As of: 23 September 2026 · Reading time: 4 min
Key takeaways
- AI and data protection: work with AI in accordance with the GDPR.
- Practical guide for the data protection-compliant use of AI tools in the company.
AI and data protection: work with AI in accordance with the GDPR. Practical guide for the data protection-compliant use of AI tools in the company.
“The best AI training is not theory-only—it lets participants implement their own use cases immediately.”
– Björn Groenewold, Managing Director, Groenewold IT Solutions
The use of AI tools like ChatGPT raises important data protection issues. What data can be entered? How to ensure GDPR compliance? What risks are there?
This guide gives clear answers and practical recommendations for action for the data protection-compliant use of AI in the company.
The challenge: AI and personal data
AI and data protection: work with AI in accordance with the GDPR.
When planning AI and data protection: work in compliance with GDPR from idea to delivery, Data Analytics & Business Intelligence, Cost Calculator: AI Development sowie Discover solutions offer practical next steps on our site.
AI systems such as ChatGPT process the entered data on servers of providers – often outside the EU.
If personal data are transmitted, the strict rules of the GDPR apply. Companies must ensure that they comply with these rules to avoid fines and damage to reputation.
⚠️ Attention: Frequent data protection cases
Input of customer data (names, email addresses, order history)
Processing of employee data (personal files, performance assessments)
Upload of documents with personal information
use of AI for decisions affecting persons
GDPR basics for AI use
The main principles
Principle Meaning for AI
Legality There must be a legal basis for data processing
Switching Data may only be processed for specified purposes
Data minimisation Only process needed data – do not enter unnecessary information
Save limitation Save data no longer than needed
Integrity Ensure appropriate security measures
Practical measures for GDPR conformity
1. Choose the correct AI version
Short: Not all AI tools are the same.
Not all AI tools are the same. For corporate use, you should choose versions that explicitly provide privacy features:
✓ Recommended options
ChatGPT Enterprise/Team: Data not used for training, SOC 2 certified
Microsoft Copilot (Business): Data stay in Microsoft Cloud, GDPR
On-premise solutions: Local AI models that do not send data to the outside
2. Data anonymize before entering
If you need to work with data that may contain personal information, anonymize it before entering:
Replace names with placeholders (e.g. "Person A", "Kunde X")
Remove email addresses and phone numbers
Generalize specific data (e.g. "Great Town in Bavaria" instead of "Munich")
3. Establish clear guidelines
Create binding corporate policies for AI use:
Define which data types may be entered List explicitly prohibited data categories Set approval processes for sensitive applications School all employees on these guidelines Document the use for compliance purposes
4. Check contract processing agreement (AVV)
If personal data is processed, you will need a contract processing contract with the AI provider. Check:
Is an AVV present and signed?
What standard contract
References and further reading
The following separate references complement the topics in this article:
- Bitkom – German digital industry association.
- German Federal Office for Information Security (BSI).
- European Commission – Digital strategy.
- MDN Web Docs (Mozilla)
- W3C – World Wide Web Consortium.
"Privacy by design is an architecture issue—especially when master data is personal."
— Björn Groenewold, Managing Director, Groenewold IT Solutions
Frequently Asked Questions (FAQ)
What is this article about: “AI and data protection: work in compliance with GDPR”?
Here we cover AI and data protection. Work in compliance with GDPR — focused on architecture, process, and business outcomes.
In short: AI and data protection: work with AI in accordance with the GDPR. Practical guide for the data protection-compliant use of AI tools in the company.
Who benefits most from the content described here?
Typical readers are business and IT leaders in AI training who want to secure quality, security, and ease of upkeep over the long term.
How does this topic fit into an IT or digital strategy?
In a digital strategy, prioritize stable core processes first, then extensions. See also professional software development and consulting.
For multi-system landscapes, IT consulting and architecture helps align vendors and internal teams.
What are sensible next steps if we need support?
If you need support with design, delivery, or modernization: schedule an appointment or outline your project via contact.
About the author

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2010) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Blog recommendations
Related articles
These posts might also interest you.

AI introduction: How to calculate and show the ROI
The decision for a KI introduction to the company is more than just a technological upgrade – it is a strategic investment in the future. But as with everyone...

AI introduction: your way to the right infrastructure and the optimal technology stack
The transformative force of artificial intelligence (AI) is undeniable and fundamentally changes industries. For companies that do not want to lose the connection, the **KI Introduction U...

AI introduction: Change management and acceptance as key to success
Digital transformation progresses unstoppable and artificial intelligence (AI) develops into a decisive competitive factor for companies of all sizes. The **KI Introduction U...
Free download
Checklist: 10 questions before software development
Key points before you start: budget, timeline, and requirements.
Get the checklist in a consultationRelevant next steps
Related services & solutions
Based on this article's topic, these pages are often the most useful next steps.
Related solutions
Cost calculators
Practical next steps after AI and data protection: work in compliance with GDPR
AI and data protection: work in compliance with GDPR addresses a practical choice for product and IT teams. Start with one clear goal: turn a useful AI idea into a governed process with clear data and risk boundaries.
Check the current process, the data involved, and the result users need. Then record the main risks and define a small first step. This keeps the decision easy to review and gives your team a shared basis.
For the EU AI Act timeline, risk classes and GPAI obligations in practice, see our pillar guide EU AI Act for mid-sized companies.
For implementation support, our AI development for business connects the article's guidance with architecture, delivery, and stable operations. Engineering and project ownership stay with our team in Leer, Germany.
This post belongs to AI training. Browse the related AI training articles or use the English software blog for other topics.
When budget is the next question, the software cost calculators provide planning ranges. The IT glossary explains key terms, while in-depth technology guides cover wider decisions.
If the topic affects a live project, book a technical consultation or send the context through our project contact form. We usually reply within one working day.
