Five steps, in order, even with no dedicated privacy officer. Each one fits in an afternoon.
- 1Write a short AI usage policy: what may be pasted, and what may not.
- 2Map what counts as sensitive in your business: customer data, staff records, financials, technical secrets.
- 3Prefer a business tier that contractually excludes training — but verify the terms, don't assume.
- 4Anonymise sensitive data before any prompt: the control that works with any tool.
- 5Train staff and make the safe path the easy path.
What counts as sensitive
Step 2 deserves a word. Everyday records are already personal data. Customer and staff names. Email and postal addresses. Phone numbers. Payment details. So the routine information you paste into AI for an email or a payroll question is squarely in scope. Each family below deserves its own care.
- Customer data: names, emails, purchase history, support tickets.
- Staff records: contracts, salaries, HR reviews.
- Financials: invoices, statements, margins, forecasts.
- Technical secrets: API keys, passwords, access tokens.
| The assumption | The reality |
|---|---|
| “We're too small for the GDPR” | The GDPR applies at any size, from the first piece of personal data |
| “The under-250 relief covers us” | Article 30(5) touches only a record, and falls away for regular processing |
| “A consumer tier is enough” | The CNIL advises a business tier that won't reuse your inputs |
| “Anonymising is too technical” | A tool does it at prompt time, with any AI |
The control that works with any tool
Step 4 is the heart of the playbook. Anonymising applies a simple GDPR principle: minimisation. The ICO sums it up well. Minimisation doesn't mean “process no personal data.” It means process only the data you actually need. An AI explaining a contract doesn't need the customer's real name.
The ICO also states the obvious. GDPR duties apply fully to AI. Lawful basis, purpose limitation, accuracy, accountability. Nothing is waived just because AI is involved. Anonymising before you send honours these rules without slowing the team.
In practice, the method is four moves. Spot the sensitive data. Replace it with reversible tokens. Send only the anonymised text. Restore the real values in the reply, locally. The safe path becomes the easy path.
That's what ONYRI Sanitize is for. The engine detects sensitive data — customer, employee, financials, API keys — and replaces it with reversible tokens before sending. Detection and the mapping stay in your browser. Only anonymised text reaches the model. Your team keeps the speed of AI. And your sensitive data never leaves the browser, from the customer's name to the API key.
Frequently asked questions
- Can a small business use AI safely for privacy?
- Yes, with a simple framework. Size exempts no one: the GDPR applies from the first piece of personal data. Write a usage policy, map what's sensitive, prefer a business tier, anonymise before you send, train the team. The ICO notes that compliance is often common sense.
- Does the GDPR really apply to small businesses?
- Yes. The GDPR applies to every organisation, whatever its size. The under-250 relief in Article 30(5) is narrow. It only waives a formal record, and falls away for regular or risky processing. In practice, a CRM or payroll processes data all the time. The core obligations remain in full.
- How can I use AI without exposing my customers' data?
- Anonymise before you send. That's the data minimisation the ICO recommends, applied at prompt time. Replace names, emails, amounts and keys with reversible tokens. The AI reasons about the structure, without seeing the real values. You restore the data afterwards, locally.
Sources & references
- Getting started with data protection: a step-by-step guide for small organisations (the law applies at any size) — Information Commissioner's Office (ICO)
- Using generative AI in very small and small-to-medium businesses (never enter personal or confidential data into a consumer AI) — CNIL (Commission nationale de l'informatique et des libertés)
- How should we assess security and data minimisation in AI? (process only the data you actually need) — Information Commissioner's Office (ICO)
Keep your sensitive data in your browser
ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.