A woman with binary code lights projected on her face, symbolizing technology. — DSGVO-konforme KI-Nutzung: Regeln und Tools

GDPR-Compliant AI Use in Your Company

In most companies, people already work with AI. The only question is whether officially or as shadow AI on private accounts. That is exactly where the data protection problem starts: anyone pasting customer data into a consumer chatbot is processing personal data without a legal basis, without a contract, and often with training enabled.

The solution is not a ban but orderly adoption. This article covers the four core questions, the EU AI Act timeline, and which tools meet the requirements. It does not replace legal advice, but it gives you the structure for the conversation with your data protection officer.

The Four Core Questions Before Any AI Rollout

1. Is there a data processing agreement (DPA)? As soon as an AI service processes personal data, Art. 28 GDPR requires a DPA. Consumer offerings don't provide one; business plans and API access from the major vendors do.

2. Where is the data processed? EU hosting is the simplest route. Anthropic and OpenAI offer EU processing via Frankfurt and Azure EU respectively, and Mistral, as an EU company, hosts in Europe anyway. With US vendors, the US CLOUD Act remains a residual risk you need to assess and document.

3. Are inputs used for model training? The knockout criterion. With consumer services, training is often on by default; with business and API access, it is contractually excluded. Verify this in writing, not through marketing claims.

4. Who controls access and usage? SSO, permission management, and audit logs make AI use traceable. Without central administration, shadow AI emerges, and the GDPR's accountability obligations come to nothing.

EU AI Act: What Comes on Top from August 2026

The GDPR stays, the AI Act comes on top. Both apply side by side. The timeline in short:

  • Since February 2025: Prohibited AI practices are banned, and Art. 4 requires AI literacy: anyone using AI tools must be trained, verifiably. This includes marketing, HR, and sales.
  • Since August 2025: Obligations for providers of general-purpose AI models (GPAI).
  • From 2 August 2026: The AI Act becomes generally applicable. Practically relevant are the transparency obligations: chatbots must identify themselves as AI, and AI-generated content must be machine-readably labeled. Fines become enforceable, up to 35 million euros or 7 percent of global revenue.
  • High-risk obligations: The EU is expected to postpone them to late 2027 (Digital Omnibus, not yet finally adopted at the time of writing). The transparency obligations from August 2026 are unaffected.

Important in practice: as a company using AI, you cannot fully delegate compliance to the tool vendor. Responsibility for the area of use, training, and transparency toward customers stays with you. Our post on the EU AI Act provides an assessment for mid-sized companies.

Which Tools Meet the Requirements

ToolDPAEU processingNo trainingCentral administration
ChatGPT (private)NoNoOpt-out neededNo
OpenAI/Anthropic APIYesYes, configurableYesVia your own integration
LangdockYesYes (Frankfurt)YesYes (SSO, audit logs)
MistralYesYes (EU vendor)YesDepending on plan
Microsoft 365 CopilotYesEU Data Boundary, check routingYesYes (tenant)

The pattern is clear: consumer access fails, enterprise plans and API integrations pass. The difference lies not in the model but in the contractual and operational model around it.

The same principle applies to your own platform: integrating AI via the Anthropic or OpenAI API into your own website means you control data flow, storage, and logging yourself, and can enforce GDPR compliance technically instead of hoping contractually.

Implementation: From Ban to Governed Use

The pragmatic path in four steps:

1. Inventory: Which AI tools are in use, officially and unofficially? 2. Tool decision: One approved tool with DPA, EU processing, and central administration instead of ten tolerated individual solutions. 3. Rules and training: What may be entered, what not? The training also fulfills the AI literacy obligation from Art. 4 AI Act. 4. Documentation: Update the record of processing activities; for sensitive applications, run a data protection impact assessment.

For AI features in your own platform, arocom handles the technical side: AI integration with controlled data flow, EU hosting, and clean logging.

Bring AI into your platform legally?

arocom integrates AI features into Drupal GDPR-compliantly, with EU hosting and controlled data flow. Write to us for a no-obligation conversation.

Which platform, which model, which legal framework: questions we regularly work through on client engagements. For strategic sparring at executive level there is arocon, the consulting brand from the arocom family.

Is ChatGPT GDPR-compliant?

Not the private version as such. It lacks a DPA and central control, and inputs can be used for training. ChatGPT Enterprise and API access offer a DPA, training exclusion, and EU options. What matters is the access route, not the model.

Do we need a DPA for AI tools?

Yes. As soon as the tool processes personal data, Art. 28 GDPR requires a data processing agreement. Without a DPA, use with customer, applicant, or employee data is not permissible.

What changes with the EU AI Act from August 2026?

The AI Act becomes generally applicable. Practically relevant are transparency obligations (chatbots must identify themselves as AI, AI content must be labeled) and enforceable fines. The AI literacy obligation from Art. 4 has applied since February 2025. The GDPR continues to apply unchanged alongside it.

May employees use private AI accounts for work?

Not with personal or confidential data. There is no DPA, no control, and usually no training exclusion. The better route is an approved company tool with clear input rules; otherwise shadow AI emerges.

What is a data protection impact assessment (DPIA)?

A structured risk assessment under Art. 35 GDPR, required when there is likely a high risk for data subjects. For AI use with sensitive data or automated decisions, it is regularly required. The AI Act does not replace it.

Is EU hosting enough for GDPR compliance?

No, it is one of four conditions. Add a DPA, contractual training exclusion, and controlled access. With US vendors, the CLOUD Act also remains a residual risk that must be assessed and documented.

How does AI & Automation hold up on your website? The Future Check shows where the biggest levers are — in 2–4 weeks.

Request Future Check Or get in touch

Go deeper

Explore this topic with AI

Copy this prompt and paste it into ChatGPT, Claude, or another AI — you'll get a personal learning plan for „GDPR-Compliant AI Use: Rules and Tools“.

You are an experienced coach for AI & Automation. I want to understand the topic "GDPR-Compliant AI Use: Rules and Tools...
Free · PDF document

CMS Comparison 2026

Drupal vs. WordPress vs. TYPO3: an objective comparison for enterprise projects.

Was this article helpful?

100 %