Processing personal data with AI is not forbidden. The GDPR contains no AI ban, it sets conditions. Meet the conditions and you may summarize customer records, draft emails that name people, and analyze documents full of personal data. Fail to meet them and you are processing unlawfully, with every single prompt.
The problem in practice: most companies start with the tool and ask the legal questions afterwards. By then Copilot or ChatGPT has been running for months, and nobody can say on what basis. The better order is the reverse. Five questions, answered before the first prompt containing personal data goes out, save you the uncomfortable cleanup later.
Does personal data end up in the tool at all?
Personal data is any information relating to an identified or identifiable person (Art. 4(1) GDPR). That is broader than many people think. Not just name and address, but also an email address, a customer number, an employee’s salary, a complaint from a customer mentioned by name.
For AI tools this means: the moment a prompt contains a customer name, an email signature, or a personnel file, you are processing personal data. Uploading a spreadsheet of customer contacts is processing. So is the request “draft a rejection letter to Mr. Miller about his overdue payment.”
Two honest notes on where the line runs:
Anonymization works, but it is harder than it looks. Data is only truly anonymous when nobody can identify the person with reasonable effort. “A client from Regensburg, 52, master baker, three locations” is not anonymous. If you consistently strip prompts of any link to a person, you leave the GDPR’s scope entirely. For many use cases that is the simplest path, but it only works if it is enforced without exceptions.
Pseudonymization is not enough. If you write “Client A” but can internally map who Client A is, the data remains personal data. All obligations continue to apply; pseudonymization is merely a safeguard.
If the answer to question 1 is “no, never,” backed by a clear rule, you can stop here. In every other case, keep reading.
What is your legal basis?
Every processing of personal data needs a legal basis under Art. 6 GDPR. Processing in an AI tool is not a category of its own; it needs the same justification as any other processing. In practice, two bases do most of the work:
Legitimate interest (Art. 6(1)(f)). The most common basis for everyday office AI use. You record which interest you pursue (more efficient handling), why the processing is necessary for it, and why the interests of the people affected do not override yours. That balancing test must be documented. It gets easier the better the tool is configured: EU data location, no training on your inputs, short retention periods.
Contract performance (Art. 6(1)(b)). Holds when the AI use serves the performance of a contract with the person concerned, for example drafting the reply to a customer inquiry.
I usually advise against consent as the basis for internal AI use. It can be withdrawn at any time, it is shaky for employee data because of the power imbalance, and it creates administrative overhead that legitimate interest does not.
Two special cases raise the bar: special categories under Art. 9 GDPR (health data, religious affiliation, union membership) need an additional exemption that rarely applies in office settings. And anyone bound by professional secrecy must respect not only the GDPR but also Section 203 of the German Criminal Code, which has its own, stricter rules.
Is the contract with the provider in place?
The AI provider processes the data on your behalf. For that, Art. 28 GDPR requires a data processing agreement (DPA). No DPA, no transfer of personal data to the tool; the rule really is that simple.
With the business contracts of the major providers (Microsoft 365 Copilot, ChatGPT Team and Enterprise, Claude for Work), the DPA is part of the contract package. Free consumer accounts come with no DPA, and inputs there are often used to train the models. That is why the account question is not a formality: an employee pasting customer data into their private ChatGPT account is processing without any contractual basis.
Check three points in the DPA and its accompanying documents: Is training on your inputs excluded? Which subprocessors are listed? And how long does the provider retain inputs and outputs?
Does the data leave the EU?
As soon as personal data is transferred to a third country, you need, on top of everything above, a basis under Chapter V of the GDPR, such as the adequacy decision for the US (Data Privacy Framework) or standard contractual clauses.
With cloud AI this question is less trivial than it sounds. An EU data center alone does not answer it, because the contracting entity, telemetry, and support access can still sit outside the EU. I took the three layers (location, contracting party, access) apart in my post on data residency for cloud AI. For this checklist, what matters is: you must be able to document where processing happens and what any third-country transfer rests on.
Do you need a DPIA, and are the internal rules in place?
A data protection impact assessment (DPIA) under Art. 35 GDPR is mandatory when the processing is likely to result in a high risk for the people affected. With AI processing personal data, that is often the case, especially where novel technology meets large data sets, which is exactly what Copilot with access to the entire company mailbox looks like. When the obligation applies and what the seven steps look like is covered in my post on DPIAs for AI tools.
Two things belong here that no DPIA can replace:
The record of processing activities (Art. 30 GDPR). The AI processing belongs in it, either as its own entry or as an addition to existing entries: purpose, data categories, recipients, deletion periods.
A rule for your team. The best legal construction is worthless if staff do not know which data may go into which tool. A one-page AI acceptable use policy with an approved-tools list and clear no-go zones closes that gap.
The 5 questions in short form
- Personal data: Do prompts or uploaded files contain data about identifiable people? If no (and enforced): the GDPR question is settled.
- Legal basis: Usually legitimate interest with a documented balancing test. Check Art. 9 data and professional secrecy separately.
- DPA: Business contract with a data processing agreement, training use excluded. Private accounts are off limits.
- Data location: Document where processing happens and what any third-country transfer rests on.
- DPIA and internal rules: Check whether a DPIA is required, update the record of processing activities, hand the team a usage policy.
This is not done in a single workday, but it is done in two weeks alongside normal business. And it is far cheaper than the cleanup after a complaint or an inquiry from the supervisory authority.
The next step
If you want to know which of the five questions your company has already answered and which are still open, take my free AI compliance check. It takes 2 minutes and shows you where you stand.
Jose Lugo is a CISSP-certified AI compliance consultant. He advises law firms, tax advisors, and financial services providers in Germany on GDPR-compliant AI adoption.