This article describes general requirements and is not legal advice. Assessing your specific case belongs with legal counsel or your data protection officer.
AI projects currently generate a lot of talk about the AI Act and little about the GDPR. That is notable, because in practice companies almost never stumble over the AI Act but over a data protection question nobody asked in advance.
The reason is simple: AI tools are usually introduced not as data processing but as an aid. A writing tool, an assistant, a feature in an existing system. Only when someone pastes a real customer case into it does it become processing of personal data, and then the usual rules apply.
Four questions before the first real record
- 1.Which data actually goes in? Not what is intended, but what gets entered in daily work.
- 2.Where is it processed and by whom? Provider, sub-processors, server location.
- 3.On what basis do we process it, and is that processing reflected in the record?
- 4.What happens to the inputs afterwards? Are they stored, analysed, or used for training?
The fourth question is the one most often left unanswered, and it frequently decides the choice of tool. Whether inputs are used to improve the model is stated in the provider's terms and can be switched off in many products. Anyone who does not check decides it implicitly.
The rule that actually holds in daily work
Data protection documents only take effect once they reach daily work. In practice a single short rule works better than a twelve page paper: a list of which content may go into which tool, and one sentence on what to do when a case is not on the list.
- Allowed: general wording, anonymised cases, publicly available information.
- Not allowed without approval: customer data, personnel data, health data, contract content, internal costings.
- When in doubt: ask, and ask a named person, not the team chat.
This list replaces no documentation, but it prevents the most common failure: an employee pasting a real complaint into a tool to draft a reply faster. Her motive is good work. Without a rule she has nothing to go by.
When an impact assessment comes into play
Article 35 GDPR provides for a data protection impact assessment where processing is likely to result in a high risk to the rights and freedoms of natural persons. Whether that applies is an assessment of the individual case. Practically the question is most worthwhile where a tool prepares decisions about people, such as job applications or creditworthiness.
We record which tools in the business work with which data, and document it so that your data protection officer or legal counsel can work from it. The legal assessment stays where it belongs.