Insights on GDPR-Compliant AI

Practical perspectives on building secure, compliant AI for firms that handle sensitive data.

AI PolicyGDPRCompliance

AI Acceptable Use Policy: What Every Firm Should Have Documented

Most employees are already using AI at work without approval. No policy means no control, and no control means data ends up where it shouldn't. Here's how to build an AI use policy that actually works.

EU AI ActAI LiteracyArticle 4

AI Literacy Obligation: What the EU AI Act Requires From Your Company

Since February 2, 2025, every company using AI must ensure employees have sufficient AI competency. Article 4 of the EU AI Act applies regardless of company size. Here's what it means in practice.

GDPRChatGPTCopilot

AI Tools GDPR Comparison: ChatGPT, Copilot, Claude, Gemini, Perplexity

Which AI tool is GDPR-compliant? ChatGPT, Copilot, Claude, Gemini, Perplexity, and DeepSeek compared side by side. DPA availability, data residency, training usage. A CISSP practitioner breaks it down.

CopilotOversharingSharePoint

Copilot and Oversharing: When AI Finds Your SharePoint Secrets

Microsoft 365 Copilot searches everything a user has access to in M365. Most companies haven't reviewed their SharePoint permissions in years. Copilot doesn't cause the problem. It reveals it.

Shadow AIGDPRAI Compliance

Your Employees Are Using AI. You Just Don't Know It Yet.

Shadow AI in German companies: 50% of employees use unapproved AI tools at work. What this means for GDPR compliance and how to respond.

EU AI Act2026AI Compliance

What 2026 Means for AI Compliance in Germany: Deadlines, Obligations, Risks

EU AI Act enforcement, Copilot forced migration, GDPR audit focus on AI. The key deadlines for 2026 at a glance.

AnthropicMicrosoftSubprocessor

Anthropic Becomes Microsoft Subprocessor: What to Change in Your DPIA Now

Since January 2026, Anthropic processes data for Microsoft 365. If your DPIA doesn't mention Anthropic, your documentation has a gap.

AI BanShadow AIAI Governance

Banning AI Doesn't Work. Here's What Does.

Why AI bans fail in practice, what Samsung and JPMorgan learned, and the alternative that actually works for regulated firms.

ClaudeAnthropicMicrosoft

Claude, Anthropic, and the Microsoft Contract: What This Means for Your DPIA

Anthropic became a Microsoft 365 Copilot subprocessor in January 2026. If employees also use Claude directly, you have two exposure paths. What your DPIA needs to cover.

CopilotLaw FirmAttorney-Client Privilege

Copilot for Law Firms: Attorney-Client Privilege Meets AI

Why Copilot in law firms isn't just a GDPR issue but touches attorney-client privilege, professional secrecy laws, and information barriers. And what to configure first.

CopilotTax FirmSection 203 German Criminal Code

Copilot in the Tax Firm: Practical Guide to Compliant Use

What Microsoft 365 Copilot can do in a tax advisory firm, where the compliance risks under German criminal law lie, and what needs to happen before rollout.

AI RiskGDPR FinesCompliance Cost

The Real Cost of Doing Nothing About AI

GDPR fines, criminal liability under Section 203 StGB, EU AI Act sanctions. What AI compliance inaction actually costs.

DeepSeekQwenChinese AI

DeepSeek, Qwen, and Chinese AI: Why German Companies Should Stay Away

DeepSeek and Qwen store data in China. No DPA, no adequacy decision, mandatory intelligence cooperation. Why this is a clear no for regulated firms.

DPIACopilotGDPR

DPIA for Microsoft 365 Copilot: What the Document Must Contain

GDPR Article 35 requires a DPIA for Copilot. Microsoft's template is a start, not a finish. Here's what actually needs to be in it.

GeminiGDPRGoogle

Google Gemini for Business: GDPR Traps Almost Nobody Knows About

Using Google Gemini at work? The consumer version stores prompts for 18 months, retains data 72 hours even when storage is 'off,' and has no DPA. A CISSP consultant breaks down the traps.

AI Getting StartedAI AdoptionCompliance

Getting Started With AI: 5 Steps Before You Choose a Tool

Before you roll out Copilot or ChatGPT: these 5 steps get your company into AI usage that's GDPR-compliant from the start.

IT ProviderCopilotCompliance

What Your IT Provider Doesn't Cover With Copilot (And Why That's Normal)

IT providers activate Copilot licenses. The compliance architecture is usually still missing. Why that is nobody's fault and how both sides work together.

PerplexityGDPRData Protection

Perplexity AI: Why the 'Safe Search Engine' Is a Privacy Risk

Perplexity AI looks harmless but poses real GDPR risks. Class action lawsuit, no encryption, no DPA. What regulated firms need to know.

GDPR AI ComplianceSection 203 StGBBerufsgeheimnis

Why Generic AI Tools Fail Firms With Professional Secrecy Obligations

Off-the-shelf AI like ChatGPT and unconfigured Copilot isn't built for firms bound by Section 203 StGB and GDPR. Here's where the defaults break down and what compliant AI actually requires.

ChatGPT GDPRSection 203 StGBTax Advisor AI

Can Tax Advisors in Germany Use ChatGPT With Client Data?

Can German tax firms legally use ChatGPT with client data? What you need to know about GDPR, professional secrecy, and which AI license actually keeps you compliant.

Copilot GDPRMicrosoft 365 CopilotDPIA

5 GDPR Questions Your Firm Must Answer Before Rolling Out Copilot

Microsoft 365 Copilot is powerful. But most firms skip the compliance basics. DPIA, sensitivity labels, Section 203 StGB, SharePoint permissions, and subprocessors — a CISSP breaks down what needs to be in place before activation.

GDPRAI ComplianceClient Data

AI and Client Data: What §203 StGB Means for Your Firm

Client data and AI tools — why Germany's §203 StGB goes beyond GDPR and what tax advisors, lawyers, and firms need to know before using ChatGPT.

GDPRChatGPTAI Compliance

Is ChatGPT GDPR-Compliant? What Businesses Actually Need to Know

ChatGPT and GDPR -- the real answer. Which license do businesses need, when is a DPA required, and where does your data actually go? A CISSP explains.