The short answer: You may use AI — but not with just any data, and not with just any provider. Four core rules: (1) Process personal data as sparingly as possible and never feed it unfiltered into free consumer AI. (2) Sign a data processing agreement (DPA) with the provider and check where processing happens and whether your inputs are used for training. (3) With US providers, put the third-country transfer on a sound legal footing. (4) From 2 August 2026, label AI chatbots and AI content (EU AI Act, Art. 50).
Legal note: This article offers practical orientation, not legal advice. Data protection depends heavily on the individual case — when in doubt, clarify specific situations with your data protection officer or a specialist lawyer.
Two rulebooks that apply together: GDPR and the EU AI Act
As soon as an AI tool processes personal data, the General Data Protection Regulation (GDPR) applies without exception — AI is not a law-free zone. Since 1 August 2024 a second rulebook has joined it: the EU AI Act (Regulation (EU) 2024/1689). For most businesses, its most important part is the transparency obligations in Article 50, which apply from 2 August 2026.
What's at stake is clear from the statutory maximum fines: the GDPR allows fines of up to 20 million euros or 4 % of worldwide annual turnover for serious infringements (whichever is higher, Art. 83). Breaches of the AI Act's transparency duties can be penalized with up to 15 million euros or 3 % of worldwide annual turnover (Art. 99). These are ceilings, not standard penalties — the point isn't panic, it's a clean process.
Which data may go to which AI — and which never unfiltered
The key term is “personal data”: any information relating to an identifiable person (Art. 4 GDPR) — name, email, address, customer number, photos, even a license plate. The principle of data minimization applies (Art. 5): as little personal data as possible. Especially strict are the “special categories” under Art. 9 (including health, trade-union, religious, and biometric data) — these essentially never belong in an external AI.
As a rough guide:
- Usually uncritical: anonymized or aggregated data, general subject-matter questions, your own texts with no personal reference.
- Only with a DPA and a vetted provider: customer data, quotes and support texts containing names, case histories.
- Never unfiltered into free consumer AI: full customer records, health or employee data, credentials and passwords.
Practical tip: remove or pseudonymize the personal reference before you enter it — “the Meier family, 3 Sample Street” becomes “Customer A”. AI tools often don't need the real name to help.
The data processing agreement (DPA) — mandatory, not a nice-to-have
If an AI provider processes personal data on your behalf, it acts as your processor. In that case Art. 28 GDPR requires a data processing agreement (DPA). Reputable providers make a standard DPA available, often self-service in the account.
Before you deploy, check four points: where are the servers (EU or a third country)? Which sub-processors are involved? What deletion periods apply? And — most importantly — are your inputs used to train the model? Free consumer versions often use inputs for training; business, API, and enterprise plans frequently don't. Don't rely on rules of thumb — check your provider's specific contract terms.
Where does the data flow? The third-country transfer (EU vs. US)
Many large AI providers are based in the US. If personal data is sent there, that's a third-country transfer under Art. 44 ff. GDPR — and it needs its own legal basis. In practice, two routes are common: the adequacy decision for the EU-US Data Privacy Framework (in force since 10 July 2023) for appropriately certified US companies — or standard contractual clauses (Art. 46 GDPR).
To be honest about it: the Data Privacy Framework is legally contested and the subject of litigation. On 3 September 2025 the General Court of the EU dismissed a challenge to the adequacy decision — so the decision stands for now; but an appeal to the Court of Justice is possible, and its long-term durability therefore remains an open question. So document which legal basis you rely on. Some providers now offer EU data centers or EU data residency — which considerably defuses the third-country transfer question.
Weiterlesen — kostenlos
Den vollständigen Inhalt freischalten
Trag deine E-Mail-Adresse ein und bestätige sie: Du abonnierst den Signal-Forge-Newsletter von FORGE und erhältst sofort Zugang zu diesem und allen weiteren registrierungspflichtigen Inhalten. Die Abmeldung ist jederzeit möglich.
Schon registriert? Der Link aus deiner Bestätigungs-Mail schaltet dieses Gerät wieder frei.
Sovereign and local AI: keeping data in-house
One effective lever against exactly these data-protection questions is to bring the AI to where the data already lives. Open-weight models can be run yourself — on your own hardware in-house or in an EU cloud. The advantage: the data never leaves the company, there's no third-country transfer, and for the actual processing you often need no external processor at all.
It's not free of trade-offs. You bear hardware and operating costs, need maintenance, and the most capable models are still mostly the big cloud models — the quality gap is shrinking, but it's real. For sensitive data, the effort can nonetheless pay off. (Transparency: FORGE also builds such sovereign solutions — that doesn't change the objective trade-off.)
From 2 August 2026: the labeling duty (EU AI Act, Art. 50)
Article 50 of the EU AI Act introduces transparency duties that affect many businesses directly. Two points matter most in practice: first, users must be able to tell that they are interacting with an AI and not a human — this concerns chatbots and voice AI, unless it's already obvious. Second, AI-generated content (text, image, audio, video) must be marked in a machine-readable way as artificially generated, and “deepfakes” must be disclosed. These duties apply from 2 August 2026; for systems already in use, a transition period runs until 2 December 2026.
The good news: it's cheap to implement. A clear notice at the start of the chat (“You are chatting with an AI assistant”) and a labeling component on published AI content are enough to begin with. Anyone who plans today has plenty of lead time before the deadline.
The quick check: “Am I allowed to do this?”
- Is personal data involved? No → usually uncritical. Yes → continue.
- Can the personal reference be removed or pseudonymized? If yes, do it before entering the data.
- Is there a DPA with the provider? No → don't use it with real customer data.
- Where is the data processed? Third country (e.g. the US) → check the legal basis (Data Privacy Framework or standard contractual clauses).
- Are inputs used for training? If yes → don't enter sensitive or personal data.
- Is it a chatbot or publicly visible AI content? → plan for labeling under Art. 50.
- When in doubt: ask your data protection officer or a lawyer — and document the decision (accountability, Art. 5(2)).
The first step
The most effective start is unspectacular: draw up a short overview of which AI tools are actually used in the business — including the “unofficial” ones individual staff use on their own initiative. For each, note: which data goes in? Which provider? DPA in place? Where are the servers? This list is half the battle — and at the same time a building block of your accountability.
GDPR compliance isn't a one-off state but a process you set up cleanly and maintain. Once the fundamentals are clear, you can use AI with a clear conscience instead of avoiding it out of uncertainty. At FORGE, we build AI solutions to be privacy-friendly from the ground up — up to variants where the data never leaves the building. If you want to tackle the individual steps yourself, you'll find them bundled in our hands-on playbook. And for concrete individual cases the rule still stands: when in doubt, involve your data protection officer or a specialist lawyer.
Sources
- Law General Data Protection Regulation (Regulation (EU) 2016/679) — esp. Art. 4, 5, 9, 28, 44 ff., 46, 83: eur-lex.europa.eu
- Law EU AI Act (Regulation (EU) 2024/1689) — Art. 50 (transparency), Art. 99 (penalties), Art. 113 (date of application 2 Aug 2026): eur-lex.europa.eu
- Decision European Commission — adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795 of 10 July 2023): eur-lex.europa.eu
- Context FORGE Blog — EU AI Act 2026 and the hands-on playbook “Getting AI agents to work”.