GDPR and data
Personal data inside AI tools, legal basis, impact assessments and processing agreements.
The GDPR does not forbid using AI. It does require that you be able to say where the data came from, why you process it and what happens to it along the way — three questions a new tool usually cannot answer yet at the moment of purchase.
Most trouble does not arrive at rollout but three months later: someone pastes a file into a tool that is not on the register, the vendor swaps a sub-processor, and the integration starts sending more than was agreed.
A common argument
„We anonymised the data, so the GDPR does not apply to us.”
How it actually is
Anonymisation ends the matter only when it is irreversible — including after combining it with what the other side already holds. What companies usually call anonymisation is pseudonymisation, and that does not take the data outside the GDPR.
Questions I hear most often
- ? On what legal basis do we put customer data into this tool?
- ? Do we need an impact assessment, or is a risk analysis enough?
- ? Can the vendor train its model on our data?
- ? What do we do when the vendor changes a sub-processor without asking?