I'm seeing an increasing number of student accommodation marketing teams start to integrate AI into their day to day tasks, which is great.
But the compliance conversation hasn't kept up. Most guidance on AI and data privacy is written for legal teams or IT departments, not for the Marketing Manager who just wants to know whether it's safe to use ChatGPT with their work.
This blog addresses that gap directly, with a focus on what matters for Purpose Built Student Accommodation (PBSA) marketing teams working in the UK.
What happens to data when you put it into an AI tool?
When you type or paste information into an AI tool like ChatGPT, that data is sent to external servers for processing. Depending on the tool's settings and your subscription tier, it may be stored, used to train future models, or retained in conversation logs. Any personal data you input could end up somewhere you didn't intend.
This is the foundational question, and it's the one most marketing teams skip past. The assumption tends to be that AI tools work like internal software, where your data stays within your organisation. They don't. Most AI tools are cloud-based services operated by third-party companies, often based outside the UK. When you paste a student's name, email address, or testimonial into ChatGPT (or any other AI tool), you're likely transferring that data to that provider's servers.
The implications under UK GDPR are significant. Personal data can only be processed if you have a lawful basis for doing so, and that lawful basis needs to cover the specific processing activity. Having consent to email a student doesn't automatically mean you have consent to upload their details into a third-party AI system. These are different processing activities, and they need to be treated as such.
Quick side note - I help marketing teams stay compliant when using AI with training that goes over this stuff and more. Learn more here: https://www.theaimethod.co/services
Some paid tiers of AI tools (ChatGPT Team and Enterprise, Claude for Business) offer data isolation, meaning your inputs aren't used for model training and aren't accessible to other users. This is a meaningful distinction. If your team is going to use AI tools with any data that touches real people, using a business-grade subscription with data isolation isn't optional. It's the minimum.
Can you use AI to write content about students?
You can use AI to draft content about students in general terms, but you can't input identifiable student information - names, email addresses, photos, testimonials, or enquiry data - into an AI tool without a specific lawful basis for that processing. The safe approach is to anonymise completely before using AI, or to use AI only for generic content.
In practice, this means a few things for PBSA marketing teams. Writing a generic social media post about student life in Leeds using AI is fine. Pasting a student's testimonial into ChatGPT and asking it to "make this sound better" isn't, because you've just transferred that student's personal data to a third-party processor without a clear lawful basis.
The same applies to photos and video. Uploading an image of identifiable students to an AI tool for editing, captioning, or analysis constitutes processing of personal data. It doesn't matter that the tool's output might not include the image. The act of uploading it is the processing event, and it needs to be covered by your data protection framework.
The practical workaround is straightforward but requires discipline. If you want to use AI to improve a student testimonial, strip out the name and any identifying details first, run it through the AI tool, then add the attribution back in your final copy. If you want to use AI to generate social content inspired by real student feedback, summarise the themes yourself and brief the AI on those themes rather than pasting in the original feedback. It adds a step, but it keeps you on the right side of the regulation.
What is changing in UK data law that affects AI use?
The UK Data (Use and Access) Act 2025 amends the UK GDPR with updated rules on automated decision-making, new cookie and consent provisions, and changes to lawful bases for direct marketing. Key AI-related provisions roll out through the first half of 2026 and directly affect how your marketing team can use AI tools.
The DUA Act eases some restrictions on automated decision-making, which may give marketing teams more flexibility to use AI for tasks like audience segmentation or lead scoring. However, it also strengthens transparency requirements. If you're using AI to make decisions that affect individuals (even marketing decisions like who receives which email), you may need to be more explicit about the fact that AI is involved.
For PBSA marketers specifically, the changes to cookie and consent rules are worth watching. If your website uses AI-powered chatbots, personalisation, or recommendation features, the updated PECR provisions may affect how you need to handle consent for those tools. The specifics are still being finalised, but the direction of travel is toward more transparency, not less.
The practical step here isn't to panic but to document. Make sure your team knows which AI tools you use, what data goes into them, and what lawful basis you're relying on for each use. That documentation is what a regulator would ask for if there were ever a complaint, and having it in place is significantly better protection than hoping nobody asks.
Do you need an AI policy for your marketing team?
Yes. Even if it's a one-page document, your marketing team needs clear guidance on what they can and can't put into AI tools, which tools are approved, and what to do if they're unsure. Without this, individual team members will make their own judgements, and those judgements will be inconsistent.
An AI policy for a PBSA marketing team doesn't need to be a 30-page legal document. It needs to answer five practical questions. Which AI tools are approved for use? What types of data can be entered into those tools? What types of data must never be entered? Who's responsible for checking compliance when a new tool is introduced? And what should a team member do if they're not sure whether something is safe?
The most common gap isn't the absence of a policy but the absence of specific examples. Telling your team "don't put personal data into AI tools" is correct but insufficient, because most people don't instinctively classify a student testimonial or an enquiry spreadsheet as "personal data" in the moment they're working with it. Your policy needs to name the specific scenarios: student names, email addresses, phone numbers, photos, video footage, testimonial quotes, enquiry form data, booking information. Make the boundaries concrete.
It's also worth including your approved tools list with a note on their data handling. If your organisation uses ChatGPT Team, for instance, your policy should confirm that this is the approved version (not the free tier, which has different data retention policies) and explain why the distinction matters. This level of specificity turns a compliance document into something your team can actually use.
Where should a PBSA marketing team start with AI compliance?
Start with an audit of what your team is already doing. In most cases, individual team members are already using AI tools informally, and you need to know what data is going where before you can put guardrails in place. From there, move to approved tools, a simple policy, and basic training on what is and isn't safe to input.
The reality in most marketing teams is that AI adoption has already happened informally. People are using ChatGPT on their phones, pasting copy into Grammarly, or using Canva's AI features without thinking about the data implications. That's not a criticism of those individuals. It's a reflection of how quickly AI tools have become embedded in everyday work, outpacing the policies that should govern their use.
Step one is a quick, honest audit. Ask your team: what AI tools are you currently using, and what are you putting into them? You'll almost certainly find that some tools are being used with data that shouldn't be going into them. That's your baseline, and it's better to know now than to find out when something goes wrong.
Step two is to select and approve a small number of tools with appropriate data handling. For most PBSA marketing teams, a paid ChatGPT Team or Claude Pro subscription with data isolation, plus Canva's built-in AI features, covers the majority of use cases. Make these the approved tools, explain why, and make clear that free-tier AI tools shouldn't be used for any work involving student data or business-sensitive information.
Step three is training. Not a one-off presentation, but an ongoing conversation about what safe AI use looks like in practice. The landscape is changing quickly. New tools launch, existing tools update their terms, and the regulatory environment is actively shifting through 2026. A team that understands the principles behind the rules will make better decisions than one that was given a checklist six months ago.
An optional step four is to get external help and guidance. I've been working in the student accommodation sector for nearly 20 years and understand the pressures marketing teams are under to attract and retain residents. I can help get your team set up with the right AI tools in a compliant and constructive way.
About The AI Method: Oliver Harrison works with in-house Content and Marketing teams, helping them move from 'thinking about AI' to actually working with it. If you'd like to explore how AI tools could fit your team's workflow, find out more at www.theaimethod.co.