If an AI workflow would touch customer, employee, prospect, or vendor data, “Is this safe and permitted?” must be answered before “Can this save time?” Privacy is part of the workflow design, not a box to check after launch.

This article provides general operational guidance, not legal, cybersecurity, or data-protection advice. Applicable duties depend on jurisdiction, role, data type, purpose, vendors, and risk. Use the checklist to surface questions; involve qualified legal, privacy, and security professionals when the use case or applicable law requires them.

Step 1: Map the data before you map the tools

Before you connect any AI tool to your website or workflow, answer one question: what data would it touch? That includes contact form submissions, purchase history, support messages, internal notes, customer lists, and any documents you might upload as context.

Write down the data type, purpose, source, destination, vendor or processor, people with access, retention, deletion path, sensitivity, and any cross-border transfer. The FTC recommends tracing how personal information moves through a business and who can access it. Run this map before adding a chatbot, personalization, or store automations.

AI use caseData it may touchSafer starting point
ChatbotCustomer questions, contact details, service history if connectedAnswer from public FAQ pages first, then add handoff
Personalized emailsPurchase history, browsing behavior, email engagementUse broad categories before sensitive or detailed profiles
Support draftingInbox messages, order data, complaint detailsDraft for human review instead of auto-sending

Start with one proposed use case. If you cannot explain why each data element is necessary, where it goes, who can access it, and when it is deleted, pause the tool connection.

Step 2: Ask vendors the questions their marketing pages skip

Before signing up or entering personal, confidential, or sensitive data, read the current contract, privacy and security documentation, and product settings. Ask:

  • Where is data processed and stored?
  • What is the retention policy, and can you shorten it?
  • Is your customer data used to train their models? Can you opt out?
  • Can the tool be configured to minimize or redact sensitive information?
  • What contractual terms cover privacy and security (DPA, SCCs, etc.)?

The depth of review should match the data and risk, but “small business” is not an exemption from understanding a provider. Verify access controls, security measures, subprocessors, retention, deletion, incident terms, and whether the vendor's actual practices match its promises. The FTC's business guidance also emphasizes collecting only what is needed, limiting access, overseeing service providers, and verifying security claims.

Step 3: Identify the rules, role, and lawful basis that actually apply

Do not assume GDPR applies—or does not apply—based on a short article. Identify the jurisdictions, people, processing activity, and whether your business acts as controller, processor, or another role. Under GDPR, the European Commission summarizes core processing principles including lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, security, and accountability.

  • Purpose and lawful basis: define the specific purpose and establish the applicable legal basis before processing. Consent, contract, and legitimate interests are not interchangeable shortcuts.
  • Transparency: give people clear, accurate information about purposes, data categories, recipients, retention, transfers, rights, and relevant automated decision-making.
  • Data minimization and retention: use only data necessary for the stated purpose, restrict access, and keep it no longer than justified.
  • Security and accountability: apply appropriate technical and organizational safeguards and preserve evidence of the decisions and controls.

Compliance is use-case and jurisdiction specific. Documentation should be proportionate and usable, but it must still cover the obligations that apply. The EDPB's Opinion 28/2024 also makes clear that questions such as anonymity and legitimate interests in AI-model processing require case-by-case assessment.

Step 4: Keep a human in the loop where it counts

Human review is an important control for high-impact decisions and customer-facing communication, but it does not by itself make processing lawful, fair, accurate, or secure. The reviewer needs authority, relevant context, and a real ability to reject or change the output.

Define which outputs require review, who reviews them, what evidence they check, which cases bypass AI, how people can reach a human, and how errors are recorded and corrected.

Map the purpose and data. Verify the provider and legal basis. Minimize access. Test the controls. Review and document the real workflow.

What a responsible setup actually looks like

A responsible setup documents the purpose, data flow, applicable roles and basis, provider review, source material, access limits, retention, security controls, human oversight, incident path, and customer-facing disclosures that are actually required and accurate. Review the design when the use, vendor, model, data, or law changes.

If any step is unclear, do not paste real data into the tool to “see what happens.” Test with synthetic or properly anonymized material where feasible and get the professional review the use case needs. Pseudonymized or merely de-identified data may still be personal data if people can be re-identified.

If you would like a hand

A workflow review can map the use case, data flow, source, vendor questions, human handoff, and measurement. It does not replace counsel, a data-protection officer, a security assessment, or other qualified specialists. If public-facing tone is the bigger trust risk, pair this with the brand voice guide.

Bring a description of the use case and data categories—not real personal, confidential, or sensitive records—to a workflow review. The next step may be a safer design, a vendor question, or referral to qualified legal, privacy, or security help.