Jonáš Světlík

GDPR and company data in AI

The moment anything personal flows into an AI, GDPR applies just as it does anywhere. Here are the practical rules on what you may and may not do - without the legalese.

The basics in one sentence

Personal data (a name, an email, a phone number, anything that identifies a specific person) is protected. AI is just one more place you send data to - and the same rules apply.

What to settle before every input

  • I have a reason to process that data?
  • Where flow - which provider, and where are their servers?
  • I have consent or a contractif it is customer data?

Practical rules

  • Anonymise - swap names and details for placeholders.
  • Use the business tierwhere data is not used for training.
  • Keep a recordof what you send where, and get it covered with the processor.

Sensitive categories

Health data and similarly sensitive categories - extra care, preferably not at all, or only in a properly buttoned-up setup.

What to watch out for

This is not legal advice. On bigger projects bring in a lawyer - this is a sound baseline so you do not get burned on the everyday stuff.

GDPR does not give AI a pass. But one extra rule covers it: before you paste anything, know whose data it is and where it goes.

Want AI where the data stays under your control?

I can deploy setups where sensitive data never leaves a safe environment, including locally on your own hardware. Get in touch and we will talk it over.