The essentials

Check the actual workflow: why may these data be processed, what role does the provider have, where are they processed and when are they deleted? A contract or an EU server cannot answer all four questions.

The workflow matters more than the sales claim

An AI tool does not receive blanket approval for customer data. To use AI in line with GDPR, start by describing one task and the information it needs. Drafting from public product details differs from analysing a customer file. For personal data, the GDPR requires, among other things, a defined purpose, a lawful basis and a restriction to necessary information.

Our recommendation for a small business is to start with one bounded drafting task and synthetic sample data. Collect the evidence needed for real data in parallel. Four checks help: lawful basis, provider roles, processing locations and deletion. They are a starting point for assessment, not comprehensive legal advice. Health data, employee assessments and automated decisions about people are outside this simple starting workflow.

Question 1: Why may these details go into the AI tool?

The purpose comes before the prompt. Write a sentence such as: “We want to draft a reply to a delivery enquiry; we need the product, quantity and requested date.” Then ask whether a name, telephone number and previous orders belong in that draft at all. Placeholders that a person later replaces in the business system will often be enough for the initial wording.

The lawful basis must fit the specific processing. A contract with an AI provider does not automatically permit processing personal data about your customers or other individuals. Saying “it saves staff time” does not replace an assessment. The Baden-Württemberg data protection authority explains that mere usefulness is insufficient for contractual necessity; legitimate interests require a balancing exercise.

Record the purpose, data fields, people affected and the assessed lawful basis with its reasoning. If the last field remains unresolved, keep testing with synthetic data. Health information and other special categories also require the conditions under Article 9 to be met.

Question 2: What does the provider do with the data?

The provider’s role must match the actual workflow. When a service processes personal data on your behalf, the agreement required by Article 28 GDPR is needed, commonly called a data processing agreement. It covers instructions, confidentiality, security measures, further processors and assistance with individual rights, among other requirements. The agreement does not replace your own lawful basis.

Request documents for the exact plan and feature you intend to use. A general privacy page is insufficient if uploads, search features or connected services receive different treatment. Ask separately about using inputs and outputs for model training and about the provider’s own purposes. Excluding training is an important component, but it is not a complete privacy assessment. If the provider processes data for its own purposes, assess its role and lawful basis separately; a processing agreement does not automatically cover that use.

Keep the contract version, subprocessor list and relevant settings together as evidence. The person responsible should be able to establish which terms applied when the workflow was approved.

Question 3: Where are data processed and accessible?

The server location describes only part of the journey. Draw four stages for your workflow: input, model processing, stored history and support. Add connected services. For each stage, ask which companies and countries are involved, including possible remote access.

EU storage does not automatically answer whether data are transferred to recipients outside the European Economic Area. If such transfers occur, the requirements of Chapter V GDPR apply in addition. The provider should identify the transfer instrument, such as an applicable adequacy decision or appropriate safeguards, and supply the supporting evidence.

The initial entry in your checklist should therefore be more specific than “German hosting”. Write: “Model processing: unresolved; support access: unresolved; subprocessor list: requested.” An unknown is an open question, not approval. A German flag does not delete data.

Question 4: What actually gets deleted, and when?

Every copy needs an accountable handling process. Ask separately about chats, uploaded files, logs, backups and data held by connected services. Record retention periods, deletion procedures, possible exceptions and the person who initiates the process. A chat disappearing from the interface does not prove that every other copy has been removed.

The German Data Protection Conference calls for effective organisational and technical procedures for rectification and erasure. For a practical check, use an invented case identifier, upload a synthetic file and follow the documented deletion procedure. What happens in backups or logs must also be established from the provider’s documentation.

Remove unnecessary working copies without unlawfully deleting original records that must be retained. Those originals have their own retention requirements. Keep working copies and original records separate on the checklist; a single blanket deadline for everything misses that distinction.

This enquiry requests the missing evidence

The supplier enquiry describes one specific use. Copy the following lines and replace the bracketed placeholders. Do not send real customer examples. The enquiry collects information; the business assesses its own lawful basis with the appropriate data protection adviser.

  • We are assessing [product, plan, feature] for [task]. The proposed data categories are [categories], relating to [groups of people]. Please answer specifically for this configuration.
  • What data protection role do you take for each processing activity? Where applicable, please provide the data processing agreement and the description of technical and organisational measures.
  • Do you use inputs, files or outputs for training or your own purposes? What contractual commitments and settings apply?
  • Which companies and subprocessors process the data, and in which countries? Please include support access and, where relevant, the instrument used for international transfers.
  • What retention and deletion rules apply to chats, files, logs and backups? How do you support access, rectification and erasure requests, and how are changes communicated?

The checklist ends with a bounded decision

The approval specifies the task, tool and data. A completed example reads: “Draft delivery enquiries; approved writing tool; synthetic product enquiries only; no customer files; owner: office manager; real data blocked until outstanding supplier questions are resolved.” This is a limited working instruction, not a certificate.

Before using real data, add access permissions, the required privacy information and an assessment of whether a data protection impact assessment is needed. Under Article 35 GDPR, this depends in particular on the likelihood of a high risk to individuals’ rights and freedoms. Having a small team does not rule it out.

As a planning calculation only: 45 minutes to organise documents, 30 minutes for synthetic test cases and 15 minutes to record the decision add up to 90 minutes. At an assumed internal labour cost of €50 per hour, that is €75. Supplier response times, software, technical changes and professional legal assessment are additional; this is not a measured project result.

Three common shortcuts leave questions unanswered

Common shortcuts do not replace a workflow assessment. “Is removing names enough?” No, if other details or a lookup list still make people identifiable. Redacting customer data before prompting covers practical preparation; if your business can link the details back to individuals using a lookup list, they remain personal data for your business.

“Is local AI automatically compliant?” No. It may avoid an external transmission route, while purpose, access controls and deletion remain the business’s responsibility. The German-language guide to using AI without the cloud explains that technical option. “Does approval then cover every team?” Only within the documented scope; new features or data categories trigger another assessment.

Create the four-question checklist for exactly one task now and put unresolved items into the supplier enquiry. Add the approved use to your internal AI policy. If you need help defining the technical scope, describe the task in an initial consultation, without including personal sample data.

Sources and status

Sources last checked: 9 October 2026. Vendor statements and our own reading of them are kept apart in the text.

  1. EUR-Lex: Datenschutz-Grundverordnung, konsolidierte Fassung
  2. Datenschutzkonferenz: Künstliche Intelligenz und Datenschutz, Mai 2024
  3. LfDI Baden-Württemberg: Rechtsgrundlagen beim Einsatz von KI
  4. Court of Justice: C-413/23 P, official summary of 4 September 2025

Corrections: [email protected].

What does this mean for your business?

We go through one concrete workflow with you and check whether AI can help.

Book a free first call →