Using AI in a GDPR-Compliant Way: A Practical Guide for SMEs

AI tools have arrived in everyday operations — support drafts replies with ChatGPT, the office summarizes quotes, the website chatbot answers around the clock. But the moment personal data is involved, the GDPR applies in full — and from 2 August 2026, so do the transparency duties of the EU AI Act. This guide shows which data may go to which AI, what to check in your contract with the provider, and how a short checklist keeps you on the safe side.

The short answer: You may use AI — but not with just any data, and not with just any provider. Four core rules: (1) Process personal data as sparingly as possible and never feed it unfiltered into free consumer AI. (2) Sign a data processing agreement (DPA) with the provider and check where processing happens and whether your inputs are used for training. (3) With US providers, put the third-country transfer on a sound legal footing. (4) From 2 August 2026, label AI chatbots and AI content (EU AI Act, Art. 50).

Legal note: This article offers practical orientation, not legal advice. Data protection depends heavily on the individual case — when in doubt, clarify specific situations with your data protection officer or a specialist lawyer.

Two rulebooks that apply together: GDPR and the EU AI Act

As soon as an AI tool processes personal data, the General Data Protection Regulation (GDPR) applies without exception — AI is not a law-free zone. Since 1 August 2024 a second rulebook has joined it: the EU AI Act (Regulation (EU) 2024/1689). For most businesses, its most important part is the transparency obligations in Article 50, which apply from 2 August 2026.

What's at stake is clear from the statutory maximum fines: the GDPR allows fines of up to 20 million euros or 4 % of worldwide annual turnover for serious infringements (whichever is higher, Art. 83). Breaches of the AI Act's transparency duties can be penalized with up to 15 million euros or 3 % of worldwide annual turnover (Art. 99). These are ceilings, not standard penalties — the point isn't panic, it's a clean process.

Which data may go to which AI — and which never unfiltered

The key term is “personal data”: any information relating to an identifiable person (Art. 4 GDPR) — name, email, address, customer number, photos, even a license plate. The principle of data minimization applies (Art. 5): as little personal data as possible. Especially strict are the “special categories” under Art. 9 (including health, trade-union, religious, and biometric data) — these essentially never belong in an external AI.

As a rough guide:

  • Usually uncritical: anonymized or aggregated data, general subject-matter questions, your own texts with no personal reference.
  • Only with a DPA and a vetted provider: customer data, quotes and support texts containing names, case histories.
  • Never unfiltered into free consumer AI: full customer records, health or employee data, credentials and passwords.

Practical tip: remove or pseudonymize the personal reference before you enter it — “the Meier family, 3 Sample Street” becomes “Customer A”. AI tools often don't need the real name to help.

The data processing agreement (DPA) — mandatory, not a nice-to-have

If an AI provider processes personal data on your behalf, it acts as your processor. In that case Art. 28 GDPR requires a data processing agreement (DPA). Reputable providers make a standard DPA available, often self-service in the account.

Before you deploy, check four points: where are the servers (EU or a third country)? Which sub-processors are involved? What deletion periods apply? And — most importantly — are your inputs used to train the model? Free consumer versions often use inputs for training; business, API, and enterprise plans frequently don't. Don't rely on rules of thumb — check your provider's specific contract terms.

Where does the data flow? The third-country transfer (EU vs. US)

Many large AI providers are based in the US. If personal data is sent there, that's a third-country transfer under Art. 44 ff. GDPR — and it needs its own legal basis. In practice, two routes are common: the adequacy decision for the EU-US Data Privacy Framework (in force since 10 July 2023) for appropriately certified US companies — or standard contractual clauses (Art. 46 GDPR).

To be honest about it: the Data Privacy Framework is legally contested and the subject of litigation. On 3 September 2025 the General Court of the EU dismissed a challenge to the adequacy decision — so the decision stands for now; but an appeal to the Court of Justice is possible, and its long-term durability therefore remains an open question. So document which legal basis you rely on. Some providers now offer EU data centers or EU data residency — which considerably defuses the third-country transfer question.

Weiterlesen — kostenlos

Den vollständigen Inhalt freischalten

Trag deine E-Mail-Adresse ein und bestätige sie: Du abonnierst den Signal-Forge-Newsletter von FORGE und erhältst sofort Zugang zu diesem und allen weiteren registrierungspflichtigen Inhalten. Die Abmeldung ist jederzeit möglich.

Schon registriert? Der Link aus deiner Bestätigungs-Mail schaltet dieses Gerät wieder frei.

Sovereign and local AI: keeping data in-house

One effective lever against exactly these data-protection questions is to bring the AI to where the data already lives. Open-weight models can be run yourself — on your own hardware in-house or in an EU cloud. The advantage: the data never leaves the company, there's no third-country transfer, and for the actual processing you often need no external processor at all.

It's not free of trade-offs. You bear hardware and operating costs, need maintenance, and the most capable models are still mostly the big cloud models — the quality gap is shrinking, but it's real. For sensitive data, the effort can nonetheless pay off. (Transparency: FORGE also builds such sovereign solutions — that doesn't change the objective trade-off.)

From 2 August 2026: the labeling duty (EU AI Act, Art. 50)

Article 50 of the EU AI Act introduces transparency duties that affect many businesses directly. Two points matter most in practice: first, users must be able to tell that they are interacting with an AI and not a human — this concerns chatbots and voice AI, unless it's already obvious. Second, AI-generated content (text, image, audio, video) must be marked in a machine-readable way as artificially generated, and “deepfakes” must be disclosed. These duties apply from 2 August 2026; for systems already in use, a transition period runs until 2 December 2026.

The good news: it's cheap to implement. A clear notice at the start of the chat (“You are chatting with an AI assistant”) and a labeling component on published AI content are enough to begin with. Anyone who plans today has plenty of lead time before the deadline.

The quick check: “Am I allowed to do this?”

  1. Is personal data involved? No → usually uncritical. Yes → continue.
  2. Can the personal reference be removed or pseudonymized? If yes, do it before entering the data.
  3. Is there a DPA with the provider? No → don't use it with real customer data.
  4. Where is the data processed? Third country (e.g. the US) → check the legal basis (Data Privacy Framework or standard contractual clauses).
  5. Are inputs used for training? If yes → don't enter sensitive or personal data.
  6. Is it a chatbot or publicly visible AI content? → plan for labeling under Art. 50.
  7. When in doubt: ask your data protection officer or a lawyer — and document the decision (accountability, Art. 5(2)).

The first step

The most effective start is unspectacular: draw up a short overview of which AI tools are actually used in the business — including the “unofficial” ones individual staff use on their own initiative. For each, note: which data goes in? Which provider? DPA in place? Where are the servers? This list is half the battle — and at the same time a building block of your accountability.

GDPR compliance isn't a one-off state but a process you set up cleanly and maintain. Once the fundamentals are clear, you can use AI with a clear conscience instead of avoiding it out of uncertainty. At FORGE, we build AI solutions to be privacy-friendly from the ground up — up to variants where the data never leaves the building. If you want to tackle the individual steps yourself, you'll find them bundled in our hands-on playbook. And for concrete individual cases the rule still stands: when in doubt, involve your data protection officer or a specialist lawyer.

Sources

  1. Law General Data Protection Regulation (Regulation (EU) 2016/679) — esp. Art. 4, 5, 9, 28, 44 ff., 46, 83: eur-lex.europa.eu
  2. Law EU AI Act (Regulation (EU) 2024/1689) — Art. 50 (transparency), Art. 99 (penalties), Art. 113 (date of application 2 Aug 2026): eur-lex.europa.eu
  3. Decision European Commission — adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795 of 10 July 2023): eur-lex.europa.eu
  4. Context FORGE Blog — EU AI Act 2026 and the hands-on playbook “Getting AI agents to work”.

Signal Forge · Free playbook

Get the free hands-on playbook.

Put AI agents to work. Plus monthly hands-on AI insights via Signal Forge.

Double opt-in · no spam · cancel anytime · The playbook arrives straight to your inbox

Next step

Deploy AI in a GDPR-Safe Way

FORGE builds AI solutions that are privacy-friendly from the ground up — including sovereign variants where the data never leaves the building. DPA, third-country transfer safeguards, and EU AI Act labeling built in from day one.

Get in touch →