Recording: personal data inside AI tools
A webinar recording on legal basis, impact assessment and when anonymisation really ends the matter. Downloadable materials included.
Piotr Kaniewski · 22 April 2026 · 61 min read
This is placeholder text — the structure and length match the intended material, but the content has not been written or reviewed by Piotr. Do not quote it.
The question that comes up most often here is "are we allowed to". That is the wrong question — or rather, a question asked two steps too late. Before we get to whether you are allowed, we have to settle what the thing actually is and who, in this configuration, answers for it.
In practice three things decide it: what the data flow looks like, who makes the decision at the end of that flow, and what happens when the decision turns out to be wrong. Everything else follows from those three, rather than being a separate topic to analyse.
Where to start
Start by writing down what you already have, not what you ought to have. Most organisations have more than they think — policies, internal rules, clauses in vendor contracts — but nobody has put them side by side and checked whether they say the same thing.
Only against that background can you see the gaps that genuinely need closing. Skip the step and you produce one more policy that contradicts the previous two, and it is the contradiction that becomes the problem once somebody asks.
Where this usually breaks
It breaks at the seam: where the document describes one process and the team works to another. A clause nobody follows is worse than no clause — an absence can be explained, whereas an unfollowed clause proves you knew and did nothing about it.
So every conclusion here is phrased as a question to ask inside your own organisation rather than a clause to paste. A clause without a process behind it is decoration.
The rest is in the subscription
Full access to the materials, training recordings and model clauses. Updates land automatically, at no extra cost.
- every article and explainer
- downloadable checklists and model clauses
- training and webinar recordings
- new materials every month
Already have access? Sign in
Related materials
The AI Act in a small company: what applies to you and what does not
Most companies are not high-risk system providers and do not need a risk management system. How to check which side of that line you are on.
Checklist: rolling out an AI tool in a team
Twenty questions to answer before signing with a vendor — from the legal basis to how you get out of the tool.
Human oversight is not the definition of an AI system
The argument "we can control it, so it is not AI" keeps coming back and keeps leading nowhere. An obligation towards a system is not a criterion for what the system is.