Back to blog
AI in OperationsDecisionsSMEsDigitalisation

AI and GDPR: Using Company Data Safely with AI

NDVDL Team9 min read
Secured server environment in which AI applications are run with company data

Using company data safely with AI is mainly about deciding which data may go where. Non-critical text can go through business plans from cloud providers with a data processing agreement. Personal or confidential data is better served by a model hosted in the EU or run on your own premises. Customer data, personnel files and trade secrets never belong in freely available public chatbots. This article offers technical orientation, not legal advice.

Why is AI a data protection issue for every SME?

AI is a data protection issue because employees often already use AI services without the business knowing. A customer complaint is copied into a chatbot to be reworded, a contract is uploaded for a summary, a job application is pasted in for an assessment. In each case, personal or confidential data leaves the company without purpose, recipient and contract having been clarified.

The GDPR does not prohibit AI. It does, however, require that for every processing of personal data it is clear why it happens, on what legal basis, who receives the data and how it is protected. AI services add questions that are less common with traditional software: Is input used for training? Where is the computing done? How long are requests stored?

Which data does not belong in public chatbots?

Freely available public chatbots should not receive any data you would not also write in an email to a stranger. Free and consumer versions usually lack a data processing agreement, and their terms of use often allow further use of the input.

  • Customer data with names, addresses, contact or contract details
  • Personnel records, job applications, health or sick-leave data
  • Quotes, cost calculations, price lists and draft contracts relating to customers
  • Design data, recipes, source code and other trade secrets
  • Credentials, network diagrams, configurations and security information

A ban on its own does little if employees find AI genuinely useful for their work. More effective is an approved alternative with a clear rule: for this data, use this service; for everything else, ask first. Otherwise copying continues in secret, just without anyone knowing about it.

Cloud AI, EU hosting or on-premise: which option fits?

There are essentially three ways to run AI, differing in where data is processed, how capable the model is and how much support is required. The right choice depends on how sensitive the data of each use case is – not on which option is currently being discussed the most.

Cloud AI from large providers

Cloud AI from large providers offers very capable models and can be used immediately without your own hardware. For business use, only business or API plans with a data processing agreement and a contractual exclusion of training on your input are suitable. Depending on the provider and plan, data may be processed outside the EU, which requires additional checks. This option suits general text, research and content without personal data.

AI models hosted in the EU

With EU hosting, the model runs in a data centre within the EU, either as a cloud provider's service with a fixed region or as an openly available model on rented infrastructure. This simplifies the question of transfers to third countries and offers a good middle ground between capability and control. Contract, access rights and logging still need to be properly arranged.

AI on your own premises (on-premise)

With on-premise AI, an openly available model runs on a server in your own server room or data centre, and requests do not leave your network. This makes sense when sensitive customer, personnel or production data is processed regularly. Locally run models are usually smaller than the largest cloud models, but they are often sufficient for clearly defined tasks such as document search or receipt processing. The server must be secured, updated and monitored like any other system.

What running AI on your own premises means technically and when the effort pays off is explained in our glossary.

On-premise AI explained

What should a data processing agreement with an AI provider cover?

A data processing agreement with an AI provider ensures that the provider processes personal data only on behalf of and as instructed by the business. With AI services, a few points deserve a closer look that matter less with traditional software. The following list is a technical checklist for discussions with the provider and your data protection officer, not a legal review.

  • Are inputs and outputs used to train or improve the models, and can this be excluded by contract?
  • In which regions and data centres are requests processed, and which sub-processors are involved?
  • How long are requests and logs stored, and how are they deleted?
  • Who at the provider has access to content and in which cases, for example for abuse monitoring?
  • Which technical and organisational measures protect the data, and how are incidents reported?

If there is no such agreement, or if use of the input for training cannot be excluded, the service is not suitable for personal or confidential business data, however well it performs technically.

What does the EU AI Act mean for AI use in an SME?

The EU AI Act is an EU regulation that classifies AI systems by risk and attaches obligations accordingly. Some applications are prohibited; strict requirements apply to high-risk applications – such as certain systems that decide on people's employment or access to services – and many others mainly carry transparency obligations. Businesses using AI should also ensure that the employees working with it are sufficiently informed about its possibilities and risks.

For typical SME applications such as drafting text, document search or receipt processing, this means in practice: knowing which AI systems are in use, training employees, labelling AI-generated content towards customers where required, and being careful as soon as AI prepares decisions about people, for example in recruitment. The specific legal classification of a use case is a matter for legal advice or your data protection officer.

How do you go about using company data safely with AI?

  1. 01Take stock: which AI services are already used in the business, officially or unofficially, and with which data?
  2. 02Classify data: distinguish between public, internal, confidential and personal data, and define which operating option is permitted for each level.
  3. 03Select services and secure them by contract: business plans with a data processing agreement, EU hosting or on-premise operation, depending on the data level.
  4. 04Carry over access rights: an AI may only see what the employee asking could see without AI.
  5. 05Set up logging: make it traceable who uses which service for what, without storing content longer than necessary.
  6. 06Write usage rules and train staff: one page, clearly worded, with examples from your own business.
  7. 07Involve data protection: update the records of processing activities and consult the data protection officer or legal advisers on new use cases.

Why are access rights so important with AI?

Access rights are important with AI because a knowledge search across all of a company's files would otherwise make accessible things that were previously just well hidden. If an employee asks what a colleague earns and the payroll list sits somewhere in a poorly permissioned folder, an AI will find it. The permissions of the file storage must therefore be checked before connecting it and enforced within the AI application. How to choose the first use case and set up a pilot is covered in our article on introducing AI in your business.

How does NDVDL support the secure use of AI?

NDVDL starts with a review at your premises: we look at which AI services are already in use, which data is involved and what file storage and permissions look like today. You then receive a written proposal stating which option fits which use case: a cloud plan with a contract, hosting in the EU or running the model on your own premises.

We implement the chosen solution, take care of servers, network and security for on-premise operation, set up permissions and logging, and then run and maintain the system. You have one fixed contact person for all of this. Legal assessment stays with your data protection officer or legal advisers; we provide the technical information they need for it.

Tell us which AI services are already used in your business, officially or on the side. We will classify them technically with you and show you which operating option suits your data.

Review your AI use

Frequently asked questions

No, you should not enter customer data into the freely available consumer versions of public chatbots such as ChatGPT, because there is usually no data processing agreement and you have no control over how the input is used. Business plans with a contract and data-use settings are a different situation, but they still need to be recorded in your records of processing activities and checked from a data protection perspective.

No. With on-premise AI the data does not leave your network, but purpose, legal basis, access rights, retention periods and server security must be governed just as for any other system. Running AI in-house simplifies the question of where data flows, but it does not replace the other obligations.

With cloud AI from large providers, requests are often processed in data centres and by companies outside the EU, depending on the plan you choose. With EU hosting, the model runs in a data centre within the EU, which simplifies the question of transfers to third countries but still has to be properly covered by contract.

The EU AI Act classifies AI systems by risk and attaches different obligations to each level. For most typical SME applications such as drafting text or searching documents, the focus is on transparency and informed, trained use; stricter requirements apply to high-risk areas, such as certain decisions about people. Classifying a specific use case requires legal advice.

A business should at least define which AI services are approved, which types of data may and may not be entered there, that results are checked before further use, and whom to contact when in doubt. These rules should be short, written down and known to all employees.

Questions about your IT infrastructure?

Talk directly to our team — no obligation, no detours.