Insight #04

What does GDPR mean in the context of AI?

The General Data Protection Regulation protects personal data. This includes information that can be directly or indirectly assigned to a natural person, for example names, email addresses, phone numbers, customer data, personnel data, or application documents.

As soon as such data is processed, the question arises, among other things, whether there is a legal basis for doing so, how long the data may be stored, who can access it, and what rights the data subjects have.

Of course, this also applies when this data is processed with the help of an AI system. The GDPR is therefore an important part of any AI strategy. But it is not the entire AI strategy.

Not every sensitive piece of information is personal data

Many of a company’s most valuable pieces of information do not fall directly under the GDPR. These include, for example, calculations, price lists, product ideas, manufacturing documents, source code, sales strategies, offers, contract drafts, internal planning, or business figures.

This information can be of enormous importance to a company. Nevertheless, it is not automatically personal data.

This is exactly where a false sense of security often arises. A solution may be set up in a data protection-compliant way and still pose a significant risk to confidential company information.

The decisive question is therefore not only:

Are we allowed to process this data?

But also:

Should we transfer this information to this service at all?

Data protection and data security are not the same thing

Data protection focuses on personal data. Data security concerns all information worthy of protection.

This involves very practical questions:

  • Where is the data processed?
  • Who can access it?
  • Who operates the technical infrastructure?
  • Is content stored?
  • Is it used for other purposes?
  • Can it be used to train a model?
  • What happens in the event of a security incident?
  • Can data be deleted completely?
  • What options does a company have if a provider’s terms change?

These questions are not only relevant for personal data. They apply just as much to trade secrets, technical documents, customer strategies, and internal expertise.

GDPR-compliant does not automatically mean secure

The term “GDPR-compliant” is often used like a general seal of quality. In practice, the statement is only of limited significance without further explanation.

A company should examine more closely what the statement refers to:

  • Is it about the location of the servers?
  • About the contractual arrangements?
  • About the deletion of data?
  • About the use of inputs for training purposes?
  • About access rights within the provider?
  • Or about the legal basis for processing?

A solution can be GDPR-compliant in one specific area and still contain risks elsewhere. That is why it is always worth looking at the entire system.

The server location alone is not enough

Many providers advertise that data is stored in Europe. That can be an important point. But it does not answer all questions.

It is also crucial which company operates the service, which legal system that company is subject to, and who can access the data technically or legally.

In this context, the US CLOUD Act is often mentioned. Under certain conditions, this law can require US companies to disclose data to US authorities. This can also affect data that is not stored in the US.

Whether and to what extent this is relevant in an individual case depends on the specific technical and legal setup.

For companies, this means: the storage location is important. Legal control over the data is at least just as important.

What happens to data in large language models?

When using language models, content is often entered that arises in everyday work. Employees improve texts, summarize documents, review contracts, draft offers, or answer technical questions.

Sensitive information can quickly end up in external systems. Users are not always aware of which data they are currently sharing.

The risk often does not arise from deliberate misconduct. It arises from convenience and a lack of rules.

That is why companies should clearly define which information may and may not be entered into external AI systems. Technical safeguards also play an important role.

A central company solution with regulated access rights is in many cases safer than the uncontrolled use of private accounts by individual employees.

Dependence on providers is also part of the risk assessment

Many powerful AI technologies today come from the US. For companies, this offers great opportunities. At the same time, it creates dependence on providers, platforms, and political conditions over which European companies have only limited influence.

Services can change their prices. Features can be discontinued. Terms of use can be adjusted. Access to certain models can be restricted by region. Political decisions or export rules can also influence the availability of technologies.

Companies should therefore not only ask which solution is currently the most powerful. They should also check how reliably this technology will remain available in the long term.

It becomes particularly critical when core processes depend entirely on a single provider. Then a technical decision quickly becomes a business risk.

Where companies must go beyond the GDPR

Responsible use of AI requires more than a data protection check. It requires clear rules for company data, technical security measures, regulated access rights, a conscious selection of providers, and contracts that clearly regulate what happens to the data.

It also requires a strategy for the event that a service is no longer available, and employees who know which information they may enter into an AI system.

The GDPR remains important. But it is only one part of the overall picture.

Vimmera thought starter

Ask yourself:

  • Do you know which data your employees are already entering into AI systems today?
  • Are there clear rules for this?
  • Do you know where this data is processed?
  • Are you familiar with the legal framework of the providers you use?
  • Is it regulated whether inputs are stored or used for training purposes?
  • Could you switch providers if prices, terms, or availability change?
  • Are confidential company data that do not fall under the GDPR also protected?

If you cannot answer several of these questions clearly, the use of AI in your company should be examined more closely.

Practical question of the week

Would your company be sufficiently protected if tomorrow all personal data were processed in full GDPR compliance?

Or would risks to trade secrets, internal knowledge, and strategically important information still remain?

Takeaway

The GDPR is important. It protects personal data and creates clear rules for its processing. However, when using AI, that alone is not enough.

Companies must also pay attention to data security, confidentiality, technical control, legal access possibilities, and dependence on individual providers.

Not every important piece of information is personal data. But many pieces of information are so valuable to a company that they must be protected with at least the same care.

A good AI strategy therefore does not begin with the question of whether a solution is GDPR-compliant. It begins with the question of which data the company must protect and under what conditions that data may be processed.

Want to take a closer look?

Would you like to know what risks exist when using AI in your company and how data protection, data security, and technological independence can be sensibly combined?

Feel free to write to us at info@vimmera.de. Together, we will look at your current use of AI and develop a path that fits your requirements, your data, and your company.