Two problems
Organisations arrive with one and leave with two.
Problem one: an employee pastes personal data into an AI tool. That is processing by a new recipient, usually involving an international transfer, and it needs a lawful basis and a controller-processor agreement.
Problem two: you deploy monitoring to detect problem one. That is separate processing of employee personal data, needing its own lawful basis, a DPIA, and in several member states a works council consultation.
Solving the first by creating an unassessed second is a common and avoidable mistake.
Not legal advice. The answer differs by member state, and national employment law sits on top of GDPR. Reviewer to be named
Problem one
Six obligations engage at once.
The last row is the one that tends to end the debate internally: if a data subject exercises their right to erasure and part of their data was pasted into a consumer AI account, you have no contractual route to comply.
| Obligation | What it means here |
|---|---|
| Lawful basis | The original basis for holding the data almost certainly does not extend to disclosing it to a third-party model provider |
| Art. 28 processor terms | A controller-processor agreement is required. An employee’s personal free-tier account has none |
| Chapter V transfers | Most major providers process outside the EEA. Needs a transfer mechanism and, in practice, a TIA |
| Purpose limitation | Data collected to deliver a service, now used to generate a marketing draft, is a new purpose |
| Art. 5(1)(f) integrity | Uncontrolled disclosure to an unassessed recipient is difficult to reconcile with this |
| Arts. 15–17 subject rights | You cannot honour erasure for data sitting in a third party you have no agreement with |
Minimisation drives the product decision
Art. 5(1)(c), applied to DLP tooling, is a comparison.
Both architectures achieve the purpose. One is demonstrably the less intrusive means — and once a less intrusive means demonstrably exists and works, “we transmitted everything because it was simpler” becomes a harder position to defend in an assessment.
When the system never receives message content, several sections of your DPIA get considerably shorter.
| Cloud-inspection DLP | On-device detection | |
|---|---|---|
| Employee personal data collected | Full content of every inspected message | Type, count, confidence, masked snippet, destination |
| Additional processors involved | The DLP vendor | None for content — it never leaves the device |
| Additional international transfer | Usually yes | No |
| Available in a breach of the vendor | Message content | Redacted records only |
| Erasure request scope | Message archive | Event records |
A sequence that works
Nine steps, in this order.
The works council step is slower than the technical deployment. Start it first.
- 01
Assess the AI tools already in use
Including the ones nobody approved.
- 02
Sanction one, properly
Art. 28 terms, a transfer mechanism, and good enough that people prefer it.
- 03
Publish an AI use policy
Naming what may never be pasted anywhere.
- 04
Run the DPIA for the monitoring
With minimisation genuinely analysed rather than asserted.
- 05
Consult the works council
Where required — and it is the longest pole.
- 06
Notify employees in advance
Including what is not collected.
- 07
Deploy log-only, tune, warn, then block
In that order, without shortcuts.
- 08
Set retention per framework
And actually enforce it.
- 09
Re-assess annually
And whenever a provider changes terms.
Straight answers
Is pasting customer data into ChatGPT a GDPR breach?
It is at minimum unauthorised processing by a new recipient. Whether it is a personal data breach requiring notification depends on the circumstances and on your assessment — but an undocumented disclosure to an unassessed processor is an issue regardless of how that assessment lands.
Do we need a DPIA for AI DLP monitoring?
Systematic monitoring of employees generally meets the DPIA threshold. The assessment is also where the architecture of your chosen tool becomes relevant, because minimisation asks whether the purpose could have been met by collecting less.
Can we rely on employee consent?
Rarely. Consent must be freely given, and regulators have consistently treated the employment relationship as undermining that. Legitimate interest with a documented balancing test is the more usual footing.
Does using an EU-hosted AI provider solve the transfer problem?
It addresses the transfer question specifically. It does not by itself address lawful basis, purpose limitation, retention, subject rights, or whether the disclosure was authorised in the first place.