GDPR-compliant AI use in your company
In most companies, people already work with AI. The only question is whether officially or as shadow AI on private accounts. That is exactly where the data protection problem starts: anyone pasting customer data into a consumer chatbot passes it to a third party without a data processing agreement, and often with training enabled. Whether the processing as such is lawful follows from Art. 6 GDPR and can often be justified in a given case. The missing contract under Art. 28 is a breach regardless. In practice that means: private account out, business plan with a DPA in.
The solution is not a ban but orderly adoption. This article covers the four core questions, the EU AI Act timeline, and which tools meet the requirements. It does not replace legal advice, but it gives you the structure for the conversation with your data protection officer.
The four core questions before any AI rollout
1. Is there a data processing agreement (DPA)? As soon as an AI service processes personal data, Art. 28 GDPR requires a DPA. Consumer offerings don't provide one; business plans and API access from the major vendors do.
2. Where is the data processed? Ask about storage and processing separately, they are not the same thing. OpenAI offers EU data residency on enterprise plans; with Anthropic the EU route runs through AWS Bedrock in Frankfurt, which changes who your contracting party is. Mistral processes in Europe by default. With US vendors, the US CLOUD Act remains a residual risk you need to assess and document.
3. Are inputs used for model training? The knockout criterion. With consumer services, training is often on by default; with business and API access, it is contractually excluded. Verify this in writing, not through marketing claims.
4. Who controls access and usage? SSO, permission management, and audit logs make AI use traceable. Without central administration, shadow AI emerges, and the GDPR's accountability obligations come to nothing.
Reviewing an AI platform
24 review questions across six axes, with a findings sheet. Vendor-neutral.
EU AI Act: what comes on top from August 2026
The GDPR stays, the AI Act comes on top. Both apply side by side. The timeline in short:
- Since February 2025: Prohibited AI practices are banned, and Art. 4 requires AI literacy. The obligation falls on the organisation as provider or deployer, not on the individual: it has to make sure its people can work with AI, and be able to show it. This includes marketing, HR, and sales.
- Since August 2025: Obligations for providers of general-purpose AI models (GPAI).
- From 2 August 2026: The AI Act becomes generally applicable. Practically relevant are the transparency obligations: chatbots must identify themselves as AI, and AI-generated content must be machine-readably labelled. Fines become enforceable, up to 35 million euros or 7 percent of global revenue.
- From 2 December 2027 and 2 August 2028: the high-risk obligations. The Digital Omnibus on AI, Regulation (EU) 2026/1744 of 8 July 2026, in force since 27 July 2026, moved them through Article 113: Annex III to 2 December 2027, Annex I to 2 August 2028. The transparency obligations from August 2026 are unaffected. Source: Official Journal L, 2026/1744 of 24 July 2026, retrieved 10 August 2026.
Important in practice: as a company using AI, you cannot fully delegate compliance to the tool vendor. Responsibility for the area of use, training, and transparency towards customers stays with you. Our post on the EU AI Act provides an assessment for mid-sized companies.
Which tools meet the requirements
| Tool | DPA | EU processing | No training | Central administration |
|---|---|---|---|---|
| ChatGPT (private) | No | No | Opt-out needed | No |
| OpenAI/Anthropic API | Yes | Partly, depends on vendor and route | Yes | Via your own integration |
| Langdock | Yes | Partly, EU models selectable | Yes | Yes (SSO, audit logs) |
| Mistral | Yes | Yes (EU vendor) | Yes | Depending on plan |
The pattern is clear: consumer access fails, enterprise plans and API integrations pass on contract, training and administration. The difference lies not in the model but in the contractual and operational model around it. arocom handles the review before rollout and the introduction that follows.
EU processing deserves a second look. Storage and inference are two different things: a vendor can keep your data in the EU and still run the request on a server outside it. This affects several of the entries above and can usually be controlled through model selection. Ask about it explicitly, a blanket "EU hosting" in the marketing copy does not answer the question.
The same principle applies to your own platform: integrating AI via the Anthropic or OpenAI API into your own website means you control data flow, storage, and logging yourself, and can enforce GDPR compliance technically instead of hoping contractually.
Implementation: from ban to governed use
The pragmatic path in four steps:
1. Inventory: Which AI tools are in use, officially and unofficially? 2. Tool decision: One approved tool with DPA, EU processing, and central administration instead of ten tolerated individual solutions. 3. Rules and training: What may be entered, what not? The training also fulfils the AI literacy obligation from Art. 4 AI Act. 4. Documentation: Update the record of processing activities; for sensitive applications, run a data protection impact assessment.
For AI features in your own platform, arocom handles the technical side: AI integration with controlled data flow, EU hosting, and clean logging.
Bring AI into your platform legally?
arocom integrates AI features into Drupal GDPR-compliantly, with EU hosting and controlled data flow. Write to us for a no-obligation conversation.
Is ChatGPT GDPR-compliant?
Not the private version as such. It lacks a DPA and central control, and inputs can be used for training. The business plans and API access offer a DPA, training exclusion, and EU options. What matters is the access route, not the model.
Do we need a DPA for AI tools?
Yes. As soon as the tool processes personal data, Art. 28 GDPR requires a data processing agreement. Without a DPA, use with customer, applicant, or employee data is not permissible.
What changes with the EU AI Act from August 2026?
The AI Act becomes generally applicable. Practically relevant are transparency obligations (chatbots must identify themselves as AI, AI content must be labelled) and enforceable fines. The AI literacy obligation from Art. 4 has applied since February 2025. The GDPR continues to apply unchanged alongside it.
May employees use private AI accounts for work?
Not with personal or confidential data. There is no DPA, no control, and usually no training exclusion. The better route is an approved company tool with clear input rules; otherwise shadow AI emerges.
What is a data protection impact assessment (DPIA)?
A structured risk assessment under Art. 35 GDPR, required when there is likely a high risk for data subjects. For AI use with sensitive data or automated decisions, it is regularly required. The AI Act does not replace it.
Is EU hosting enough for GDPR compliance?
No, it is one of four conditions. Add a DPA, contractual training exclusion, and controlled access. With US vendors, the CLOUD Act also remains a residual risk that must be assessed and documented.
How does AI & Automation hold up on your website? The Future Check shows where the biggest levers are — in 2–4 weeks.
Go deeper
Read next
Copy this prompt and paste it into ChatGPT, Claude, or another AI — you'll get a personal learning plan for „GDPR-compliant AI use: rules and tools“.
You are an experienced coach for AI & Automation. I want to understand the topic "GDPR-compliant AI use: rules and tools...Was this article helpful?