GDPR

GDPR and AI tools: two problems, not one.

Pasting personal data into an AI tool is processing by a new recipient, usually involving an international transfer, and needs a lawful basis plus a controller-processor agreement. Monitoring employees for it is separate processing that needs its own basis and a DPIA.

ONE PASTE SANCTIONED PERSONAL
Same hostname. Same interface. Entirely different legal position.
Also in compliance HIPAA and AI tools PCI DSS and AI tools

Two problems

Organisations arrive with one and leave with two.

Problem one: an employee pastes personal data into an AI tool. That is processing by a new recipient, usually involving an international transfer, and it needs a lawful basis and a controller-processor agreement.

Problem two: you deploy monitoring to detect problem one. That is separate processing of employee personal data, needing its own lawful basis, a DPIA, and in several member states a works council consultation.

Solving the first by creating an unassessed second is a common and avoidable mistake.

Not legal advice. The answer differs by member state, and national employment law sits on top of GDPR.  Reviewer to be named

Problem one

Six obligations engage at once.

The last row is the one that tends to end the debate internally: if a data subject exercises their right to erasure and part of their data was pasted into a consumer AI account, you have no contractual route to comply.

Obligations engaged when personal data reaches an AI tool
ObligationWhat it means here
Lawful basisThe original basis for holding the data almost certainly does not extend to disclosing it to a third-party model provider
Art. 28 processor termsA controller-processor agreement is required. An employee’s personal free-tier account has none
Chapter V transfersMost major providers process outside the EEA. Needs a transfer mechanism and, in practice, a TIA
Purpose limitationData collected to deliver a service, now used to generate a marketing draft, is a new purpose
Art. 5(1)(f) integrityUncontrolled disclosure to an unassessed recipient is difficult to reconcile with this
Arts. 15–17 subject rightsYou cannot honour erasure for data sitting in a third party you have no agreement with

Minimisation drives the product decision

Art. 5(1)(c), applied to DLP tooling, is a comparison.

Both architectures achieve the purpose. One is demonstrably the less intrusive means — and once a less intrusive means demonstrably exists and works, “we transmitted everything because it was simpler” becomes a harder position to defend in an assessment.

When the system never receives message content, several sections of your DPIA get considerably shorter.

Cloud-inspection DLP compared with on-device detection
 Cloud-inspection DLPOn-device detection
Employee personal data collectedFull content of every inspected messageType, count, confidence, masked snippet, destination
Additional processors involvedThe DLP vendorNone for content — it never leaves the device
Additional international transferUsually yesNo
Available in a breach of the vendorMessage contentRedacted records only
Erasure request scopeMessage archiveEvent records

A sequence that works

Nine steps, in this order.

The works council step is slower than the technical deployment. Start it first.

  1. 01

    Assess the AI tools already in use

    Including the ones nobody approved.

  2. 02

    Sanction one, properly

    Art. 28 terms, a transfer mechanism, and good enough that people prefer it.

  3. 03

    Publish an AI use policy

    Naming what may never be pasted anywhere.

  4. 04

    Run the DPIA for the monitoring

    With minimisation genuinely analysed rather than asserted.

  5. 05

    Consult the works council

    Where required — and it is the longest pole.

  6. 06

    Notify employees in advance

    Including what is not collected.

  7. 07

    Deploy log-only, tune, warn, then block

    In that order, without shortcuts.

  8. 08

    Set retention per framework

    And actually enforce it.

  9. 09

    Re-assess annually

    And whenever a provider changes terms.

Straight answers

Is pasting customer data into ChatGPT a GDPR breach?

It is at minimum unauthorised processing by a new recipient. Whether it is a personal data breach requiring notification depends on the circumstances and on your assessment — but an undocumented disclosure to an unassessed processor is an issue regardless of how that assessment lands.

Do we need a DPIA for AI DLP monitoring?

Systematic monitoring of employees generally meets the DPIA threshold. The assessment is also where the architecture of your chosen tool becomes relevant, because minimisation asks whether the purpose could have been met by collecting less.

Can we rely on employee consent?

Rarely. Consent must be freely given, and regulators have consistently treated the employment relationship as undermining that. Legitimate interest with a documented balancing test is the more usual footing.

Does using an EU-hosted AI provider solve the transfer problem?

It addresses the transfer question specifically. It does not by itself address lawful basis, purpose limitation, retention, subject rights, or whether the disclosure was authorised in the first place.

Bring your DPIA.

The minimisation section is the one where the architecture does the work, and it is usually the shortest.