Customer Data Privacy When You Use AI: An SME Guide

·6 min read·Ervandra Halim

Key answer

Customer data privacy with AI is a real legal exposure for Indonesian SMEs under the PDP law, not just an enterprise problem: pasting a customer's name, phone number, or order history into a public AI tool without a business-tier data agreement is a data processing event that can breach your obligations as a data controller. Ervandra Halim's guidance: know which data is sensitive, never paste it unmasked into public AI, and name one person staff can ask when unsure.

  • Under Indonesia's PDP law, pasting a customer's name and details into a public AI tool is a data processing event, and doing so without a business-tier data agreement can breach your obligations as a data controller.
  • Personal data under PDP splits into general (names, phone numbers, transaction history) and specific (health, biometric, financial, children's data) tiers, and the specific tier requires stricter consent and carries heavier exposure if it leaks.
  • A workable privacy policy for staff fits on one page: what counts as personal data, what's safe to paste, which AI tools are approved, and one named person to ask when in doubt.

A staff member pastes a customer complaint, full name, phone number, and order history into ChatGPT to draft a polite reply. Nobody flagged it, nobody signed off, and it happens ten times a day across most SMEs I work with. Customer data privacy with ai is no longer a theoretical concern in Indonesia. Under the Personal Data Protection Law (UU PDP), that paste is a data processing event, and if it lands on a public AI tool with no data agreement, you may have just breached your own obligations as a data controller.

Most owners think privacy is an enterprise problem, something banks and hospitals worry about. It isn't anymore. If you hold customer names, phone numbers, addresses, or transaction history, and increasingly you use AI to process any of it, the PDP law applies to you regardless of company size. The good news: compliance here is mostly about habits, not expensive tooling.

This guide covers what counts as personal data under Indonesian law, what never belongs in a public AI tool, and a one-page policy you can hand to staff this week.

What Counts as Personal Data Under Indonesia's PDP Law?

Personal data under Indonesia's PDP law splits into two tiers, general and specific, and which tier your data falls into determines how careful you need to be. General data covers everyday identifiers such as names and phone numbers; specific data covers health records, biometrics, and financial details, and it triggers stricter consent and handling requirements.

General personal data: full name, phone number, email, address, gender, transaction history, purchase preferences. This is what most SMEs handle daily.

Specific personal data: health records, biometric data, financial account details, children's data, criminal records, genetic data. This tier requires stricter consent and handling, and a leak here carries heavier exposure.

If your business is a clinic, financing company, or fintech-adjacent service, you're almost certainly touching specific data. A retail chain or F&B business mostly deals with general data, but loyalty programs, membership numbers, and payment details still count.

The law requires a lawful basis to process any of it, consent being the most common for SMEs. If you never asked customers whether their data could be used for analysis or AI-assisted processing, you don't have that basis yet.

What Should You Never Paste Into a Public AI Tool?

Customer data that identifies a specific person by name, whether paired with a phone number, address, or order history, should never go into a public AI tool without a business-tier data processing agreement. This is where most breaches actually happen in practice, not from hackers, but from well-meaning staff trying to work faster.

Never paste into ChatGPT, Claude's free consumer tier, Gemini's free tier, or any AI tool without an enterprise data processing agreement:

  • Full customer names paired with phone numbers, addresses, or order history
  • Payment details, even partial card numbers or bank account numbers
  • ID numbers (KTP, NPWP) in any form
  • Health or medical information about customers or employees
  • Internal HR data, salary information, employee performance reviews
  • Any dataset exported directly from your CRM or POS without anonymization

What's generally safe to paste: anonymized or aggregated data ("we had 340 transactions last week averaging Rp85,000"), draft copy with placeholder names, general questions about process or wording.

The test I give clients: if the data would embarrass you or violate a customer's trust if it appeared in a screenshot on social media, it doesn't go into a public AI tool.

How Do You Choose an AI Vendor With Real Data Processing Terms?

Choosing an AI vendor safely comes down to two questions: does it have a real data processing agreement (DPA), and does your data train its models by default. Not all AI tools carry the same risk, and vendors that answer both questions clearly are the ones worth trusting with customer data.

Before adopting any AI tool that will touch customer data, check three things:

  1. Does it have an enterprise or business tier with a DPA? Consumer free tiers of most AI products, by default, may use your inputs for model training. Business tiers usually opt you out and offer contractual terms.
  2. Where is the data processed and stored? Ask directly. If the vendor can't answer, that's your answer.
  3. Can you delete data on request? You need this to honor your own customers' rights under PDP if they ask you to erase their data.

If you're building a custom AI workflow rather than subscribing to a generic tool, this is exactly the point where a comparison of off-the-shelf AI vs custom AI workflows becomes relevant. Custom workflows built on your own infrastructure give you far more control over where customer data actually goes.

A One-Page Policy You Can Use This Week

You don't need a 40-page compliance document. You need something staff will actually read. Here's the structure I hand to SME clients:

Section Content
What is personal data Names, phone numbers, addresses, ID numbers, payment info, health data
Never paste to public AI Any of the above, unmasked, in any AI chat tool
Safe to use Anonymized summaries, aggregated numbers, placeholder examples
Approved tools Name the specific AI tools with business-tier DPAs your company has approved
Who to ask One named person (owner, ops manager) for anything unclear
What to do if unsure Don't paste it. Ask first.

Print it, put it in the WhatsApp group staff actually use, and revisit it once a quarter. Policies that live in a Google Doc nobody opens don't work.

If you're collecting customer data through a website, loyalty program, or POS system, check whether you have a clear consent mechanism at the point of collection. A checkbox at signup stating how data will be used, including whether AI tools process it, covers you legally and builds trust. If your current systems predate this thinking entirely, it may be worth reading seven signs your business has outgrown spreadsheets, since spreadsheet-based customer lists are usually the least controlled, least auditable place data ends up.

The Practical Takeaway

Customer data privacy with ai comes down to three habits: know which data is sensitive, never let it touch a public AI tool without a business-tier agreement, and write down the rule so staff aren't guessing. None of this requires a legal team or a six-figure compliance project, it requires one afternoon to draft the policy and one meeting to explain why it matters. The businesses that get burned aren't the ones with malicious intent, they're the ones that never had the conversation.

The businesses that get burned aren't the ones with malicious intent, they're the ones that never had the conversation. Ervandra Halim

data privacypdp lawai compliancecustomer dataindonesia

Frequently asked questions

Is anonymized or aggregated customer data exempt from PDP restrictions when using AI tools?

Yes, in practice. Aggregated figures like total transaction counts or average order values carry far lower risk than any dataset that ties activity back to a named individual, so this kind of anonymized summary is generally safe to paste into a public AI tool. The rule of thumb: if no single customer can be identified from what you're pasting, you're on much safer ground.

Does the PDP law still apply if my business only handles general data like names and phone numbers, not health or financial records?

Yes. The PDP law applies to any business holding customer names, phone numbers, addresses, or transaction history, regardless of company size or industry, once general personal data is involved you already need a lawful basis, typically consent, to process it. The stricter rules only apply on top of that for specific data like health or financial records.

Are ChatGPT's or Claude's free consumer tiers ever safe for customer data?

Not for anything that identifies a real customer. Free consumer tiers generally lack a data processing agreement and may use your inputs to train their models by default, which is why the safe list in this guide is limited to anonymized summaries, placeholder examples, and general wording questions, never a named customer's details paired with contact or transaction information.

Who should be responsible for approving AI tools that touch customer data?

One named person, the owner or an ops manager, not a committee or a vague plan to let IT handle it. The one-page policy in this guide assigns this role explicitly so staff have somewhere to go when they're unsure, and vendor approval, checking for a DPA, data location, and deletion rights, should run through that same person before any new AI tool touches customer data.

Ervandra Halim

Ervandra Halim

CPTO & Principal Architect

Ervandra Halim helps owners and leaders modernize operations and put AI to work daily. He partners with a few businesses at a time, mostly by referral.

Keep reading

© 2011–2026 Ervandra Halim