top of page

Customer consent when you use AI on their data, in practice

  • 5 days ago
  • 3 min read

Introduction


Two separate questions arise when a business starts processing customer information through these tools. The first is whether it is lawful, which depends on the data, the jurisdiction, the basis you rely on and any contract you have signed. The second is whether the customer would object if they found out, which is a question about the relationship and is not answered by the first.

They diverge more often than people expect. Processing may be entirely lawful and still damage trust if it emerges without warning, particularly in professional relationships where clients assume their information stays with the person they gave it to. Both questions need answering, and answering only the legal one is a common and avoidable mistake.


1. Customer consent when you use AI on their data is two questions


Legality and trust.

What you are permitted to do, and what your customer would consider acceptable. Both need an answer, and the second is the one that determines whether the relationship survives finding out.


2. Establish your lawful basis first


Consent is not always the right one.

Depending on jurisdiction, processing may rest on contract, legitimate interests, or consent, and the correct basis depends on the circumstances. Assuming consent is required, or assuming it is not, are equally common errors.


3. Check your existing contracts and privacy notice


They may already constrain you.

Client agreements, confidentiality clauses, professional obligations and your published privacy information all describe what you said you would do. New processing that falls outside that description needs addressing.


4. Treat sensitive categories separately


Higher requirements almost everywhere.

Health information, financial detail, information about children, and anything that could cause harm if exposed. The rules for these are stricter in most jurisdictions and the trust consequences are larger.


5. Apply the test of unexpected disclosure


The practical trust check.

Would this customer be surprised or uncomfortable to learn what you are doing? If the answer is yes, tell them in advance, regardless of whether you were obliged to.


6. Where you tell them, be specific


Vagueness is worse than silence.

"We use technology to improve our service" tells nobody anything and reads as evasive when examined. What is processed, for what purpose, and what is not done with it, in plain language.


7. Be careful with anything that leaves your control


The clearest line for most customers.

Internal use of a tool that processes data within your own systems is understood differently from sending client material to a third-party service. Customers who accept the first frequently object to the second.


8. Give people a way to object


Both good practice and often required.

A route to ask what you do, to object, or to request that their information is handled differently. Where individuals have rights over their data, you need a process to respond to a request rather than an intention to.


9. Keep a record of what you decided


The documentation that matters later.

What processing you assessed, what basis you relied on, what you told people and when. If it is ever questioned, the record is the answer, and reconstructing the reasoning afterwards is not the same thing.

Data protection law, professional confidentiality rules, sector regulation and the requirements around automated processing vary considerably by jurisdiction and are changing quickly in several. For anything involving personal data at scale or sensitive categories, confirm the position that applies to you.


Conclusion


Answer the trust question as well as the legal one, because they do not always agree.

Establish your lawful basis rather than assuming consent is or is not required, check what your existing contracts and privacy notice already commit you to, treat sensitive categories with more care, apply the test of whether the customer would be uncomfortable to find out, be specific rather than vague where you do tell them, recognise that sending data to a third-party service is understood differently from internal processing, provide a route to object, and record the decision and its reasoning.


Related reading


 
 
 

Comments


bottom of page