Customer data, privacy and AI tools: what an Indian small business should know
Using AI does not remove your responsibility for customer data. A plain-language guide to the habits, the settings and the basics of India's data protection law.

On this page
When someone in your team pastes a customer list into an AI tool, that information leaves your business and goes to another company's computers. Usually nothing bad happens. But the responsibility for that data remains yours. This guide explains, in plain words, what to do about it.
It is general information to help you ask the right questions. It is not legal advice.
What counts as personal data
Any information about a person who can be identified: name, phone number, email, address, photo, ID numbers, purchase history linked to a name, an employee's salary. A list of products and prices is not personal data. A list of customers and what they bought is.
The law in brief
India has a law for this: the Digital Personal Data Protection Act, 2023, with rules published in 2025. Its duties are coming into force in stages, so check the current position. The main ideas are simple:
- Purpose. Use personal data only for the purpose the person gave it for, or agreed to.
- Notice and consent. Tell people clearly what you collect and why, and get their agreement where the law requires it. They can withdraw it.
- Accuracy and limits. Keep data correct, and do not keep it longer than needed.
- Security. Take reasonable steps to protect it. Penalties for failing to do so can be very large.
- Rights. People can ask what you hold about them, and ask you to correct or delete it.
- Breach. If personal data is leaked, the law requires you to inform the authority and the people affected.
- Children. Data of people under 18 needs extra care and a parent's consent.
The law applies to small businesses too. A company that handles data for you, such as an AI tool provider, is acting on your behalf, and you remain answerable.
Five habits that cover most of the risk
1. Collect less
Do not ask for information you do not need. If you do not need a date of birth or an ID number, do not collect it. Data you never collected cannot leak.
2. Use placeholders with AI
Before pasting text into an AI tool, replace personal details: [customer name], [phone], [address]. Ask for the draft, then add the real details yourself. This one habit removes most of the risk. A team policy helps: see Simple AI rules for your team.
3. Check the tool's data settings
For every AI tool used for work, find out:
- whether what you type is used to train the provider's models, and how to turn that off
- whether a business plan offers stronger terms
- where the data is stored and how long it is kept
- how to delete it
Write the answers down. If you cannot find them, treat the tool as unsafe for customer data. See What to check before you pay for any AI tool.
4. Limit who can see what
- Separate logins for each person. No shared passwords.
- Two-step login on email, accounting and customer tools.
- Remove access on the day someone leaves.
- Customer lists are not sent to personal email or personal WhatsApp.
5. Delete what you no longer need
Old enquiry sheets, CVs of people you did not hire and exported customer lists in download folders are all risk with no benefit. Set a date twice a year to clear them. Keep what tax and other laws require you to keep.
A simple test for any new use of AI
Before a new AI use starts, ask four questions:
| Question | If the answer is "no" |
|---|---|
| Does the task work without personal data? | Use placeholders or sample data. |
| Have we read this tool's data terms? | Read them first. |
| Would the customer be comfortable if they knew? | Rethink it, or ask them. |
| Can we delete the data from the tool afterwards? | Choose another tool. |
Example
A made-up coaching centre, used only to show the thinking.
The centre wants AI to write fee reminder messages. The first idea is to paste the full student list with parents' phone numbers and pending amounts. Instead, the owner asks AI for three reminder templates with placeholders, and the office staff fill in names and amounts from the fee register when sending. The result is the same, and no personal data left the centre. Because many students are under 18, the centre is also careful to hold parents' consent for the data it keeps.
Marketing messages
Send promotional messages on WhatsApp, SMS or email only to people who agreed to receive them, and make it easy to say stop. Keep a simple record of who agreed and when. This is good manners as well as good compliance.
If something goes wrong
If you learn that customer data has been exposed, for example a sheet shared with the wrong person or an account that was broken into:
- Stop the leak: change passwords, remove the shared link.
- Write down what happened, when, and which data.
- Take advice quickly about your duty to inform the authority and the people affected.
- Fix the cause.
What a small business should do this month
- List where you keep customer and employee data: sheets, apps, phones.
- Write one page of AI rules and explain it to the team.
- Check the data settings of the AI tools already in use.
- Turn on two-step login for the important accounts.
- Add a short privacy notice where you collect data: your form, your website, your invoice footer.
A final point
Customers give their details to businesses they trust. Handling those details carefully is not only a legal duty. It is part of your reputation.


