Insight #04

What does GDPR mean in the context of AI?

The General Data Protection Regulation protects personal data. This includes information that can be directly or indirectly attributed to a natural person, such as names, email addresses, telephone numbers, customer data, personnel data or application documents.

As soon as such data are processed, the question arises, among other things, whether there is a legal basis for this, how long the data may be stored, who can access them, and what rights the data subjects have.

This naturally also applies when this data is processed using an AI system. The GDPR is therefore an important component of any AI strategy. However, it is not the entire AI strategy.

Not every sensitive piece of information is personal data

Many of a company’s most valuable pieces of information do not fall directly under the GDPR. These include, for example, calculations, price lists, product ideas, manufacturing documents, source code, sales strategies, offers, contract drafts, internal planning or business figures.

This information can be of enormous importance to a company. Nevertheless, it is not automatically personal data.

This is precisely where a false sense of security often arises. A solution may be set up in compliance with data protection law and still pose a significant risk to confidential company information.

The crucial question is therefore not only:

May we process this data?

But also:

Should we transmit this information to this service at all?

Data protection and data security are not the same thing

Data protection focuses on personal data. Data security concerns all information worthy of protection.

This involves very practical questions:

  • Where is the data processed?
  • Who can access it?
  • Who operates the technical infrastructure?
  • Is content stored?
  • Are they used for other purposes?
  • Can they be used to train a model?
  • What happens in the event of a security incident?
  • Can data be deleted completely?
  • What options does a company have if a provider's terms change?

These questions are not only relevant to personal data. They apply equally to trade secrets, technical documentation, customer strategies, and internal expertise.

GDPR-compliant does not automatically mean secure

The term “GDPR-compliant” is often used like a general seal of quality. In practice, the statement has only limited meaning without further explanation.

A company should examine more closely what the statement refers to:

  • Is it about the location of the servers?
  • The contractual arrangements?
  • About the deletion of data?
  • The use of inputs for training purposes?
  • Access rights within the provider’s organisation?
  • Or about the legal basis for the processing?

A solution can be GDPR-compliant in one area while still containing risks elsewhere. That is why it is always worth taking a look at the entire system.

The server location alone is not enough

Many providers advertise that data is stored in Europe. That can be an important factor. But it does not answer all questions.

It is also crucial which company operates the service, which law that company is subject to, and who can access the data technically or legally.

In this context, the US CLOUD Act is often mentioned. Under certain conditions, this law may oblige US companies to disclose data to US authorities. This may also affect data that is not stored in the USA.

Whether and to what extent this is relevant in individual cases depends on the specific technical and legal design.

For companies, this means: The storage location is important. Legal control over the data is at least as important.

What happens to data in large language models?

When using language models, content that arises in everyday work is often entered. Employees have texts improved, documents summarized, contracts reviewed, proposals drafted, or technical questions answered.

Sensitive information can quickly end up in external systems. Users are not always aware of which data they are sharing.

The risk often arises not from intentional misconduct. It arises from convenience and a lack of rules.

Companies should therefore clearly define which information may be entered into external AI systems and which may not. Technical safeguards also play an important role.

A centralized enterprise solution with regulated access rights is in many cases more secure than the uncontrolled use of private accounts by individual employees.

Dependence on providers is also a risk to consider.

Many high-performance AI technologies today come from the USA. This offers great opportunities for companies. At the same time, it creates a dependency on providers, platforms and political frameworks over which European companies have only limited influence.

Services may change their prices. Features may be discontinued. Terms of use may be adjusted. Access to certain models may be restricted regionally. Political decisions or export regulations can also affect the availability of technologies.

Companies should therefore not only ask themselves which solution is the most powerful today. They should also examine how reliably this technology will remain available in the long term.

It becomes particularly critical when core processes depend entirely on a single provider. A technical decision can then quickly become a business risk.

Where companies need to go beyond the GDPR

Responsible AI use requires more than a data protection review. It requires clear rules for company data, technical security measures, regulated access rights, careful selection of providers, and contracts that clearly govern what happens to the data.

It also needs a strategy for the event that a service is no longer available, and employees who know what information they are allowed to enter into an AI system.

The GDPR remains important in this context. However, it is only one part of the overall picture.

Vimmera Thought Starter

Ask yourself:

  • Do you know what data your employees are already entering into AI systems today?
  • Are there clear rules for this?
  • Do you know where this data is processed?
  • Do you know the legal framework governing the providers you use?
  • Is it regulated whether inputs are stored or used for training purposes?
  • Could you switch providers if prices, terms or availability change?
  • Are confidential company data that do not fall under the GDPR also protected?

If you cannot clearly answer several of these questions, the use of AI in your company should be examined more closely.

Practical question of the week

Would your company be sufficiently protected if all personal data were processed in full compliance with the GDPR tomorrow?

Or would risks to trade secrets, internal knowledge, and strategically important information still remain?

Key takeaways

The GDPR is important. It protects personal data and establishes clear rules for its processing. However, this alone is not sufficient when using AI.

Companies must pay equal attention to data security, confidentiality, technical control, legal access options, and dependence on individual providers.

Not every important piece of information is personal data. But many types of information are so valuable to a company that they must be protected at least as carefully.

A good AI strategy therefore does not begin with the question of whether a solution is GDPR-compliant. It begins with the question of which data the company must protect and under what conditions this data may be processed.

Ready to take a closer look?

Would you like to know what risks exist when using AI in your company and how data protection, data security and technological independence can be meaningfully combined?

Feel free to write to us at info@vimmera.de. Together, we will look at your existing use of AI and develop an approach that fits your requirements, your data, and your company.