It was not our AI usage. It was not our US-hosted database or server.
It was the service sending our platform emails.
Everyone should. And we genuinely do at Taught by Humans. But sometimes a customer, a project, a contract forces you to really examine and document everything.
When we were awarded a three-month contract to develop and pilot an AI-driven interactive digital learning platform for the Ministry of Justice (AI Action Plan for Justice), we had to complete a DPIA - a data protection impact assessment that maps every bit of data your product touches, where it goes, and whether that is lawful.
For many small businesses this uncovers some really big issues or changes that need to be made. I really expected to be told we could not use OpenAI for Dotly.
I am a self-confessed data privacy nerd, so I had already read all the policies backwards and forwards. When I was blanket told no data in the US, I was surprised - but actually the US CLOUD Act makes this make sense. No personally identifiable data, not no data at all.
This sounds quite scary, but it actually isn't. We had to make a few small changes, and the process of documenting everything was a useful learning opportunity. Which I'm going to share, so it feels less overwhelming.
What You Can Do
Stop using all US tech. Thankfully, I'm joking - as that would be really hard.
- If you can:
- Turn data sharing off. This means you use the tech, but your data is not stored or used for training. Most major AI companies have settings to do this, in the chat or in the APIs. We were able to do this for the AI we use in Dotly, and it means we are much more in control of our data.
- Host in the UK or EU. Often there is a choice of which data centres are used. Our database runs on Supabase - a Singapore company hosting our data on EU servers, encrypted at rest. Not straightforwardly subject to US jurisdiction.
- If these are not possible, think carefully about what data is actually being shared. The server that runs our platform, Vercel, sends all logs to the US. But we do not actually need to save any personally identifiable info in the log - using user_id in errors not email, checking no random data output logs. Good practice anyway.
- Sometimes it is not possible at all. The system sending our platform emails - Resend - saved all logs in the US. With email, you cannot avoid it - it has to be readable to be delivered. So we switched to Brevo, an EU-based email sender.
And the thing that surprisingly was not an issue - OpenAI. They have really clear, granular data privacy rules, and we were able to ensure no PII and no US data storage at all.
What started as a scary, potentially derailing concern for a tiny business has actually turned into our greatest asset. We understand every bit of tech we integrate to or use, and can explain it to our customers. A nice way to build trust.
