🇩🇪
KI und Datenschutz: DSGVO-konform arbeiten - Groenewold IT Solutions

AI and data protection: work in compliance with GDPR

AI training • 1 February 2027

As of: 23 September 2026 · Reading time: 4 min

Teilen:

Key takeaways

  • AI and data protection: work with AI in accordance with the GDPR.
  • Practical guide for the data protection-compliant use of AI tools in the company.

AI and data protection: work with AI in accordance with the GDPR. Practical guide for the data protection-compliant use of AI tools in the company.

“The best AI training is not theory-only—it lets participants implement their own use cases immediately.”

– Björn Groenewold, Managing Director, Groenewold IT Solutions

The use of AI tools like ChatGPT raises important data protection issues. What data can be entered? How to ensure GDPR compliance? What risks are there?

This guide gives clear answers and practical recommendations for action for the data protection-compliant use of AI in the company.

The challenge: AI and personal data

AI and data protection: work with AI in accordance with the GDPR.

When planning AI and data protection: work in compliance with GDPR from idea to delivery, Data Analytics & Business Intelligence, Cost Calculator: AI Development sowie Discover solutions offer practical next steps on our site.

AI systems such as ChatGPT process the entered data on servers of providers – often outside the EU.

If personal data are transmitted, the strict rules of the GDPR apply. Companies must ensure that they comply with these rules to avoid fines and damage to reputation.

⚠️ Attention: Frequent data protection cases

  • Input of customer data (names, email addresses, order history)

  • Processing of employee data (personal files, performance assessments)

  • Upload of documents with personal information

  • use of AI for decisions affecting persons

GDPR basics for AI use

The main principles

Principle Meaning for AI

Legality There must be a legal basis for data processing

Switching Data may only be processed for specified purposes

Data minimisation Only process needed data – do not enter unnecessary information

Save limitation Save data no longer than needed

Integrity Ensure appropriate security measures

Practical measures for GDPR conformity

1. Choose the correct AI version

Short: Not all AI tools are the same.

Not all AI tools are the same. For corporate use, you should choose versions that explicitly provide privacy features:

  • ChatGPT Enterprise/Team: Data not used for training, SOC 2 certified

  • Microsoft Copilot (Business): Data stay in Microsoft Cloud, GDPR

  • On-premise solutions: Local AI models that do not send data to the outside

2. Data anonymize before entering

If you need to work with data that may contain personal information, anonymize it before entering:

  • Replace names with placeholders (e.g. "Person A", "Kunde X")

  • Remove email addresses and phone numbers

  • Generalize specific data (e.g. "Great Town in Bavaria" instead of "Munich")

3. Establish clear guidelines

Create binding corporate policies for AI use:

Define which data types may be entered List explicitly prohibited data categories Set approval processes for sensitive applications School all employees on these guidelines Document the use for compliance purposes

4. Check contract processing agreement (AVV)

If personal data is processed, you will need a contract processing contract with the AI provider. Check:

  • Is an AVV present and signed?

  • What standard contract

References and further reading

The following separate references complement the topics in this article:

"Privacy by design is an architecture issue—especially when master data is personal."

— Björn Groenewold, Managing Director, Groenewold IT Solutions

Frequently Asked Questions (FAQ)

What is this article about: “AI and data protection: work in compliance with GDPR”?

Here we cover AI and data protection. Work in compliance with GDPR — focused on architecture, process, and business outcomes.

In short: AI and data protection: work with AI in accordance with the GDPR. Practical guide for the data protection-compliant use of AI tools in the company.

Who benefits most from the content described here?

Typical readers are business and IT leaders in AI training who want to secure quality, security, and ease of upkeep over the long term.

How does this topic fit into an IT or digital strategy?

In a digital strategy, prioritize stable core processes first, then extensions. See also professional software development and consulting.

For multi-system landscapes, IT consulting and architecture helps align vendors and internal teams.

What are sensible next steps if we need support?

If you need support with design, delivery, or modernization: schedule an appointment or outline your project via contact.

About the author

Björn Groenewold
Björn Groenewold(Dipl.-Inf.)

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH

Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2010) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.

Software ArchitectureAI IntegrationLegacy ModernisationProject Management

Blog recommendations

Related articles

These posts might also interest you.

Free download

Checklist: 10 questions before software development

Key points before you start: budget, timeline, and requirements.

Get the checklist in a consultation

Relevant next steps

Related services & solutions

Based on this article's topic, these pages are often the most useful next steps.

More on this topic

Practical next steps after AI and data protection: work in compliance with GDPR

AI and data protection: work in compliance with GDPR addresses a practical choice for product and IT teams. Start with one clear goal: turn a useful AI idea into a governed process with clear data and risk boundaries.

Check the current process, the data involved, and the result users need. Then record the main risks and define a small first step. This keeps the decision easy to review and gives your team a shared basis.

For the EU AI Act timeline, risk classes and GPAI obligations in practice, see our pillar guide EU AI Act for mid-sized companies.

For implementation support, our AI development for business connects the article's guidance with architecture, delivery, and stable operations. Engineering and project ownership stay with our team in Leer, Germany.

This post belongs to AI training. Browse the related AI training articles or use the English software blog for other topics.

When budget is the next question, the software cost calculators provide planning ranges. The IT glossary explains key terms, while in-depth technology guides cover wider decisions.

If the topic affects a live project, book a technical consultation or send the context through our project contact form. We usually reply within one working day.

Next Step

Questions about this topic? We're happy to help.

Our experts are available for in-depth conversations – practical and without obligation.

30 min strategy call – 100% free & non-binding