By VONA
AI and Data Privacy: What Companies Need to Know Now
GDPR, DPAs, third countries and shadow AI: a practical overview with a data traffic light and checklist so you use AI in your company with data protection in mind.
Anyone who uses AI in a company hands data out of their own control: customer names in an email, contract details in a summary, internal figures in an analysis. The technology is introduced quickly, but the question “What happens to this data?” is often asked late. This article gives you a practical overview: what matters legally, where the typical stumbling blocks lie in everyday work and how to use AI without endangering data protection and confidentiality. It does not replace legal advice but helps you ask the right questions.
What it is about legally
The GDPR makes no distinction between a human and an automated recipient. As soon as personal data is processed, the familiar rules apply. For AI applications, these points matter most:
- Legal basis (Art. 6): What do you process the data for, and what do you rely on (contract, legitimate interest, consent)?
- Information duties (Art. 13/14): People concerned must know that and why their data is processed — even when AI is involved.
- Data processing agreements (Art. 28): If an AI provider processes data on your behalf, a data processing agreement (DPA) is usually required.
- Transfers to third countries (Chapter V): If processing takes place outside the EU, you need a sound basis, such as the EU-US Data Privacy Framework or standard contractual clauses. The legal situation and provider certifications change, so check them for currency.
- Data minimization and retention periods: Enter only what the task requires, and clarify how long inputs are stored.
- Data protection impact assessment (Art. 35): It can be required for applications with a high risk for the people concerned.
- Automated individual decisions (Art. 22): Decisions with legal or similarly significant effect must not be left to an AI alone.
On top of that comes the European AI regulation (EU AI Act). It classifies AI applications by risk and attaches graded obligations, among other things regarding employees’ AI literacy. Which deadlines apply to you depends on your role and the application: check the current status (here: October 2026). If there is a works council, its co-determination rights over technical systems that monitor performance or behavior must also be observed.
Typical stumbling blocks in everyday work
- Shadow AI: employees use private accounts or free tools because there is no approved access. DPA and control are missing there.
- Customer data in public tools: a quickly pasted email with names and order data is enough to transmit personal data.
- Training on inputs: whether inputs are used for training depends on provider and plan. Behavior is not the same everywhere, so do not rely on assumptions.
- Missing DPA: the service is used before the contract is in place.
- Knowledge assistants without a permissions concept: a RAG system finds everything you show it. Without permissions, employees may see documents not meant for them.
- Unnoticed storage: logs, histories and caches keep inputs longer than you think.
A simple data traffic light
A clear classification of which data may go into which tools helps. An example (adapt it to your company):
- Green: public information, your own marketing texts, truly anonymous data. Free use in approved tools.
- Yellow: internal information without personal reference. Only in tools with a DPA and suitable settings.
- Red: personal data (especially health, employees, children), contract data, trade secrets. Only in vetted solutions, with the highest protection needs local or not at all, and after consulting the data protection officer.
Technical approaches
- Choose providers carefully: DPA available? Processing in the EU possible? Inputs excluded from training? How long is data stored? The answers differ by provider and plan.
- Pseudonymize or anonymize: remove names and direct identifiers before data goes to an external service. The model often does not need them. Important: just deleting names does not make data anonymous automatically.
- Run it yourself: open-weights models on your own infrastructure or with a provider of your choice keep the data within your own area of responsibility. This requires operation, updates and security but is an option for sensitive applications.
- Permissions for knowledge assistants: the assistant may only use sources the asking person may also see otherwise.
- Define logs and retention periods: what is stored, where and for how long? This should be documented.
Checklist before you start
- Describe the use case and data types: which data flows, from where, to where?
- Clarify legal basis and information duties.
- Vet the provider and conclude a DPA.
- Clarify storage location, use for training and retention periods.
- Involve the data protection officer; check whether a data protection impact assessment is needed.
- Define the data traffic light and a usage policy.
- Set up access rights and logging.
- Train employees (AI literacy) and name a contact person.
- Provide human review for important results (human-in-the-loop).
- After launch, regularly check whether workflows or provider terms have changed.
Organizational: policy and training
Technology alone does not solve the problem. A short, understandable usage policy says which tools are allowed, which data may go in and whom to ask when in doubt. Employees need to know and understand it — not out of mistrust but because the line between harmless and problematic input is not always obvious in everyday work. Plan regular refreshers.
Briefly answered
May I use ChatGPT or similar services in my company? Basically yes, but not thoughtlessly. Decisive are data type, provider, contract (DPA), settings and a clear policy.
Do I need a DPA? Usually yes, if a provider processes personal data on your behalf.
Is a local AI automatically GDPR-compliant? No. It keeps data in-house but replaces neither legal basis nor information duties, permissions concept and deletion concept.
Is it enough to remove names? Not always. Data is only anonymous when people can no longer be identified even by combining details. Otherwise it is merely pseudonymization, and the GDPR still applies.
Conclusion
AI and data protection do not exclude each other. They do require you to ask early what happens to the data and to secure that organizationally. A solid foundation at the start saves later corrections and builds the trust AI projects in a company need. Involve the data protection officer as a partner, not as a brake. If you would like support with planning, you will find our offer under AI integration.